CVE-2023-38180

Name
CVE-2023-38180
Description
.NET and Visual Studio Denial of Service Vulnerability
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vendor-advisory https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38180
MISC https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CL2L4WE5QRT7WEXANYXSKSU43APC5N2V/
MISC https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NWVZFKTLNMNKPZ755EMRYIA6GHFOWGKY/
134c704f-9b21-4f2e-91b3-4a467353bcc0 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-38180

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:microsoft:asp.net_core:2.1*:*:*:*:*:*:*:* asp.net-core >= 2.0 < 2.1.40
cpe:2.3:a:microsoft:.net:6.0.0:*:*:*:*:*:*:* .net >= 6.0.0 < 6.0.21
cpe:2.3:a:microsoft:.net:7.0.0:*:*:*:*:*:*:* .net >= 7.0.0 < 7.0.10
cpe:2.3:a:microsoft:visual_studio_2022:17.2:*:*:*:*:*:*:* visual-studio-2022 >= 17.2.0 < 17.2.18
cpe:2.3:a:microsoft:visual_studio_2022:17.4:*:*:*:*:*:*:* visual-studio-2022 >= 17.4.0 < 17.4.10
cpe:2.3:a:microsoft:visual_studio:2022:*:*:*:*:*:*:* visual-studio >= 17.6.0 < 17.6.6
cpe:2.3:a:microsoft:.net:6.0.0:-:*:*:*:*:*:* .net == None == 6.0.0
cpe:2.3:a:microsoft:.net:7.0.0:*:*:*:*:*:*:* .net == None == 7.0.0
cpe:2.3:a:microsoft:asp.net_core:2.1:*:*:*:*:*:*:* asp.net_core == None == 2.1
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* visual_studio_2022 >= 17.2.0 < 17.2.18
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* visual_studio_2022 >= 17.4.0 < 17.4.10
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* visual_studio_2022 >= 17.6.0 < 17.6.6
cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:* asp.net_core >= 2.1 < 2.1.40

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
dotnet7-runtime edge-community 7.0.10-r0 Antoine Martin (ayakael) <dev@ayakael.net> fixed
dotnet7-runtime 3.19-community 7.0.10-r0 None fixed
dotnet7-runtime 3.18-community 7.0.10-r0 Antoine Martin (ayakael) <dev@ayakael.net> fixed
dotnet7-build edge-community 7.0.110-r0 Antoine Martin (ayakael) <dev@ayakael.net> fixed
dotnet7-build 3.19-community 7.0.110-r0 None fixed
dotnet7-build 3.18-community 7.0.110-r0 Antoine Martin (ayakael) <dev@ayakael.net> fixed
dotnet6-runtime edge-community 6.0.21-r0 Antoine Martin (ayakael) <dev@ayakael.net> fixed
dotnet6-runtime 3.20-community 6.0.21-r0 None fixed
dotnet6-runtime 3.19-community 6.0.21-r0 None fixed
dotnet6-runtime 3.18-community 6.0.21-r0 Antoine Martin (ayakael) <dev@ayakael.net> fixed
dotnet6-build edge-community 6.0.121-r0 Antoine Martin (ayakael) <dev@ayakael.net> fixed
dotnet6-build 3.20-community 6.0.121-r0 None fixed
dotnet6-build 3.19-community 6.0.121-r0 None fixed
dotnet6-build 3.18-community 6.0.121-r0 Antoine Martin (ayakael) <dev@ayakael.net> fixed