A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.
{
"binaries": [
{
"binary_name": "aspnetcore-runtime-7.0",
"binary_version": "7.0.119-0ubuntu1~22.04.1"
},
{
"binary_name": "aspnetcore-targeting-pack-7.0",
"binary_version": "7.0.119-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-apphost-pack-7.0",
"binary_version": "7.0.119-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-host-7.0",
"binary_version": "7.0.119-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-hostfxr-7.0",
"binary_version": "7.0.119-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-runtime-7.0",
"binary_version": "7.0.119-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-sdk-7.0",
"binary_version": "7.0.119-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-sdk-7.0-source-built-artifacts",
"binary_version": "7.0.119-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-targeting-pack-7.0",
"binary_version": "7.0.119-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-templates-7.0",
"binary_version": "7.0.119-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet7",
"binary_version": "7.0.119-0ubuntu1~22.04.1"
},
{
"binary_name": "netstandard-targeting-pack-2.1-7.0",
"binary_version": "7.0.119-0ubuntu1~22.04.1"
}
]
}