MEDIUM 6.5
GHSA-5633-f33j-c6f7
Tampering vulnerability in .NET Core
Details
A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet / Microsoft.NETCore.App
Introduced in:
2.1.0 Fixed in: 2.1.7 Fix
dotnet add package Microsoft.NETCore.App --version 2.1.7 References
- https://nvd.nist.gov/vuln/detail/CVE-2018-8416 [ADVISORY]
- https://github.com/dotnet/announcements/issues/95 [WEB]
- https://github.com/github/advisory-database/issues/302 [WEB]
- https://access.redhat.com/errata/RHSA-2018:3676 [WEB]
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8416 [WEB]