[USN-6438-1] .NET vulnerabilities

Severity High
Affected Packages 24
CVEs 2

Several security issues were fixed in dotnet6, dotnet7.

Kevin Jones discovered that .NET did not properly process certain
X.509 certificates. An attacker could possibly use this issue to
cause a denial of service. (CVE-2023-36799)

It was discovered that the .NET Kestrel web server did not properly
handle HTTP/2 requests. A remote attacker could possibly use this
issue to cause a denial of service. (CVE-2023-44487)

Package Affected Version
pkg:deb/ubuntu/netstandard-targeting-pack-2.1?distro=mantic < 6.0.123-0ubuntu1
pkg:deb/ubuntu/netstandard-targeting-pack-2.1-7.0?distro=mantic < 7.0.112-0ubuntu1
pkg:deb/ubuntu/dotnet7?distro=mantic < 7.0.112-0ubuntu1
pkg:deb/ubuntu/dotnet6?distro=mantic < 6.0.123-0ubuntu1
pkg:deb/ubuntu/dotnet-templates-7.0?distro=mantic < 7.0.112-0ubuntu1
pkg:deb/ubuntu/dotnet-templates-6.0?distro=mantic < 6.0.123-0ubuntu1
pkg:deb/ubuntu/dotnet-targeting-pack-7.0?distro=mantic < 7.0.112-0ubuntu1
pkg:deb/ubuntu/dotnet-targeting-pack-6.0?distro=mantic < 6.0.123-0ubuntu1
pkg:deb/ubuntu/dotnet-sdk-7.0?distro=mantic < 7.0.112-0ubuntu1
pkg:deb/ubuntu/dotnet-sdk-7.0-source-built-artifacts?distro=mantic < 7.0.112-0ubuntu1
pkg:deb/ubuntu/dotnet-sdk-6.0?distro=mantic < 6.0.123-0ubuntu1
pkg:deb/ubuntu/dotnet-sdk-6.0-source-built-artifacts?distro=mantic < 6.0.123-0ubuntu1
pkg:deb/ubuntu/dotnet-runtime-7.0?distro=mantic < 7.0.112-0ubuntu1
pkg:deb/ubuntu/dotnet-runtime-6.0?distro=mantic < 6.0.123-0ubuntu1
pkg:deb/ubuntu/dotnet-hostfxr-7.0?distro=mantic < 7.0.112-0ubuntu1
pkg:deb/ubuntu/dotnet-hostfxr-6.0?distro=mantic < 6.0.123-0ubuntu1
pkg:deb/ubuntu/dotnet-host?distro=mantic < 6.0.123-0ubuntu1
pkg:deb/ubuntu/dotnet-host-7.0?distro=mantic < 7.0.112-0ubuntu1
pkg:deb/ubuntu/dotnet-apphost-pack-7.0?distro=mantic < 7.0.112-0ubuntu1
pkg:deb/ubuntu/dotnet-apphost-pack-6.0?distro=mantic < 6.0.123-0ubuntu1
pkg:deb/ubuntu/aspnetcore-targeting-pack-7.0?distro=mantic < 7.0.112-0ubuntu1
pkg:deb/ubuntu/aspnetcore-targeting-pack-6.0?distro=mantic < 6.0.123-0ubuntu1
pkg:deb/ubuntu/aspnetcore-runtime-7.0?distro=mantic < 7.0.112-0ubuntu1
pkg:deb/ubuntu/aspnetcore-runtime-6.0?distro=mantic < 6.0.123-0ubuntu1
ID
USN-6438-1
Severity
high
Severity from
CVE-2023-44487
URL
https://ubuntu.com/security/notices/USN-6438-1
Published
2023-10-19T16:12:40
(11 months ago)
Modified
2023-10-19T16:12:40
(11 months ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/netstandard-targeting-pack-2.1?distro=mantic ubuntu netstandard-targeting-pack-2.1 < 6.0.123-0ubuntu1 mantic
Affected pkg:deb/ubuntu/netstandard-targeting-pack-2.1-7.0?distro=mantic ubuntu netstandard-targeting-pack-2.1-7.0 < 7.0.112-0ubuntu1 mantic
Affected pkg:deb/ubuntu/dotnet7?distro=mantic ubuntu dotnet7 < 7.0.112-0ubuntu1 mantic
Affected pkg:deb/ubuntu/dotnet6?distro=mantic ubuntu dotnet6 < 6.0.123-0ubuntu1 mantic
Affected pkg:deb/ubuntu/dotnet-templates-7.0?distro=mantic ubuntu dotnet-templates-7.0 < 7.0.112-0ubuntu1 mantic
Affected pkg:deb/ubuntu/dotnet-templates-6.0?distro=mantic ubuntu dotnet-templates-6.0 < 6.0.123-0ubuntu1 mantic
Affected pkg:deb/ubuntu/dotnet-targeting-pack-7.0?distro=mantic ubuntu dotnet-targeting-pack-7.0 < 7.0.112-0ubuntu1 mantic
Affected pkg:deb/ubuntu/dotnet-targeting-pack-6.0?distro=mantic ubuntu dotnet-targeting-pack-6.0 < 6.0.123-0ubuntu1 mantic
Affected pkg:deb/ubuntu/dotnet-sdk-7.0?distro=mantic ubuntu dotnet-sdk-7.0 < 7.0.112-0ubuntu1 mantic
Affected pkg:deb/ubuntu/dotnet-sdk-7.0-source-built-artifacts?distro=mantic ubuntu dotnet-sdk-7.0-source-built-artifacts < 7.0.112-0ubuntu1 mantic
Affected pkg:deb/ubuntu/dotnet-sdk-6.0?distro=mantic ubuntu dotnet-sdk-6.0 < 6.0.123-0ubuntu1 mantic
Affected pkg:deb/ubuntu/dotnet-sdk-6.0-source-built-artifacts?distro=mantic ubuntu dotnet-sdk-6.0-source-built-artifacts < 6.0.123-0ubuntu1 mantic
Affected pkg:deb/ubuntu/dotnet-runtime-7.0?distro=mantic ubuntu dotnet-runtime-7.0 < 7.0.112-0ubuntu1 mantic
Affected pkg:deb/ubuntu/dotnet-runtime-6.0?distro=mantic ubuntu dotnet-runtime-6.0 < 6.0.123-0ubuntu1 mantic
Affected pkg:deb/ubuntu/dotnet-hostfxr-7.0?distro=mantic ubuntu dotnet-hostfxr-7.0 < 7.0.112-0ubuntu1 mantic
Affected pkg:deb/ubuntu/dotnet-hostfxr-6.0?distro=mantic ubuntu dotnet-hostfxr-6.0 < 6.0.123-0ubuntu1 mantic
Affected pkg:deb/ubuntu/dotnet-host?distro=mantic ubuntu dotnet-host < 6.0.123-0ubuntu1 mantic
Affected pkg:deb/ubuntu/dotnet-host-7.0?distro=mantic ubuntu dotnet-host-7.0 < 7.0.112-0ubuntu1 mantic
Affected pkg:deb/ubuntu/dotnet-apphost-pack-7.0?distro=mantic ubuntu dotnet-apphost-pack-7.0 < 7.0.112-0ubuntu1 mantic
Affected pkg:deb/ubuntu/dotnet-apphost-pack-6.0?distro=mantic ubuntu dotnet-apphost-pack-6.0 < 6.0.123-0ubuntu1 mantic
Affected pkg:deb/ubuntu/aspnetcore-targeting-pack-7.0?distro=mantic ubuntu aspnetcore-targeting-pack-7.0 < 7.0.112-0ubuntu1 mantic
Affected pkg:deb/ubuntu/aspnetcore-targeting-pack-6.0?distro=mantic ubuntu aspnetcore-targeting-pack-6.0 < 6.0.123-0ubuntu1 mantic
Affected pkg:deb/ubuntu/aspnetcore-runtime-7.0?distro=mantic ubuntu aspnetcore-runtime-7.0 < 7.0.112-0ubuntu1 mantic
Affected pkg:deb/ubuntu/aspnetcore-runtime-6.0?distro=mantic ubuntu aspnetcore-runtime-6.0 < 6.0.123-0ubuntu1 mantic
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...