RHSA-2020:2249HighCVSS 7.5
Red Hat Security Advisory: .NET Core on Red Hat Enterprise Linux security and bug fix update
🔗 CVE IDs covered (2)
📋 Description
CVE-2020-1108 — dotnet: Denial of service via untrusted input CVE-2020-1161 — dotnet: Denial of service due to infinite loop
🎯 Affected products42
- .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7)
- .NET Core on Red Hat Enterprise Linux Server (v. 7)
- .NET Core on Red Hat Enterprise Linux Workstation (v. 7)
- rh-dotnet31-aspnetcore-runtime-3.1-0:3.1.4-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7)
- rh-dotnet31-aspnetcore-runtime-3.1-0:3.1.4-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux Server (v. 7)
- rh-dotnet31-aspnetcore-runtime-3.1-0:3.1.4-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux Workstation (v. 7)
- rh-dotnet31-aspnetcore-targeting-pack-3.1-0:3.1.4-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7)
- rh-dotnet31-aspnetcore-targeting-pack-3.1-0:3.1.4-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux Server (v. 7)
- rh-dotnet31-aspnetcore-targeting-pack-3.1-0:3.1.4-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux Workstation (v. 7)
- rh-dotnet31-dotnet-0:3.1.104-2.el7.src as a component of .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7)
- rh-dotnet31-dotnet-0:3.1.104-2.el7.src as a component of .NET Core on Red Hat Enterprise Linux Server (v. 7)
- rh-dotnet31-dotnet-0:3.1.104-2.el7.src as a component of .NET Core on Red Hat Enterprise Linux Workstation (v. 7)
- rh-dotnet31-dotnet-0:3.1.104-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7)
- rh-dotnet31-dotnet-0:3.1.104-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux Server (v. 7)
- rh-dotnet31-dotnet-0:3.1.104-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux Workstation (v. 7)
- rh-dotnet31-dotnet-apphost-pack-3.1-0:3.1.4-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7)
- rh-dotnet31-dotnet-apphost-pack-3.1-0:3.1.4-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux Server (v. 7)
- rh-dotnet31-dotnet-apphost-pack-3.1-0:3.1.4-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux Workstation (v. 7)
- rh-dotnet31-dotnet-debuginfo-0:3.1.104-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7)
- rh-dotnet31-dotnet-debuginfo-0:3.1.104-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux Server (v. 7)
- rh-dotnet31-dotnet-debuginfo-0:3.1.104-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux Workstation (v. 7)
- rh-dotnet31-dotnet-host-0:3.1.4-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7)
- rh-dotnet31-dotnet-host-0:3.1.4-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux Server (v. 7)
- rh-dotnet31-dotnet-host-0:3.1.4-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux Workstation (v. 7)
- rh-dotnet31-dotnet-hostfxr-3.1-0:3.1.4-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7)
- rh-dotnet31-dotnet-hostfxr-3.1-0:3.1.4-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux Server (v. 7)
- rh-dotnet31-dotnet-hostfxr-3.1-0:3.1.4-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux Workstation (v. 7)
- rh-dotnet31-dotnet-runtime-3.1-0:3.1.4-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7)
- rh-dotnet31-dotnet-runtime-3.1-0:3.1.4-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux Server (v. 7)
- rh-dotnet31-dotnet-runtime-3.1-0:3.1.4-2.el7.x86_64 as a component of .NET Core on Red Hat Enterprise Linux Workstation (v. 7)
- +12 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2020:2249
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1827643
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1827645
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_2249.json