Bug 1933741 (CVE-2021-24112) - CVE-2021-24112 dotnet: Remote Code Execution Vulnerability
Summary: CVE-2021-24112 dotnet: Remote Code Execution Vulnerability
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2021-24112
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1933745
TreeView+ depends on / blocked
 
Reported: 2021-03-01 15:31 UTC by Marian Rehak
Modified: 2023-07-17 19:42 UTC (History)
7 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in dotnet. When a .NET application utilizing libgdiplus on a non-Windows system accepts input, this flaw allows an attacker to send a specially crafted request that could result in remote code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Clone Of:
Environment:
Last Closed: 2021-04-13 21:26:13 UTC
Embargoed:


Attachments (Terms of Use)

Description Marian Rehak 2021-03-01 15:31:18 UTC
When a .NET application utilizing libgdiplus on a non-Windows system accepts input, an attacker could send a specially crafted request that could result in remote code execution.

Reference:

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-24112

Comment 1 RaTasha Tillery-Smith 2021-03-03 13:03:14 UTC
External References:

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-24112


Note You need to log in before you can comment on or make changes to this bug.