Red Hat Bugzilla – Bug 1552060
CVE-2018-0875 .NET Core: Hash Collision Denial of Service
Last modified: 2018-03-15 14:24:47 EDT
Case insensitive string comparison uses an insecure hashing algorithm which can be compromised in .NET Core 1.x (Unix) and .NET Core 2.0. The attack vector could be a Dictionary which uses case invariant keys.
Acknowledgments: Name: Ben Adams (Illyriad Games)
This issue has been addressed in the following products: .NET Core on Red Hat Enterprise Linux Via RHSA-2018:0522 https://access.redhat.com/errata/RHSA-2018:0522