CVE Vulnerabilities

CVE-2024-43485

Inefficient Algorithmic Complexity

Published: Oct 08, 2024 | Modified: Oct 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

.NET and Visual Studio Denial of Service Vulnerability

Weakness

An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Affected Software

Name Vendor Start Version End Version
.net Microsoft 6.0.0 (including) 6.0.35 (excluding)
.net Microsoft 8.0.0 (including) 8.0.10 (excluding)
Dotnet6 Ubuntu jammy *
Dotnet6 Ubuntu upstream *
Dotnet7 Ubuntu jammy *
Dotnet8 Ubuntu devel *
Dotnet8 Ubuntu jammy *
Dotnet8 Ubuntu noble *
Dotnet8 Ubuntu oracular *
Dotnet8 Ubuntu upstream *
Red Hat Enterprise Linux 8 RedHat dotnet6.0-0:6.0.135-1.el8_10 *
Red Hat Enterprise Linux 8 RedHat dotnet8.0-0:8.0.110-1.el8_10 *
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support RedHat dotnet6.0-0:6.0.135-1.el8_6 *
Red Hat Enterprise Linux 8.6 Telecommunications Update Service RedHat dotnet6.0-0:6.0.135-1.el8_6 *
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions RedHat dotnet6.0-0:6.0.135-1.el8_6 *
Red Hat Enterprise Linux 8.8 Extended Update Support RedHat dotnet6.0-0:6.0.135-1.el8_8 *
Red Hat Enterprise Linux 9 RedHat dotnet6.0-0:6.0.135-1.el9_4 *
Red Hat Enterprise Linux 9 RedHat dotnet8.0-0:8.0.110-1.el9_4 *
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions RedHat dotnet6.0-0:6.0.135-1.el9_0 *
Red Hat Enterprise Linux 9.2 Extended Update Support RedHat dotnet6.0-0:6.0.135-1.el9_2 *

References