CVE-2018-8409High
System.IO.Pipelines Denial of Service
🔗 CVE IDs covered (1)
📋 Description
A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an application that is leveraging System.IO.Pipelines. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by providing specially crafted requests to the application. The update addresses the vulnerability by correcting how System.IO.Pipelines handles requests.
🎯 Affected products3
- .NET Core 2.1
- ASP.NET Core 2.1
- System.IO.Pipelines
✅ Remediation
KBRelease Notes (Security Update)