UbuntuUpdates.org

Package "dotnet-runtime-7.0"

Name: dotnet-runtime-7.0

Description:

dotNET runtime

Latest version: 7.0.117-0ubuntu1~23.10.1
Release: mantic (23.10)
Level: security
Repository: universe
Head package: dotnet7
Homepage: https://dot.net/core

Links


Download "dotnet-runtime-7.0"


Other versions of "dotnet-runtime-7.0" in Mantic

Repository Area Version
base universe 7.0.110-0ubuntu1
updates universe 7.0.117-0ubuntu1~23.10.2
proposed universe 7.0.118-0ubuntu1~23.10.1

Changelog

Version: 7.0.117-0ubuntu1~23.10.1 2024-03-12 19:06:56 UTC

  dotnet7 (7.0.117-0ubuntu1~23.10.1) mantic-security; urgency=medium

  * New upstream release
  * SECURITY UPDATE: denial of service
    - CVE-2024-21392: DoS in .NET Core / YARP HTTP / 2 WebSocket support.

 -- Ian Constantin <email address hidden> Fri, 08 Mar 2024 10:35:31 +0200

Source diff to previous version

Version: 7.0.116-0ubuntu1~23.10.1 2024-02-13 22:06:52 UTC

  dotnet7 (7.0.116-0ubuntu1~23.10.1) mantic-security; urgency=medium

  * New upstream release
  * SECURITY UPDATE: denial of service
    - CVE-2024-21386: denial of service vector in SignalR server.
  * SECURITY UPDATE: denial of service
    - CVE-2024-21404: .NET with OpenSSL support is vulnerable to a denial of
      service when parsing X509 certificates.

 -- Ian Constantin <email address hidden> Thu, 08 Feb 2024 13:54:58 +0200

Source diff to previous version
CVE-2024-21386 .NET Denial of Service Vulnerability
CVE-2024-21404 .NET Denial of Service Vulnerability

Version: 7.0.115-0ubuntu1~23.10.1 2024-01-11 15:07:11 UTC

  dotnet7 (7.0.115-0ubuntu1~23.10.1) mantic-security; urgency=medium

  * New upstream release
  * SECURITY UPDATE: validation bypass
    - CVE-2024-0057: X509 Certificates - validation bypass across Azure
  * SECURITY UPDATE: denial of service
    - CVE-2024-21319: Azure Identity - Pre-Authentication DoS in JWT

 -- Ian Constantin <email address hidden> Sat, 06 Jan 2024 18:09:54 +0200

Source diff to previous version
CVE-2024-0057 NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
CVE-2024-21319 Microsoft Identity Denial of service vulnerability

Version: 7.0.114-0ubuntu1~23.10.1 2023-11-14 21:09:49 UTC

  dotnet7 (7.0.114-0ubuntu1~23.10.1) mantic-security; urgency=medium

  [ Nishit Majithia ]
  * New upstream release
  * SECURITY UPDATE: security feature bypass
    - CVE-2023-36558: Security Feature Bypass in Blazor forms
  * SECURITY UPDATE: Arbitrary File Write and Deletion
    - CVE-2023-36049: Microsoft .NET FormatFtpCommand CRLF Injection
      Arbitrary File Write and Deletion

 -- Ian Constantin <email address hidden> Mon, 13 Nov 2023 16:08:21 +0200

Source diff to previous version

Version: 7.0.113-0ubuntu1~23.10.1 2023-10-25 05:12:41 UTC

  dotnet7 (7.0.113-0ubuntu1~23.10.1) mantic-security; urgency=medium

  * New upstream release
  * SECURITY REGRESSION: regression update (LP: #2040208)
    - Addresses a regression previously introduced by the fix for
      CVE-2023-36799.

 -- Ian Constantin <email address hidden> Tue, 24 Oct 2023 10:53:54 +0300

2040208 Update to 7.0.113
CVE-2023-36799 .NET Core and Visual Studio Denial of Service Vulnerability



About   -   Send Feedback to @ubuntu_updates