Security Update for .NET Core (February 2021) (macOS)

critical Nessus Plugin ID 146347

Synopsis

An application installed on the remote macOS or Mac OS X host is affected by multiple vulnerabilities.

Description

The Microsoft .NET Core runtime installed on the remote macOS or Mac OS X host is missing a security update. It is, therefore, affected by multiple vulnerabilities:

- A denial of service vulnerability exists in .NET Core when creating HTTPS web requests during X509 certificate chain building. An unauthenticated, remote attacker can exploit this to cause the application to stop responding. (CVE-2021-1721)

- A remote code execution vulnerability exists in .NET Core when parsing certain types of graphics files. An unauthenticated, remote attacker can exploit this to execute arbitrary code. This vulnerability only exists on systems running on macOS or Linux. (CVE-2021-24112)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to .NET Core Runtime version 2.1.25, 3.1.2, 5.0.3 or later.

See Also

https://dotnet.microsoft.com/download/dotnet-core/2.1

https://dotnet.microsoft.com/download/dotnet-core/3.1

https://dotnet.microsoft.com/download/dotnet/5.0

https://github.com/dotnet/announcements/issues/175

https://github.com/dotnet/announcements/issues/176

http://www.nessus.org/u?2455d834

http://www.nessus.org/u?a75f459e

http://www.nessus.org/u?51c16faa

Plugin Details

Severity: Critical

ID: 146347

File Name: macosx_ms21_feb_dotnet_core.nasl

Version: 1.11

Type: local

Agent: macosx

Published: 2/9/2021

Updated: 11/29/2024

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2021-24112

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:microsoft:.net_core

Required KB Items: installed_sw/.NET Core MacOS

Exploit Ease: No known exploits are available

Patch Publication Date: 2/9/2021

Vulnerability Publication Date: 2/9/2021

Reference Information

CVE: CVE-2021-1721, CVE-2021-24112