GHSA-rr3c-f55v-qhv5

Suggest an improvement
Source
https://github.com/advisories/GHSA-rr3c-f55v-qhv5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-rr3c-f55v-qhv5/GHSA-rr3c-f55v-qhv5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rr3c-f55v-qhv5
Aliases
Published
2018-10-16T17:34:00Z
Modified
2023-11-08T03:59:30.908714Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Denial of service vulnerability exists when .NET and .NET Core improperly process XML documents
Details

Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1.1 and 2.0 allow a denial of service vulnerability due to the way XML documents are processed, aka ".NET and .NET Core Denial Of Service Vulnerability". This CVE is unique from CVE-2018-0765.

References

Affected packages

NuGet / System.Security.Cryptography.Xml

Package

Name
System.Security.Cryptography.Xml
View open source insights on deps.dev
Purl
pkg:nuget/System.Security.Cryptography.Xml

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.2

Affected versions

4.*

4.4.0-preview1-25305-02
4.4.0-preview2-25405-01
4.4.0
4.4.1