Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZ4aDctNHYydy0zNnE2

ASP.NET Core fails to properly validate web requests

A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range.

Permalink: https://github.com/advisories/GHSA-6xh7-4v2w-36q6
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZ4aDctNHYydy0zNnE2
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 4 years ago
Updated: 4 months ago


CVSS Score: 7.5
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Identifiers: GHSA-6xh7-4v2w-36q6, CVE-2017-0247
References:

Affected Packages

nuget:System.Net.Http.WinHttpHandler
Versions: >= 4.3.0, < 4.5.4, = 4.0.0
Fixed in: 4.5.4, 4.0.1
nuget:Microsoft.AspNetCore.Mvc.WebApiCompatShim
Versions: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
nuget:Microsoft.AspNetCore.Mvc.ViewFeatures
Versions: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
nuget:Microsoft.AspNetCore.Mvc.TagHelpers
Versions: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
nuget:Microsoft.AspNetCore.Mvc.Razor
Versions: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
nuget:Microsoft.AspNetCore.Mvc.Razor.Host
Versions: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
nuget:Microsoft.AspNetCore.Mvc.Localization
Versions: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
nuget:Microsoft.AspNetCore.Mvc.Formatters.Xml
Versions: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
nuget:Microsoft.AspNetCore.Mvc.Formatters.Json
Versions: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
nuget:Microsoft.AspNetCore.Mvc.DataAnnotations
Versions: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
nuget:Microsoft.AspNetCore.Mvc.Cors
Versions: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
nuget:Microsoft.AspNetCore.Mvc.ApiExplorer
Versions: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
nuget:Microsoft.AspNetCore.Mvc.Abstractions
Versions: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
nuget:System.Net.WebSockets.Client
Versions: = 4.3.0, = 4.0.0
Fixed in: 4.3.1, 4.0.1
nuget:System.Net.Security
Versions: = 4.3.0, = 4.0.0
Fixed in: 4.3.1, 4.0.1
nuget:System.Text.Encodings.Web
Versions: = 4.3.0, = 4.0.0
Fixed in: 4.3.1, 4.0.1
nuget:System.Net.Http
Versions: = 4.3.1, = 4.1.1
Fixed in: 4.3.2, 4.1.2
nuget:Microsoft.AspNetCore.Mvc.Core
Versions: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
nuget:Microsoft.AspNetCore.Mvc
Versions: >= 1.0.0, < 1.0.4, >= 1.1.0, < 1.1.3
Fixed in: 1.0.4, 1.1.3