Input validation error in Microsoft products - CVE-2023-38180
Published: August 8, 2023 / Updated: August 10, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send specially crafted input to the application and perform a denial of service (DoS) attack.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Robotic Process Automation for Cloud Pak
Visual Studio
ASP.NET Core
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Ubuntu
Fedora
aspnetcore-runtime-6.0
aspnetcore-targeting-pack-6.0
dotnet-targeting-pack-6.0
dotnet-apphost-pack-6.0
dotnet-host
dotnet-runtime-6.0
dotnet-hostfxr-6.0
dotnet6 (Ubuntu package)
dotnet-sdk-6.0 (Ubuntu package)
dotnet-runtime-6.0 (Ubuntu package)
dotnet-hostfxr-6.0 (Ubuntu package)
dotnet-host (Ubuntu package)
aspnetcore-runtime-6.0 (Ubuntu package)
dotnet6.0
rh-dotnet60-dotnet (Red Hat package)
dotnet6.0 (Red Hat package)
netstandard-targeting-pack-2.1
dotnet-templates-6.0
dotnet
dotnet-sdk-6.0-source-built-artifacts
dotnet-sdk-6.0
dotnet7 (Ubuntu package)
dotnet-sdk-7.0 (Ubuntu package)
dotnet-runtime-7.0 (Ubuntu package)
dotnet-hostfxr-7.0 (Ubuntu package)
dotnet-host-7.0 (Ubuntu package)
aspnetcore-runtime-7.0 (Ubuntu package)
dotnet7.0 (Red Hat package)
dotnet7.0
How to mitigate CVE-2023-38180
Visual Studio - addressed in versions 17.2.18 17.2.33927.290, 17.4.10 17.4.33927.135, 17.6.6 17.6.33927.249
ASP.NET Core - update to 2.1.40
aspnetcore-runtime-6.0 - update to 6.0.21-1.0.1
aspnetcore-targeting-pack-6.0 - update to 6.0.21-1.0.1
dotnet-targeting-pack-6.0 - update to 6.0.21-1.0.1
dotnet-apphost-pack-6.0 - update to 6.0.21-1.0.1
dotnet-host - update to 6.0.21-1.0.1
dotnet-runtime-6.0 - update to 6.0.21-1.0.1
dotnet-hostfxr-6.0 - update to 6.0.21-1.0.1
dotnet6 (Ubuntu package) - addressed in versions 6.0.121-0ubuntu1~22.04.1, 6.0.121-0ubuntu1~23.04.1
dotnet-sdk-6.0 (Ubuntu package) - addressed in versions 6.0.121-0ubuntu1~22.04.1, 6.0.121-0ubuntu1~23.04.1
dotnet-runtime-6.0 (Ubuntu package) - addressed in versions 6.0.121-0ubuntu1~22.04.1, 6.0.121-0ubuntu1~23.04.1
dotnet-hostfxr-6.0 (Ubuntu package) - addressed in versions 6.0.121-0ubuntu1~22.04.1, 6.0.121-0ubuntu1~23.04.1
dotnet-host (Ubuntu package) - addressed in versions 6.0.121-0ubuntu1~22.04.1, 6.0.121-0ubuntu1~23.04.1
aspnetcore-runtime-6.0 (Ubuntu package) - addressed in versions 6.0.121-0ubuntu1~22.04.1, 6.0.121-0ubuntu1~23.04.1
dotnet6.0 - update to 6.0.121-1
rh-dotnet60-dotnet (Red Hat package) - update to 6.0.121-1.el7_9
dotnet6.0 (Red Hat package) - addressed in versions 6.0.121-1.el8_6, 6.0.121-1.el8_8, 6.0.121-1.el9_0, 6.0.121-1.el9_2
dotnet6.0 - addressed in versions 6.0.121-1.fc37, 6.0.121-1.fc38
netstandard-targeting-pack-2.1 - update to 6.0.121-1.0.1
dotnet-templates-6.0 - update to 6.0.121-1.0.1
dotnet - update to 6.0.121-1.0.1
dotnet-sdk-6.0-source-built-artifacts - update to 6.0.121-1.0.1
dotnet-sdk-6.0 - update to 6.0.121-1.0.1
dotnet7 (Ubuntu package) - addressed in versions 7.0.110-0ubuntu1~22.04.1, 7.0.110-0ubuntu1~23.04.1
dotnet-sdk-7.0 (Ubuntu package) - addressed in versions 7.0.110-0ubuntu1~22.04.1, 7.0.110-0ubuntu1~23.04.1
dotnet-runtime-7.0 (Ubuntu package) - addressed in versions 7.0.110-0ubuntu1~22.04.1, 7.0.110-0ubuntu1~23.04.1
dotnet-hostfxr-7.0 (Ubuntu package) - addressed in versions 7.0.110-0ubuntu1~22.04.1, 7.0.110-0ubuntu1~23.04.1
dotnet-host-7.0 (Ubuntu package) - addressed in versions 7.0.110-0ubuntu1~22.04.1, 7.0.110-0ubuntu1~23.04.1
aspnetcore-runtime-7.0 (Ubuntu package) - addressed in versions 7.0.110-0ubuntu1~22.04.1, 7.0.110-0ubuntu1~23.04.1
dotnet7.0 (Red Hat package) - addressed in versions 7.0.110-1.el8_8, 7.0.110-1.el9_2
dotnet7.0 - addressed in versions 7.0.110-1.fc37, 7.0.110-1.fc38
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.9, 23.0.9
External References
Related Security Bulletins
- Denial of service in ASP .NET and Visual Studio
- Ubuntu update for dotnet6
- Ubuntu update for dotnet6
- Red Hat Enterprise Linux 9.0 Extended Update Support update for .NET 6.0
- Red Hat Enterprise Linux 8.6 Extended Update Support update for .NET 6.0
- .NET Core on Red Hat Enterprise Linux update for rh-dotnet60-dotnet
- Red Hat Enterprise Linux 9 update for .NET 7.0
- Red Hat Enterprise Linux 8 update for .NET 7.0
- Red Hat Enterprise Linux 9 update for .NET 6.0
- Red Hat Enterprise Linux 8 update for .NET 6.0
- Fedora 37 update for dotnet6.0, dotnet7.0
- Fedora 38 update for dotnet6.0, dotnet7.0
- Multiple vulnerabilities in IBM Robotic Process Automation
- Amazon Linux AMI update for dotnet6.0
- Anolis OS update for dotnet6.0