dotnet3.1-3.1.419-1.el8.ML.1

エラータID: AXSA:2022-3727:07

Release date: 
Wednesday, August 24, 2022 - 07:27
Subject: 
dotnet3.1-3.1.419-1.el8.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

.NET Core is a managed-software framework. It implements a subset of the .NET
framework APIs and several new APIs, and it includes a CLR implementation.

New versions of .NET Core that address a security vulnerability are now available. The updated versions are .NET Core SDK 3.1.419 and .NET Core Runtime 3.1.25.

Security Fix(es):

* dotnet: excess memory allocation via HttpClient causes DoS (CVE-2022-23267)
* dotnet: malicious content causes high CPU and memory usage (CVE-2022-29117)
* dotnet: parsing HTML causes Denial of Service (CVE-2022-29145)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2022-23267
.NET and Visual Studio Denial of Service Vulnerability. This CVE ID is unique from CVE-2022-29117, CVE-2022-29145.
CVE-2022-29117
.NET and Visual Studio Denial of Service Vulnerability. This CVE ID is unique from CVE-2022-23267, CVE-2022-29145.
CVE-2022-29145
.NET and Visual Studio Denial of Service Vulnerability. This CVE ID is unique from CVE-2022-23267, CVE-2022-29117.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. dotnet3.1-3.1.419-1.el8.ML.1.src.rpm
    MD5: 61e878d5286ff8a0c7edaf70524f607c
    SHA-256: 80acf113f884f3d3aa1cb603dd4872b51f0aea1df449365d67057ac4961ae25a
    Size: 315.66 MB

Asianux Server 8 for x86_64
  1. aspnetcore-runtime-3.1-3.1.25-1.el8.ML.1.x86_64.rpm
    MD5: 7b0422094a2eea9e7a5c262074ea5c18
    SHA-256: dac93e6eb5320e72b47a29179a667415db7c6e5240db51f95db44cf9f2fa5b32
    Size: 6.27 MB
  2. aspnetcore-targeting-pack-3.1-3.1.25-1.el8.ML.1.x86_64.rpm
    MD5: e50f08fb308958deade29c54cdf1cb8f
    SHA-256: 1242f0856ff37b80782ae7bdced007253593065bac0a76e630f1a54639372884
    Size: 1.11 MB
  3. dotnet-apphost-pack-3.1-3.1.25-1.el8.ML.1.x86_64.rpm
    MD5: e41f0a9450fe6c9bad41e34eda6b7c2c
    SHA-256: e84c2cceb60ccde4e2fe47c9186624a118d121415715577187eb21f162a558fa
    Size: 79.83 kB
  4. dotnet-hostfxr-3.1-3.1.25-1.el8.ML.1.x86_64.rpm
    MD5: d830117030560d14d27ebd116f8f43f1
    SHA-256: 731435bbe31131cb6b53088cc449a77d981d94ea5f72c38ea5576b334e1afa61
    Size: 183.02 kB
  5. dotnet-runtime-3.1-3.1.25-1.el8.ML.1.x86_64.rpm
    MD5: df5b509877fee8629be88291d01f93be
    SHA-256: d796dae8085096c39d8dcf6767f836145b88f6a03c8ae16a4e4ab92cb5847c79
    Size: 27.05 MB
  6. dotnet-sdk-3.1-3.1.419-1.el8.ML.1.x86_64.rpm
    MD5: 67069e0b202a98d933b0ee84ecc89a0b
    SHA-256: a6d695b4ed4c6dfc8d171bf26fde16a57fd88d44a2162efc0470e8f1b4aae937
    Size: 41.79 MB
  7. dotnet-targeting-pack-3.1-3.1.25-1.el8.ML.1.x86_64.rpm
    MD5: 3c8deee0444afa07abb3e4d2d544db87
    SHA-256: 0a498f74349d82e6be77a4c0a10e94b8c6c5c7ea4f78e4a6d33b5689644e04b2
    Size: 2.02 MB
  8. dotnet-templates-3.1-3.1.419-1.el8.ML.1.x86_64.rpm
    MD5: 781e8e6b7909ddd4f843a09a8063c1ac
    SHA-256: 6f28f8fd0a419d340a2da7f0d696e552442d4361bcf3f5bd317c8827177b6b82
    Size: 2.13 MB