CVE-2023-36049 - Arbitrary File Write and Deletion Vulnerability: FormatFtpCommand Microsoft .NET FormatFtpCommand CRLF Injection Arbitrary File Write and Deletion Vulnerability Affected versions: .NET 6.0 .NET 7.0 .NET 8.0
This CVE is public now: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36049
Created dotnet6.0 tracking bugs for this issue: Affects: fedora-all [bug 2249767] Created dotnet7.0 tracking bugs for this issue: Affects: fedora-all [bug 2249768]
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:7253 https://access.redhat.com/errata/RHSA-2023:7253
This issue has been addressed in the following products: .NET Core on Red Hat Enterprise Linux Via RHSA-2023:7259 https://access.redhat.com/errata/RHSA-2023:7259
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:7255 https://access.redhat.com/errata/RHSA-2023:7255
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:7257 https://access.redhat.com/errata/RHSA-2023:7257
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:7254 https://access.redhat.com/errata/RHSA-2023:7254
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:7256 https://access.redhat.com/errata/RHSA-2023:7256
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:7258 https://access.redhat.com/errata/RHSA-2023:7258