ID

VAR-202005-0234


CVE

CVE-2020-1108


TITLE

.NET Core and .NET Framework Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2020-006114

DESCRIPTION

A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application. The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: .NET Core on Red Hat Enterprise Linux 7 security update Advisory ID: RHSA-2020:2476-01 Product: .NET Core on Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:2476 Issue date: 2020-06-10 CVE Names: CVE-2020-1108 ==================================================================== 1. Summary: An update for rh-dotnet21-dotnet is now available for .NET Core on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 .NET Core on Red Hat Enterprise Linux Server (v. 7) - x86_64 .NET Core on Red Hat Enterprise Linux Workstation (v. 7) - x86_64 3. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. The updated version is .NET Core Runtime 2.1.19 and SDK 2.1.515. Security Fix(es): * dotnet: Denial of service via untrusted input (CVE-2020-1108) This is an additional update to comprehensively address CVE-2020-1108. Default inclusions for applications built with .NET Core have been updated to reference the newest versions and their security fixes. For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1827643 - CVE-2020-1108 dotnet: Denial of service via untrusted input 6. Package List: .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7): Source: rh-dotnet21-2.1-18.el7.src.rpm rh-dotnet21-dotnet-2.1.515-1.el7.src.rpm x86_64: rh-dotnet21-2.1-18.el7.x86_64.rpm rh-dotnet21-dotnet-2.1.515-1.el7.x86_64.rpm rh-dotnet21-dotnet-debuginfo-2.1.515-1.el7.x86_64.rpm rh-dotnet21-dotnet-host-2.1.19-1.el7.x86_64.rpm rh-dotnet21-dotnet-runtime-2.1-2.1.19-1.el7.x86_64.rpm rh-dotnet21-dotnet-sdk-2.1-2.1.515-1.el7.x86_64.rpm rh-dotnet21-dotnet-sdk-2.1.5xx-2.1.515-1.el7.x86_64.rpm rh-dotnet21-runtime-2.1-18.el7.x86_64.rpm .NET Core on Red Hat Enterprise Linux Server (v. 7): Source: rh-dotnet21-2.1-18.el7.src.rpm rh-dotnet21-dotnet-2.1.515-1.el7.src.rpm x86_64: rh-dotnet21-2.1-18.el7.x86_64.rpm rh-dotnet21-dotnet-2.1.515-1.el7.x86_64.rpm rh-dotnet21-dotnet-debuginfo-2.1.515-1.el7.x86_64.rpm rh-dotnet21-dotnet-host-2.1.19-1.el7.x86_64.rpm rh-dotnet21-dotnet-runtime-2.1-2.1.19-1.el7.x86_64.rpm rh-dotnet21-dotnet-sdk-2.1-2.1.515-1.el7.x86_64.rpm rh-dotnet21-dotnet-sdk-2.1.5xx-2.1.515-1.el7.x86_64.rpm rh-dotnet21-runtime-2.1-18.el7.x86_64.rpm .NET Core on Red Hat Enterprise Linux Workstation (v. 7): Source: rh-dotnet21-2.1-18.el7.src.rpm rh-dotnet21-dotnet-2.1.515-1.el7.src.rpm x86_64: rh-dotnet21-2.1-18.el7.x86_64.rpm rh-dotnet21-dotnet-2.1.515-1.el7.x86_64.rpm rh-dotnet21-dotnet-debuginfo-2.1.515-1.el7.x86_64.rpm rh-dotnet21-dotnet-host-2.1.19-1.el7.x86_64.rpm rh-dotnet21-dotnet-runtime-2.1-2.1.19-1.el7.x86_64.rpm rh-dotnet21-dotnet-sdk-2.1-2.1.515-1.el7.x86_64.rpm rh-dotnet21-dotnet-sdk-2.1.5xx-2.1.515-1.el7.x86_64.rpm rh-dotnet21-runtime-2.1-18.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-1108 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXuCqrtzjgjWX9erEAQgIPg/7Ba2cdZAbQ4uL6AsEoi4kN888lESbUKUM F3VebsFFw9mpaGJ+dp4O6Ihc9kKZdP6uFWq3VE5I5WPD2BcoZF/OoVfCY1FHmFy6 fWSZ0ii+Axg8Mqj4uqxlhlFujkxdeQSpfsY38rtPscLGBROEzPAZnUMH/RDXg9TD 3TdXT4SNVMQPloanzVRDPXEx4OLqgKn9ITpXLah/Jq6zsM37ZDbnM8vQ3o2nH11d 77N+M+RuGsamPfsbu8sEpgvdXkMtorUjO57PDWeWvxNiRYL/5at5TdcTePjWe5YK XANwzPRFtaEU87TFeTVbNrG3MdRl/Uk6FVbuJtNzFIxwi8+qIf1hnUpV0MZxZ1Rg o77fulouuHCSwV/j7/BN9I8Q7EJj/zm52PldVkbsR0JEr4kZMmlVxS9/VL/LroKS qFSAm8yykqI+g7b2EgBQCekIfuurbp1EPeyJ6WcVSb6kcH0xZrXE/t1u/qKIqICe Ozf/bnjDQ0ACpJTE8pAhs5NhrVXvLuz6qhu8kUHTkW6dRxqRCFhAOhnezsfeWG1K nfQOeNfny0SbIJlwh4nsWE3Zv2f/H8KYilfulHvA2SuIGg7mgE0wyPwDXCltyzEW JIlM5YyJrQOHLdjfFi8XRqcU1mFII/F9QoV6KqAoZfJ2LgjXLm9au8MNLWRkN7M1 XE8bQvAYQCc=mOEK -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 2.34

sources: NVD: CVE-2020-1108 // JVNDB: JVNDB-2020-006114 // VULMON: CVE-2020-1108 // PACKETSTORM: 158007 // PACKETSTORM: 158019 // PACKETSTORM: 157702 // PACKETSTORM: 157794 // PACKETSTORM: 157788 // PACKETSTORM: 158021 // PACKETSTORM: 157704

AFFECTED PRODUCTS

vendor:microsoftmodel:.net frameworkscope:eqversion:4.7

Trust: 1.0

vendor:microsoftmodel:.netscope:eqversion:5.0

Trust: 1.0

vendor:microsoftmodel:.net frameworkscope:eqversion:4.8

Trust: 1.0

vendor:microsoftmodel:.net corescope:eqversion:2.1

Trust: 1.0

vendor:microsoftmodel:.net frameworkscope:eqversion:3.0

Trust: 1.0

vendor:microsoftmodel:.net frameworkscope:eqversion:3.5

Trust: 1.0

vendor:microsoftmodel:.net frameworkscope:eqversion:4.6.1

Trust: 1.0

vendor:microsoftmodel:visual studio 2019scope:eqversion:16.5

Trust: 1.0

vendor:microsoftmodel:.net frameworkscope:eqversion:4.6

Trust: 1.0

vendor:microsoftmodel:.net frameworkscope:eqversion:2.0

Trust: 1.0

vendor:microsoftmodel:.net frameworkscope:eqversion:4.7.1

Trust: 1.0

vendor:microsoftmodel:visual studio 2017scope:eqversion:15.9

Trust: 1.0

vendor:microsoftmodel:powershell corescope:eqversion:6.2

Trust: 1.0

vendor:microsoftmodel:visual studio 2019scope:eqversion:16.0

Trust: 1.0

vendor:microsoftmodel:.net frameworkscope:eqversion:3.5.1

Trust: 1.0

vendor:microsoftmodel:visual studio 2019scope:eqversion:16.4

Trust: 1.0

vendor:microsoftmodel:.net frameworkscope:eqversion:4.6.2

Trust: 1.0

vendor:microsoftmodel:.net corescope:gteversion:2.1

Trust: 1.0

vendor:microsoftmodel:.net frameworkscope:eqversion:4.5.2

Trust: 1.0

vendor:microsoftmodel:powershellscope:eqversion:7.0

Trust: 1.0

vendor:microsoftmodel:.net corescope:lteversion:2.1.18

Trust: 1.0

vendor:microsoftmodel:.net frameworkscope:eqversion:4.7.2

Trust: 1.0

vendor:microsoftmodel:.net corescope:eqversion:3.1

Trust: 1.0

vendor:microsoftmodel:.net corescope:lteversion:3.1.4

Trust: 1.0

vendor:microsoftmodel:.net corescope:gteversion:3.0

Trust: 1.0

vendor:microsoftmodel:.net corescope: - version: -

Trust: 0.8

vendor:microsoftmodel:.net frameworkscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-006114 // NVD: CVE-2020-1108

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-1108
value: HIGH

Trust: 1.0

NVD: JVNDB-2020-006114
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202005-570
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2020-1108
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-006114
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

nvd@nist.gov: CVE-2020-1108
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-006114
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNNVD: CNNVD-202005-570 // JVNDB: JVNDB-2020-006114 // NVD: CVE-2020-1108

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2020-1108

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202005-570

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202005-570

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-006114

PATCH

title:CVE-2020-1108 | .NET Core & .NET Framework Denial of Service Vulnerabilityurl:https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1108

Trust: 0.8

title:CVE-2020-1108 | .NET Core および .NET Framework のサービス拒否の脆弱性url:https://portal.msrc.microsoft.com/ja-jp/security-guidance/advisory/CVE-2020-1108

Trust: 0.8

title:Microsoft .NET Core and .NET Framework Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=118696

Trust: 0.6

title:Red Hat: Important: .NET Core on Red Hat Enterprise Linux security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20202146 - Security Advisory

Trust: 0.1

title:Red Hat: Important: .NET Core security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20202143 - Security Advisory

Trust: 0.1

sources: VULMON: CVE-2020-1108 // CNNVD: CNNVD-202005-570 // JVNDB: JVNDB-2020-006114

EXTERNAL IDS

db:NVDid:CVE-2020-1108

Trust: 3.2

db:JVNDBid:JVNDB-2020-006114

Trust: 0.8

db:PACKETSTORMid:157794

Trust: 0.7

db:PACKETSTORMid:158021

Trust: 0.7

db:PACKETSTORMid:157704

Trust: 0.7

db:AUSCERTid:ESB-2020.2021

Trust: 0.6

db:AUSCERTid:ESB-2020.2010

Trust: 0.6

db:AUSCERTid:ESB-2020.1814

Trust: 0.6

db:AUSCERTid:ESB-2020.1691

Trust: 0.6

db:AUSCERTid:ESB-2020.2061

Trust: 0.6

db:NSFOCUSid:46713

Trust: 0.6

db:CNNVDid:CNNVD-202005-570

Trust: 0.6

db:VULMONid:CVE-2020-1108

Trust: 0.1

db:PACKETSTORMid:158007

Trust: 0.1

db:PACKETSTORMid:158019

Trust: 0.1

db:PACKETSTORMid:157702

Trust: 0.1

db:PACKETSTORMid:157788

Trust: 0.1

sources: VULMON: CVE-2020-1108 // PACKETSTORM: 158007 // PACKETSTORM: 158019 // PACKETSTORM: 157702 // PACKETSTORM: 157794 // PACKETSTORM: 157788 // PACKETSTORM: 158021 // PACKETSTORM: 157704 // CNNVD: CNNVD-202005-570 // JVNDB: JVNDB-2020-006114 // NVD: CVE-2020-1108

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2020-1108

Trust: 2.1

url:https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/cve-2020-1108

Trust: 1.6

url:https://msrc.microsoft.com/update-guide/vulnerability/cve-2020-1108

Trust: 1.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-1108

Trust: 0.8

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.7

url:https://access.redhat.com/security/cve/cve-2020-1108

Trust: 0.7

url:https://bugzilla.redhat.com/):

Trust: 0.7

url:https://access.redhat.com/security/team/key/

Trust: 0.7

url:https://access.redhat.com/articles/11258

Trust: 0.7

url:https://access.redhat.com/security/team/contact/

Trust: 0.7

url:https://access.redhat.com/security/updates/classification/#important

Trust: 0.7

url:https://www.auscert.org.au/bulletins/esb-2020.2061/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.1691/

Trust: 0.6

url:http://www.nsfocus.net/vulndb/46713

Trust: 0.6

url:https://packetstormsecurity.com/files/157794/red-hat-security-advisory-2020-2250-01.html

Trust: 0.6

url:https://packetstormsecurity.com/files/158021/red-hat-security-advisory-2020-2475-01.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.1814/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.2010/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.2021/

Trust: 0.6

url:https://vigilance.fr/vulnerability/microsoft-visual-studio-vulnerabilities-of-may-2020-32249

Trust: 0.6

url:https://packetstormsecurity.com/files/157704/red-hat-security-advisory-2020-2146-01.html

Trust: 0.6

url:https://access.redhat.com/errata/rhsa-2020:2146

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2020-1161

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2020-1161

Trust: 0.2

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/181094

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2020:2450

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2020:2476

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2020:2143

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2020:2250

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2020:2249

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2020:2475

Trust: 0.1

sources: VULMON: CVE-2020-1108 // PACKETSTORM: 158007 // PACKETSTORM: 158019 // PACKETSTORM: 157702 // PACKETSTORM: 157794 // PACKETSTORM: 157788 // PACKETSTORM: 158021 // PACKETSTORM: 157704 // CNNVD: CNNVD-202005-570 // JVNDB: JVNDB-2020-006114 // NVD: CVE-2020-1108

CREDITS

Red Hat

Trust: 1.3

sources: PACKETSTORM: 158007 // PACKETSTORM: 158019 // PACKETSTORM: 157702 // PACKETSTORM: 157794 // PACKETSTORM: 157788 // PACKETSTORM: 158021 // PACKETSTORM: 157704 // CNNVD: CNNVD-202005-570

SOURCES

db:VULMONid:CVE-2020-1108
db:PACKETSTORMid:158007
db:PACKETSTORMid:158019
db:PACKETSTORMid:157702
db:PACKETSTORMid:157794
db:PACKETSTORMid:157788
db:PACKETSTORMid:158021
db:PACKETSTORMid:157704
db:CNNVDid:CNNVD-202005-570
db:JVNDBid:JVNDB-2020-006114
db:NVDid:CVE-2020-1108

LAST UPDATE DATE

2026-08-28T23:16:53.141000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2020-1108date:2020-12-08T00:00:00
db:CNNVDid:CNNVD-202005-570date:2020-06-16T00:00:00
db:JVNDBid:JVNDB-2020-006114date:2020-06-30T00:00:00
db:NVDid:CVE-2020-1108date:2026-08-19T17:17:18.240

SOURCES RELEASE DATE

db:VULMONid:CVE-2020-1108date:2020-05-21T00:00:00
db:PACKETSTORMid:158007date:2020-06-10T15:06:32
db:PACKETSTORMid:158019date:2020-06-10T15:11:03
db:PACKETSTORMid:157702date:2020-05-14T20:53:30
db:PACKETSTORMid:157794date:2020-05-21T16:41:39
db:PACKETSTORMid:157788date:2020-05-21T16:34:50
db:PACKETSTORMid:158021date:2020-06-10T15:11:23
db:PACKETSTORMid:157704date:2020-05-14T20:53:58
db:CNNVDid:CNNVD-202005-570date:2020-05-12T00:00:00
db:JVNDBid:JVNDB-2020-006114date:2020-06-30T00:00:00
db:NVDid:CVE-2020-1108date:2020-05-21T23:15:14.867