ID

VAR-202005-0134


CVE

CVE-2020-1161


TITLE

Microsoft ASP.NET Core input validation error vulnerability

Trust: 1.2

sources: CNVD: CNVD-2020-40626 // CNNVD: CNNVD-202005-568

DESCRIPTION

A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the ASP.NET Core application. The update addresses the vulnerability by correcting how the ASP.NET Core web application handles web requests. (DoS) Vulnerability exists. Microsoft Visual Studio is a series of development tool suite products and a basic and complete development tool set. It includes most of the tools needed throughout the software life cycle. The framework is used to build cloud-based applications such as Web applications, Internet of Things applications, and mobile backends. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: .NET Core on Red Hat Enterprise Linux security and bug fix update Advisory ID: RHSA-2020:2249-01 Product: .NET Core on Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:2249 Issue date: 2020-05-21 CVE Names: CVE-2020-1108 CVE-2020-1161 ===================================================================== 1. Summary: An update for rh-dotnet31-dotnet is now available for .NET Core on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 .NET Core on Red Hat Enterprise Linux Server (v. 7) - x86_64 .NET Core on Red Hat Enterprise Linux Workstation (v. 7) - x86_64 3. Description: .NET Core is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET Core that address security vulnerabilities are now available. The updated versions are .NET Core SDK 3.1.104 and .NET Core Runtime 3.1.4. Security Fix(es): * dotnet: Denial of service via untrusted input (CVE-2020-1108) * dotnet: Denial of service due to infinite loop (CVE-2020-1161) Default inclusions for applications built with .NET Core have been updated to reference the newest versions and their security fixes. For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1827643 - CVE-2020-1108 dotnet: Denial of service via untrusted input 1827645 - CVE-2020-1161 dotnet: Denial of service due to infinite loop 6. Package List: .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7): Source: rh-dotnet31-dotnet-3.1.104-2.el7.src.rpm x86_64: rh-dotnet31-aspnetcore-runtime-3.1-3.1.4-2.el7.x86_64.rpm rh-dotnet31-aspnetcore-targeting-pack-3.1-3.1.4-2.el7.x86_64.rpm rh-dotnet31-dotnet-3.1.104-2.el7.x86_64.rpm rh-dotnet31-dotnet-apphost-pack-3.1-3.1.4-2.el7.x86_64.rpm rh-dotnet31-dotnet-debuginfo-3.1.104-2.el7.x86_64.rpm rh-dotnet31-dotnet-host-3.1.4-2.el7.x86_64.rpm rh-dotnet31-dotnet-hostfxr-3.1-3.1.4-2.el7.x86_64.rpm rh-dotnet31-dotnet-runtime-3.1-3.1.4-2.el7.x86_64.rpm rh-dotnet31-dotnet-sdk-3.1-3.1.104-2.el7.x86_64.rpm rh-dotnet31-dotnet-targeting-pack-3.1-3.1.4-2.el7.x86_64.rpm rh-dotnet31-dotnet-templates-3.1-3.1.104-2.el7.x86_64.rpm rh-dotnet31-netstandard-targeting-pack-2.1-3.1.104-2.el7.x86_64.rpm .NET Core on Red Hat Enterprise Linux Server (v. 7): Source: rh-dotnet31-dotnet-3.1.104-2.el7.src.rpm x86_64: rh-dotnet31-aspnetcore-runtime-3.1-3.1.4-2.el7.x86_64.rpm rh-dotnet31-aspnetcore-targeting-pack-3.1-3.1.4-2.el7.x86_64.rpm rh-dotnet31-dotnet-3.1.104-2.el7.x86_64.rpm rh-dotnet31-dotnet-apphost-pack-3.1-3.1.4-2.el7.x86_64.rpm rh-dotnet31-dotnet-debuginfo-3.1.104-2.el7.x86_64.rpm rh-dotnet31-dotnet-host-3.1.4-2.el7.x86_64.rpm rh-dotnet31-dotnet-hostfxr-3.1-3.1.4-2.el7.x86_64.rpm rh-dotnet31-dotnet-runtime-3.1-3.1.4-2.el7.x86_64.rpm rh-dotnet31-dotnet-sdk-3.1-3.1.104-2.el7.x86_64.rpm rh-dotnet31-dotnet-targeting-pack-3.1-3.1.4-2.el7.x86_64.rpm rh-dotnet31-dotnet-templates-3.1-3.1.104-2.el7.x86_64.rpm rh-dotnet31-netstandard-targeting-pack-2.1-3.1.104-2.el7.x86_64.rpm .NET Core on Red Hat Enterprise Linux Workstation (v. 7): Source: rh-dotnet31-dotnet-3.1.104-2.el7.src.rpm x86_64: rh-dotnet31-aspnetcore-runtime-3.1-3.1.4-2.el7.x86_64.rpm rh-dotnet31-aspnetcore-targeting-pack-3.1-3.1.4-2.el7.x86_64.rpm rh-dotnet31-dotnet-3.1.104-2.el7.x86_64.rpm rh-dotnet31-dotnet-apphost-pack-3.1-3.1.4-2.el7.x86_64.rpm rh-dotnet31-dotnet-debuginfo-3.1.104-2.el7.x86_64.rpm rh-dotnet31-dotnet-host-3.1.4-2.el7.x86_64.rpm rh-dotnet31-dotnet-hostfxr-3.1-3.1.4-2.el7.x86_64.rpm rh-dotnet31-dotnet-runtime-3.1-3.1.4-2.el7.x86_64.rpm rh-dotnet31-dotnet-sdk-3.1-3.1.104-2.el7.x86_64.rpm rh-dotnet31-dotnet-targeting-pack-3.1-3.1.4-2.el7.x86_64.rpm rh-dotnet31-dotnet-templates-3.1-3.1.104-2.el7.x86_64.rpm rh-dotnet31-netstandard-targeting-pack-2.1-3.1.104-2.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-1108 https://access.redhat.com/security/cve/CVE-2020-1161 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXsaf4tzjgjWX9erEAQjTHA//daLObmVWkk7wO3loCqPQJgXiuyshm1Jj 2pXg1tT24AQE2lGzOts8f7HjpCC60LeSAXLQseKlmZ7Nrdhi/KE8dFto3JhcBp0n fjFHoImjPgz5cIOWU94LS9H3ST9Ih+kL9b9o4DIRff6/KlpWEvdfoMejgaNl4zjW YV+ozpiDxmvOo0OudxMgFiw17iSUO28a3HZqLBz+DE/7+2RY8irLGVyYo/0XVpz0 mnbkDWcue4wJmDcQzrtsSSLm2L3m3CIHGF4kJ+C3QdSdtOQchHG3Y9XtkeEEIWz8 uHE+gkfRU9Nm+cw+4QMW7o0b1mwX329oyd+1O5D/KeaJ6ABM8yfihEfmVxSpCGW1 4+qSjDNeauC+c/Rm0jBtWRQCct/XJQbBrqii05dlarA9a+YHiBeIkDt5U46Y0/FD CcAsZtyf1Zfe8DyTFMsEQ5DDltudbRgguTbEmMBEeOOkmZFQE7aSI5veeWuUuxqs UIjckIgUN7MWYtm8Fq4KMOJe5l4uYwY3T3G6r8AxxJs1PLokuYvT7CHTkjPg9hEG Dv4J3fkzD9rybvaZUDkTDDLgGoK3zHSlcYlRAEwLT9aN2pCF0PyHYnZtsdz93oEP tyddvt2olVLDsJBkYlTvwRBVNLTzv7Uj4qFUJqW4LjhtGpHZvld60Gf7xh8ooqv7 g8PwL1mfJdI= =8ZmH -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 2.97

sources: NVD: CVE-2020-1161 // JVNDB: JVNDB-2020-005783 // CNVD: CNVD-2020-40626 // CNNVD: CNNVD-202005-568 // VULMON: CVE-2020-1161 // PACKETSTORM: 157794 // PACKETSTORM: 157788

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-40626

AFFECTED PRODUCTS

vendor:microsoftmodel:asp.net corescope:eqversion:3.1

Trust: 2.4

vendor:microsoftmodel:visual studio 2017scope:lteversion:15.9

Trust: 1.0

vendor:microsoftmodel:visual studio 2019scope:gteversion:16.0

Trust: 1.0

vendor:microsoftmodel:visual studio 2017scope:gteversion:15.1

Trust: 1.0

vendor:microsoftmodel:visual studio 2019scope:lteversion:16.5

Trust: 1.0

vendor:microsoftmodel:visual studioscope:eqversion:2017 version 15.9 (includes 15.0 - 15.8)

Trust: 0.8

vendor:microsoftmodel:visual studioscope:eqversion:2019 version 16.0

Trust: 0.8

vendor:microsoftmodel:visual studioscope:eqversion:2019 version 16.4 (includes 16.0 - 16.3)

Trust: 0.8

vendor:microsoftmodel:visual studioscope:eqversion:2019 version 16.5

Trust: 0.8

vendor:microsoftmodel:visual studioscope:eqversion:201715.9

Trust: 0.6

vendor:microsoftmodel:visual studioscope:eqversion:201916.0

Trust: 0.6

vendor:microsoftmodel:visual studioscope:eqversion:201916.4

Trust: 0.6

vendor:microsoftmodel:visual studioscope:eqversion:201916.5

Trust: 0.6

sources: CNVD: CNVD-2020-40626 // JVNDB: JVNDB-2020-005783 // NVD: CVE-2020-1161

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-1161
value: HIGH

Trust: 1.0

NVD: JVNDB-2020-005783
value: HIGH

Trust: 0.8

CNVD: CNVD-2020-40626
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202005-568
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2020-1161
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-005783
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2020-40626
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-1161
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-005783
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-40626 // CNNVD: CNNVD-202005-568 // JVNDB: JVNDB-2020-005783 // NVD: CVE-2020-1161

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-20

Trust: 0.8

sources: JVNDB: JVNDB-2020-005783 // NVD: CVE-2020-1161

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202005-568

TYPE

input validation error

Trust: 0.6

sources: CNNVD: CNNVD-202005-568

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-005783

PATCH

title:CVE-2020-1161 | ASP.NET Core Denial of Service Vulnerabilityurl:https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-1161

Trust: 0.8

title:CVE-2020-1161 | ASP.NET Core のサービス拒否の脆弱性url:https://portal.msrc.microsoft.com/ja-jp/security-guidance/advisory/CVE-2020-1161

Trust: 0.8

title:Patch for Microsoft ASP.NET Core input validation error vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/225853

Trust: 0.6

title:Microsoft ASP.NET Core Enter the fix for the verification error vulnerabilityurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=119629

Trust: 0.6

sources: CNVD: CNVD-2020-40626 // CNNVD: CNNVD-202005-568 // JVNDB: JVNDB-2020-005783

EXTERNAL IDS

db:NVDid:CVE-2020-1161

Trust: 3.3

db:JVNDBid:JVNDB-2020-005783

Trust: 0.8

db:PACKETSTORMid:157794

Trust: 0.7

db:CNVDid:CNVD-2020-40626

Trust: 0.6

db:AUSCERTid:ESB-2020.1814

Trust: 0.6

db:NSFOCUSid:46715

Trust: 0.6

db:CNNVDid:CNNVD-202005-568

Trust: 0.6

db:VULMONid:CVE-2020-1161

Trust: 0.1

db:PACKETSTORMid:157788

Trust: 0.1

sources: CNVD: CNVD-2020-40626 // VULMON: CVE-2020-1161 // PACKETSTORM: 157794 // PACKETSTORM: 157788 // CNNVD: CNNVD-202005-568 // JVNDB: JVNDB-2020-005783 // NVD: CVE-2020-1161

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2020-1161

Trust: 1.6

url:https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/cve-2020-1161

Trust: 1.6

url:https://access.redhat.com/security/cve/cve-2020-1161

Trust: 1.4

url:https://msrc.microsoft.com/update-guide/vulnerability/cve-2020-1161

Trust: 1.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-1161

Trust: 0.8

url:https://www.ipa.go.jp/security/ciadr/vul/20200513-ms.html

Trust: 0.8

url:https://www.jpcert.or.jp/at/2020/at200022.html

Trust: 0.8

url:https://packetstormsecurity.com/files/157794/red-hat-security-advisory-2020-2250-01.html

Trust: 0.6

url:http://www.nsfocus.net/vulndb/46715

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.1814/

Trust: 0.6

url:https://portal.msrc.microsoft.com/zh-cn/security-guidance/advisory/cve-2020-1161

Trust: 0.6

url:https://vigilance.fr/vulnerability/microsoft-visual-studio-vulnerabilities-of-may-2020-32249

Trust: 0.6

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2020-1108

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2020-1108

Trust: 0.2

url:https://bugzilla.redhat.com/):

Trust: 0.2

url:https://access.redhat.com/security/team/key/

Trust: 0.2

url:https://access.redhat.com/articles/11258

Trust: 0.2

url:https://access.redhat.com/security/team/contact/

Trust: 0.2

url:https://access.redhat.com/security/updates/classification/#important

Trust: 0.2

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/181110

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2020:2250

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2020:2249

Trust: 0.1

sources: CNVD: CNVD-2020-40626 // VULMON: CVE-2020-1161 // PACKETSTORM: 157794 // PACKETSTORM: 157788 // CNNVD: CNNVD-202005-568 // JVNDB: JVNDB-2020-005783 // NVD: CVE-2020-1161

CREDITS

Red Hat

Trust: 0.8

sources: PACKETSTORM: 157794 // PACKETSTORM: 157788 // CNNVD: CNNVD-202005-568

SOURCES

db:CNVDid:CNVD-2020-40626
db:VULMONid:CVE-2020-1161
db:PACKETSTORMid:157794
db:PACKETSTORMid:157788
db:CNNVDid:CNNVD-202005-568
db:JVNDBid:JVNDB-2020-005783
db:NVDid:CVE-2020-1161

LAST UPDATE DATE

2026-08-21T23:18:11.518000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-40626date:2020-07-17T00:00:00
db:VULMONid:CVE-2020-1161date:2020-05-27T00:00:00
db:CNNVDid:CNNVD-202005-568date:2020-05-28T00:00:00
db:JVNDBid:JVNDB-2020-005783date:2020-06-23T00:00:00
db:NVDid:CVE-2020-1161date:2026-08-19T17:17:28.160

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-40626date:2020-07-17T00:00:00
db:VULMONid:CVE-2020-1161date:2020-05-21T00:00:00
db:PACKETSTORMid:157794date:2020-05-21T16:41:39
db:PACKETSTORMid:157788date:2020-05-21T16:34:50
db:CNNVDid:CNNVD-202005-568date:2020-05-12T00:00:00
db:JVNDBid:JVNDB-2020-005783date:2020-06-23T00:00:00
db:NVDid:CVE-2020-1161date:2020-05-21T23:15:17.603