RHSA-2020:2250HighCVSS 7.5
Red Hat Security Advisory: dotnet3.1 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2020-1108 — dotnet: Denial of service via untrusted input CVE-2020-1161 — dotnet: Denial of service due to infinite loop
🎯 Affected products20
- Red Hat Enterprise Linux AppStream (v. 8)
- aspnetcore-runtime-3.1-0:3.1.4-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- aspnetcore-targeting-pack-3.1-0:3.1.4-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- dotnet-0:3.1.104-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- dotnet-apphost-pack-3.1-0:3.1.4-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- dotnet-apphost-pack-3.1-debuginfo-0:3.1.4-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- dotnet-host-0:3.1.4-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- dotnet-host-debuginfo-0:3.1.4-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- dotnet-hostfxr-3.1-0:3.1.4-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- dotnet-hostfxr-3.1-debuginfo-0:3.1.4-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- dotnet-runtime-3.1-0:3.1.4-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- dotnet-runtime-3.1-debuginfo-0:3.1.4-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- dotnet-sdk-3.1-0:3.1.104-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- dotnet-sdk-3.1-debuginfo-0:3.1.104-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- dotnet-targeting-pack-3.1-0:3.1.4-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- dotnet-templates-3.1-0:3.1.104-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- dotnet3.1-0:3.1.104-2.el8_2.src as a component of Red Hat Enterprise Linux AppStream (v. 8)
- dotnet3.1-debuginfo-0:3.1.104-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- dotnet3.1-debugsource-0:3.1.104-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- netstandard-targeting-pack-2.1-0:3.1.104-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2020:2250
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1827643
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1827645
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_2250.json