-----BEGIN PGP SIGNATURE-----
wsD5BAABCAAjFiEEcxdv4gCCE8W9nrt5a1+PL+d1/EgFAmVVLbkFAwAAAAAACgkQa1+PL+d1/Egv
FAwAmB94DrQqcOA1lYE0edU2r6JXbXJ6hSTJOVz5f1KxL/i2EoKRPTqNfX1PM7hJ8zc84cWfWWkw
OOTvsGwlikmurRZQLG/luGORwtoggVLWgw9eOA17QatQSl46ddpWup8wnA4NgaF6ERwNiFBPod30
uml9z367+Gtd1S5QlXcUqcA26zLtTgkuz+KGnRaLQYJAwSBdzb7Wa7H0tG9PEvL8HvF8lokEjlwT
DtWhiFbvI5bNBQrOrmaY64sCYW+CHZ4y+xJFshvJeeXO4MnrUivW/gsjsM93+8oXV9KAR3kIlL1/
2OuL6+enbmaRIMFl7Z77RbEGy3LxAcbWo8E95Anhknj7G1SVktAAf9fP1dUVHoyTc3h0BgBvJP6B
3KvHKNx5odW/g132fuqnM2tlVOtIxQJDbnIrgNQXG+mmlLRg8Gpx0eZp168H49EFChx+eBCOmx+Z
mh7DBlDTXRlLh7YqBWYi5OrX6gq56LyHE/I6i/lyy2MyTiXX40yZp6kJ9VhH
=l6bl
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6480-1
November 15, 2023
dotnet6, dotnet7, dotnet8 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 23.04
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in .NET.
Software Description:
- dotnet6: dotNET CLI tools and runtime
- dotnet7: dotNET CLI tools and runtime
- dotnet8: dotNET CLI tools and runtime
Details:
Barry Dorrans discovered that .NET did not properly implement certain
security features for Blazor server forms. An attacker could possibly
use this issue to bypass validation, which could trigger unintended
actions. (CVE-2023-36558)
Piotr Bazydlo discovered that .NET did not properly handle untrusted
URIs provided to System.Net.WebRequest.Create. An attacker could possibly
use this issue to inject arbitrary commands to backend FTP servers.
(CVE-2023-36049)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
aspnetcore-runtime-6.0 6.0.125-0ubuntu1~23.10.1
aspnetcore-runtime-7.0 7.0.114-0ubuntu1~23.10.1
aspnetcore-runtime-8.0 8.0.0-0ubuntu1~23.10.1
dotnet-host 6.0.125-0ubuntu1~23.10.1
dotnet-host-7.0 7.0.114-0ubuntu1~23.10.1
dotnet-host-8.0 8.0.0-0ubuntu1~23.10.1
dotnet-hostfxr-6.0 6.0.125-0ubuntu1~23.10.1
dotnet-hostfxr-7.0 7.0.114-0ubuntu1~23.10.1
dotnet-hostfxr-8.0 8.0.0-0ubuntu1~23.10.1
dotnet-runtime-6.0 6.0.125-0ubuntu1~23.10.1
dotnet-runtime-7.0 7.0.114-0ubuntu1~23.10.1
dotnet-runtime-8.0 8.0.0-0ubuntu1~23.10.1
dotnet-sdk-6.0 6.0.125-0ubuntu1~23.10.1
dotnet-sdk-7.0 7.0.114-0ubuntu1~23.10.1
dotnet-sdk-8.0 8.0.100-0ubuntu1~23.10.1
dotnet6 6.0.125-0ubuntu1~23.10.1
dotnet7 7.0.114-0ubuntu1~23.10.1
dotnet8 8.0.100-8.0.0-0ubuntu1~23.10.1
Ubuntu 23.04:
aspnetcore-runtime-6.0 6.0.125-0ubuntu1~23.04.1
aspnetcore-runtime-7.0 7.0.114-0ubuntu1~23.04.1
dotnet-host 6.0.125-0ubuntu1~23.04.1
dotnet-host-7.0 7.0.114-0ubuntu1~23.04.1
dotnet-hostfxr-6.0 6.0.125-0ubuntu1~23.04.1
dotnet-hostfxr-7.0 7.0.114-0ubuntu1~23.04.1
dotnet-runtime-6.0 6.0.125-0ubuntu1~23.04.1
dotnet-runtime-7.0 7.0.114-0ubuntu1~23.04.1
dotnet-sdk-6.0 6.0.125-0ubuntu1~23.04.1
dotnet-sdk-7.0 7.0.114-0ubuntu1~23.04.1
dotnet6 6.0.125-0ubuntu1~23.04.1
dotnet7 7.0.114-0ubuntu1~23.04.1
Ubuntu 22.04 LTS:
aspnetcore-runtime-6.0 6.0.125-0ubuntu1~22.04.1
aspnetcore-runtime-7.0 7.0.114-0ubuntu1~22.04.1
dotnet-host 6.0.125-0ubuntu1~22.04.1
dotnet-host-7.0 7.0.114-0ubuntu1~22.04.1
dotnet-hostfxr-6.0 6.0.125-0ubuntu1~22.04.1
dotnet-hostfxr-7.0 7.0.114-0ubuntu1~22.04.1
dotnet-runtime-6.0 6.0.125-0ubuntu1~22.04.1
dotnet-runtime-7.0 7.0.114-0ubuntu1~22.04.1
dotnet-sdk-6.0 6.0.125-0ubuntu1~22.04.1
dotnet-sdk-7.0 7.0.114-0ubuntu1~22.04.1
dotnet6 6.0.125-0ubuntu1~22.04.1
dotnet7 7.0.114-0ubuntu1~22.04.1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6480-1
CVE-2023-36049, CVE-2023-36558
Package Information:
https://launchpad.net/ubuntu/+source/dotnet6/6.0.125-0ubuntu1~23.10.1
https://launchpad.net/ubuntu/+source/dotnet7/7.0.114-0ubuntu1~23.10.1
https://launchpad.net/ubuntu/+source/dotnet8/8.0.100-8.0.0-0ubuntu1~23.10.1
https://launchpad.net/ubuntu/+source/dotnet6/6.0.125-0ubuntu1~23.04.1
https://launchpad.net/ubuntu/+source/dotnet7/7.0.114-0ubuntu1~23.04.1
https://launchpad.net/ubuntu/+source/dotnet6/6.0.125-0ubuntu1~22.04.1
https://launchpad.net/ubuntu/+source/dotnet7/7.0.114-0ubuntu1~22.04.1
No comments:
Post a Comment