UbuntuUpdates.org

Package "dotnet-targeting-pack-6.0"

Name: dotnet-targeting-pack-6.0

Description:

Internal - targeting pack for Microsoft.NETCore.App 6.0

Latest version: 6.0.126-0ubuntu1~23.04.1
Release: lunar (23.04)
Level: security
Repository: universe
Head package: dotnet6
Homepage: https://dot.net/core

Links


Download "dotnet-targeting-pack-6.0"


Other versions of "dotnet-targeting-pack-6.0" in Lunar

Repository Area Version
base universe 6.0.116-0ubuntu2
updates universe 6.0.126-0ubuntu1~23.04.1

Changelog

Version: 6.0.126-0ubuntu1~23.04.1 2024-01-11 15:07:02 UTC

  dotnet6 (6.0.126-0ubuntu1~23.04.1) lunar-security; urgency=medium

  * New upstream release
  * SECURITY UPDATE: validation bypass
    - CVE-2024-0057: X509 Certificates - Validation Bypass across Azure
  * SECURITY UPDATE: denial of service
    - CVE-2024-21319: Azure Identity - Pre-Authentication DoS in JWT

 -- Nishit Majithia <email address hidden> Thu, 04 Jan 2024 12:13:51 +0530

Source diff to previous version
CVE-2024-0057 NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
CVE-2024-21319 Microsoft Identity Denial of service vulnerability

Version: 6.0.125-0ubuntu1~23.04.1 2023-11-14 21:09:47 UTC

  dotnet6 (6.0.125-0ubuntu1~23.04.1) lunar-security; urgency=medium

  [ Nishit Majithia ]
  * New upstream release
  * SECURITY UPDATE: security feature bypass
    - CVE-2023-36558: Security Feature Bypass in Blazor forms
  * SECURITY UPDATE: Arbitrary File Write and Deletion
    - CVE-2023-36049: Microsoft .NET FormatFtpCommand CRLF Injection
      Arbitrary File Write and Deletion

 -- Ian Constantin <email address hidden> Mon, 13 Nov 2023 15:37:56 +0200

Source diff to previous version

Version: 6.0.124-0ubuntu1~23.04.1 2023-10-25 05:12:41 UTC

  dotnet6 (6.0.124-0ubuntu1~23.04.1) lunar-security; urgency=medium

  * New upstream release
  * SECURITY REGRESSION: regression update (LP: #2040207)
    - Addresses a regression previously introduced by the fix for
      CVE-2023-36799

 -- Nishit Majithia <email address hidden> Mon, 23 Oct 2023 12:19:45 +0530

Source diff to previous version
2040207 Update to 6.0.124
CVE-2023-36799 .NET Core and Visual Studio Denial of Service Vulnerability

Version: 6.0.123-0ubuntu1~23.04.1 2023-10-10 19:07:13 UTC

  dotnet6 (6.0.123-0ubuntu1~23.04.1) lunar-security; urgency=medium

  * New upstream release.
  * SECURITY UPDATE: denial of service
    - CVE-2023-44487: Denial of service - Kestrel server.

 -- Ian Constantin <email address hidden> Wed, 04 Oct 2023 23:02:20 +0300

Source diff to previous version

Version: 6.0.122-0ubuntu1~23.04.1 2023-09-12 19:08:10 UTC

  dotnet6 (6.0.122-0ubuntu1~23.04.1) lunar-security; urgency=medium

  * New upstream release.
  * SECURITY UPDATE: denial of service
    - CVE-2023-36799: A vulnerability exists in .NET when processing X.509
      certificates that may result in Denial of Service.
  * debian/tests/cli-metadata-should-be-correct: updated regex for the Host
    Runtime Version check.

 -- Nishit Majithia <email address hidden> Tue, 05 Sep 2023 12:29:44 +0530




About   -   Send Feedback to @ubuntu_updates