CVE-2018-8409High

System.IO.Pipelines Denial of Service

Published
September 11, 2018
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an application that is leveraging System.IO.Pipelines. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by providing specially crafted requests to the application. The update addresses the vulnerability by correcting how System.IO.Pipelines handles requests.

🎯 Affected products3

  • .NET Core 2.1
  • ASP.NET Core 2.1
  • System.IO.Pipelines

✅ Remediation

KBRelease Notes (Security Update)

🔗 References (2)