CVE-2017-0247
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range.
Affected (101)
Products: Microsoft: Asp.net Model View Controller, Microsoft.aspnetcore.mvc.abstractions, Microsoft.aspnetcore.mvc.apiexplorer, Microsoft.aspnetcore.mvc.cors, Microsoft.aspnetcore.mvc.dataannotations, Microsoft.aspnetcore.mvc.formatters.json, Microsoft.aspnetcore.mvc.formatters.xml, Microsoft.aspnetcore.mvc.localization, Microsoft.aspnetcore.mvc.razor, Microsoft.aspnetcore.mvc.razor.host, Microsoft.aspnetcore.mvc.taghelpers, Microsoft.aspnetcore.mvc.viewfeatures, Microsoft.aspnetcore.mvc.webapicompatshim, System.net.http, System.net.http.winhttphandler, System.net.security, System.net.websockets.client, System.text.encodings.web
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 4.1.1 | |
| Version 4.0.1 | |
| Version 4.0.0 | |
| Version 4.0.0 | |
| Version 4.0.0 |
References (6)
Source: secure@microsoft.com
Technical DescriptionThird Party Advisory
Source: secure@microsoft.com
PatchVendor Advisory
Source: secure@microsoft.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Technical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.