Bug 2303442 - CVE-2024-37890 dotnet7.0: denial of service when handling a request with many HTTP headers [fedora-all]
Summary: CVE-2024-37890 dotnet7.0: denial of service when handling a request with many...
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: dotnet7.0
Version: 40
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Omair Majid
QA Contact:
URL:
Whiteboard: {"flaws": ["d03c9b4d-858d-4cb9-988b-9...
Depends On:
Blocks: CVE-2024-37890
TreeView+ depends on / blocked
 
Reported: 2024-08-07 11:33 UTC by Dhananjay Arunesh
Modified: 2024-08-07 21:10 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2024-08-07 21:10:48 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Dhananjay Arunesh 2024-08-07 11:33:04 UTC
More information about this security flaw is available in the following bug:

https://bugzilla.redhat.com/show_bug.cgi?id=2292777

Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Omair Majid 2024-08-07 21:10:48 UTC
.NET 7 (dotnet7.0) has reached its End of Life on May 2024: https://dotnet.microsoft.com/en-us/platform/support/policy/dotnet-core#lifecycle. We have no desire, skills or resources to continue maintaining it in Fedora. That means this CVE (assuming it's valid) will not be fixed.

We have dropped .NET 7 from upcoming versions of Fedora to reflect that it's no longer being maintained. But we can't remove it from existing releases of Fedora.


Note You need to log in before you can comment on or make changes to this bug.