CVE-2018-0875High

.NET Core Denial of Service Vulnerability

Published
March 13, 2018
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A denial of service vulnerability exists in the way that .NET Core handles specially crafted requests, causing a hash collision. To exploit the vulnerability, an attacker could send a small number of specially crafted requests to an .NET Core web application, causing performance to degrade significantly enough to cause a denial of service condition. The security update addresses the vulnerability by correcting how .NET Core handles specially crafted requests to prevent a hash collision.

🎯 Affected products4

  • .NET Core 1.0
  • .NET Core 1.1
  • .NET Core 2.0
  • PowerShell Core 6.0.0

✅ Remediation

KBCommit (Security Update) KBRelease Notes (Security Update)

🔗 References (3)