GHSA-6xh7-4v2w-36q6

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-6xh7-4v2w-36q6/GHSA-6xh7-4v2w-36q6.json
Aliases
  • CVE-2017-0247
Published
2018-10-16T19:58:05Z
Modified
2022-06-10T02:17:51.623993Z
Details

A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range.

References

Affected packages

NuGet / Microsoft.AspNetCore.Mvc

Microsoft.AspNetCore.Mvc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc

Microsoft.AspNetCore.Mvc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.Core

Microsoft.AspNetCore.Mvc.Core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.Core

Microsoft.AspNetCore.Mvc.Core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / System.Net.Http

System.Net.Http

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.1.1
Fixed
4.1.2

Affected versions

4.*

4.1.1

NuGet / System.Net.Http

System.Net.Http

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.1
Fixed
4.3.2

Affected versions

4.*

4.3.1

NuGet / System.Text.Encodings.Web

System.Text.Encodings.Web

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.0.1

Affected versions

4.*

4.0.0

NuGet / System.Text.Encodings.Web

System.Text.Encodings.Web

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.0
Fixed
4.3.1

Affected versions

4.*

4.3.0

NuGet / System.Net.Http.WinHttpHandler

System.Net.Http.WinHttpHandler

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.0.1

Affected versions

4.*

4.0.0

NuGet / System.Net.Http.WinHttpHandler

System.Net.Http.WinHttpHandler

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.0
Fixed
4.5.4

Affected versions

4.*

4.3.0
4.3.1
4.3.2
4.3.3
4.4.0
4.4.0-preview1-25305-02
4.4.0-preview2-25405-01
4.5.0
4.5.0-preview1-26216-02
4.5.0-preview2-26406-04
4.5.0-rc1
4.5.1
4.5.2
4.5.2-servicing-27114-05
4.5.3

NuGet / System.Net.Security

System.Net.Security

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.0.1

Affected versions

4.*

4.0.0

NuGet / System.Net.Security

System.Net.Security

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.0
Fixed
4.3.1

Affected versions

4.*

4.3.0

NuGet / System.Net.WebSockets.Client

System.Net.WebSockets.Client

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.0.1

Affected versions

4.*

4.0.0

NuGet / System.Net.WebSockets.Client

System.Net.WebSockets.Client

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.0
Fixed
4.3.1

Affected versions

4.*

4.3.0

NuGet / Microsoft.AspNetCore.Mvc.Abstractions

Microsoft.AspNetCore.Mvc.Abstractions

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.Abstractions

Microsoft.AspNetCore.Mvc.Abstractions

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.ApiExplorer

Microsoft.AspNetCore.Mvc.ApiExplorer

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.ApiExplorer

Microsoft.AspNetCore.Mvc.ApiExplorer

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.Cors

Microsoft.AspNetCore.Mvc.Cors

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.Cors

Microsoft.AspNetCore.Mvc.Cors

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.DataAnnotations

Microsoft.AspNetCore.Mvc.DataAnnotations

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.DataAnnotations

Microsoft.AspNetCore.Mvc.DataAnnotations

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.Formatters.Json

Microsoft.AspNetCore.Mvc.Formatters.Json

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.Formatters.Json

Microsoft.AspNetCore.Mvc.Formatters.Json

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.Formatters.Xml

Microsoft.AspNetCore.Mvc.Formatters.Xml

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.Formatters.Xml

Microsoft.AspNetCore.Mvc.Formatters.Xml

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.Localization

Microsoft.AspNetCore.Mvc.Localization

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.Localization

Microsoft.AspNetCore.Mvc.Localization

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.Razor.Host

Microsoft.AspNetCore.Mvc.Razor.Host

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.Razor.Host

Microsoft.AspNetCore.Mvc.Razor.Host

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.Razor

Microsoft.AspNetCore.Mvc.Razor

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.Razor

Microsoft.AspNetCore.Mvc.Razor

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.TagHelpers

Microsoft.AspNetCore.Mvc.TagHelpers

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.TagHelpers

Microsoft.AspNetCore.Mvc.TagHelpers

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.ViewFeatures

Microsoft.AspNetCore.Mvc.ViewFeatures

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.ViewFeatures

Microsoft.AspNetCore.Mvc.ViewFeatures

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.WebApiCompatShim

Microsoft.AspNetCore.Mvc.WebApiCompatShim

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.WebApiCompatShim

Microsoft.AspNetCore.Mvc.WebApiCompatShim

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2