dotnet / announcements

Subscribe to this repo to be notified of Announcements and changes in .NET Core.
Creative Commons Attribution 4.0 International
1.29k stars 44 forks source link

Microsoft Security Advisory CVE-2020-8927 | .NET Remote Code Execution Vulnerability #211

Open dcwhittaker opened 2 years ago

dcwhittaker commented 2 years ago

Microsoft Security Advisory CVE-2020-8927 | .NET Remote Code Execution Vulnerability

Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0 and .NET Core 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exists in .NET 5.0 and .NET Core 3.1 where a buffer overflow exists in the Brotli library versions prior to 1.0.8.

Discussion

Discussion for this issue can be found at https://github.com/dotnet/runtime/issues/66346

Mitigation factors

Microsoft has not identified any mitigating factors for this vulnerability.

Affected software