imPC@ndo IT

Tracker / CVE-2017-0247

CVE-2017-0247

High 7.5

A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range.

Affected products and versions

microsoft asp.net_model_view_controller
microsoft microsoft.aspnetcore.mvc.abstractions
microsoft microsoft.aspnetcore.mvc.apiexplorer
microsoft microsoft.aspnetcore.mvc.cors
microsoft microsoft.aspnetcore.mvc.dataannotations
microsoft microsoft.aspnetcore.mvc.formatters.json
microsoft microsoft.aspnetcore.mvc.formatters.xml
microsoft microsoft.aspnetcore.mvc.localization
microsoft microsoft.aspnetcore.mvc.razor
microsoft microsoft.aspnetcore.mvc.razor.host
microsoft microsoft.aspnetcore.mvc.taghelpers
microsoft microsoft.aspnetcore.mvc.viewfeatures
microsoft microsoft.aspnetcore.mvc.webapicompatshim
microsoft system.net.http
microsoft system.net.http.winhttphandler
microsoft system.net.security
microsoft system.net.websockets.client
microsoft system.text.encodings.web

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References