-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2020.2010
        .NET Core 3.1 on Red Hat Enterprise Linux 8 security update
                               10 June 2020

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           .NET Core 3.1 on Red Hat Enterprise Linux 8
Publisher:         Red Hat
Operating System:  Red Hat Enterprise Linux Server 8
                   Red Hat Enterprise Linux WS/Desktop 8
                   Red Hat
Impact/Access:     Denial of Service -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2020-1108  

Reference:         ASB-2020.0098
                   ESB-2020.1982
                   ESB-2020.1814
                   ESB-2020.1691

Original Bulletin: 
   https://access.redhat.com/errata/RHSA-2020:2450

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Important: .NET Core 3.1 on Red Hat Enterprise Linux 8 security update
Advisory ID:       RHSA-2020:2450-01
Product:           Red Hat Enterprise Linux
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:2450
Issue date:        2020-06-09
CVE Names:         CVE-2020-1108 
=====================================================================

1. Summary:

An update for .NET Core 3.1 is now available for Red Hat Enterprise Linux
8.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AppStream (v. 8) - x86_64

3. Description:

.NET Core is a managed-software framework. It implements a subset of the
.NET framework APIs and several new APIs, and it includes a CLR
implementation.

New versions of .NET Core that address a security vulnerability are now
available. The updated versions are .NET Core SDK 3.1.105 and .NET Core
Runtime 3.1.5.

Security Fixes:

* dotnet: Denial of service via untrusted input (CVE-2020-1108)

This is an additional update to comprehensively address CVE-2020-1108.

Default inclusions for applications built with .NET Core have been updated
to reference the newest versions and their security fixes.

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1827643 - CVE-2020-1108 dotnet: Denial of service via untrusted input

6. Package List:

Red Hat Enterprise Linux AppStream (v. 8):

Source:
dotnet3.1-3.1.105-2.el8_2.src.rpm

x86_64:
aspnetcore-runtime-3.1-3.1.5-2.el8_2.x86_64.rpm
aspnetcore-targeting-pack-3.1-3.1.5-2.el8_2.x86_64.rpm
dotnet-3.1.105-2.el8_2.x86_64.rpm
dotnet-apphost-pack-3.1-3.1.5-2.el8_2.x86_64.rpm
dotnet-apphost-pack-3.1-debuginfo-3.1.5-2.el8_2.x86_64.rpm
dotnet-host-3.1.5-2.el8_2.x86_64.rpm
dotnet-host-debuginfo-3.1.5-2.el8_2.x86_64.rpm
dotnet-hostfxr-3.1-3.1.5-2.el8_2.x86_64.rpm
dotnet-hostfxr-3.1-debuginfo-3.1.5-2.el8_2.x86_64.rpm
dotnet-runtime-3.1-3.1.5-2.el8_2.x86_64.rpm
dotnet-runtime-3.1-debuginfo-3.1.5-2.el8_2.x86_64.rpm
dotnet-sdk-3.1-3.1.105-2.el8_2.x86_64.rpm
dotnet-sdk-3.1-debuginfo-3.1.105-2.el8_2.x86_64.rpm
dotnet-targeting-pack-3.1-3.1.5-2.el8_2.x86_64.rpm
dotnet-templates-3.1-3.1.105-2.el8_2.x86_64.rpm
dotnet3.1-debuginfo-3.1.105-2.el8_2.x86_64.rpm
dotnet3.1-debugsource-3.1.105-2.el8_2.x86_64.rpm
netstandard-targeting-pack-2.1-3.1.105-2.el8_2.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2020-1108
https://access.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXt//WtzjgjWX9erEAQid7A//TJfL0nbaOAkPD8J7oi+kfXCv5qOuXsFP
1zbqo3fpY4lXawgUXwxXvZ9xe55n7D8X4lLQf8YbfjUDkVbIZwvPdJyGXHlSk5qR
TyiiFhclhdvvqVQ+gAKk71nIkPBKaD42ZmMunRklZHsulbMrJBCqd7VEZ5LFqMMz
hNKBdF0YoUGaVA5xF9pqty4yfULNH7DPb5MiLrC4lrCZglAAvsCJ2nventaZhKLm
6cQHHI6yXRzrZxsJkImJs1CRN4LBSmN239hxEk8Ng2FbyQgj4DvGC0T1trKCSb0K
PLNSMryBiJeQdA0/c0aIrtq0RFCxtmS6RKRKD9dkcGKchMmXpGyPVkBwNjJ8WhKd
3O5l8dY32cbdOSPlziXej415gzlt48t/in3r+iHQ1YCXqSlzNP4L855o/XRO8s3J
wWBz+8SkIAaj6VkeNsZMu0MbSD8RYjPQ+UCmijFiK5ffJFPQY8U08H9mYYhcOaMw
i26uNMlMjuZclYrppJjgZw0kPfKmHsVGBDra5WugWPQJvEqp6h9tcs5XwTBOh/1+
WbcoETJ+D1uF16LAw6B60oVAErwCJ6g5WP0DEKYEyzYNnJa8Bla0wptGAKuyNDHx
pvFieRF1Vg8F4lS5cYa2Uw6Wh2aJOrOuu41/t+AXj9+R+MhakNSQ2iaDpB0LP5Cw
AJBoL3Nb5no=
=Uec3
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXuBgMONLKJtyKPYoAQhqcw/8D7+ndT0sI4msoaoiz2hzApytzoAD6YYb
MiP8qH2XuhXFFHn6NUEJ3dB1lGv+nnAPLbVeRXYafwsaz6FURjknnDIHhu/lPQvB
1BHa8HWw5KXo1dCY6l3oIKEzVEgQTvSNCn+HomoxZm0fjEvbl0MGLJKvVGGa6wOh
FkkWkFG9SkEMkDUK7CBorZskb4peKVBtZhUhzBPFj4SsjeeD5E0XlCTF3HMb2Txm
wcr+YstDUwNreh3kUcYRdO4OY8ujhnT8bG3bW6k93bpvLr7dKZlir1cBaaW/U/Vr
pybsUJ97eocZfIo4qadtrwq61ChxT9Zeo/4jS2AUQw0fX8EAvBQCfKFlIMCvnz4j
kdRorkPhpfgLfaLzKhs9rp5wXSAeiphFoNsIwfGmEAxx3xKpMnNDywCUjhJ3IVL8
f2P4yB78Zge7gYarFIorWzpl5bqeQBBTcdEyOm/FhImsk4EWl95jglUM8TlBpCJQ
nDIQPINb4KsKUrBY2jGc+HBQWvMe+x3BM3SRfQnW1CWLDXxFTO6WS36bld9eLe0O
zZ8e3rG9J6XB1sSJwjw7aI7XEOz/akWThRsvmOFPoYTYsK9NsdQ+pem040AzPb+z
prV0iTKZ45eCtFl1NP8lL7J+IwV3EzbSniKBZyoESbUpt4yg+pT7/B31BjjKZkS2
WXZ+yIkmnbc=
=7SOg
-----END PGP SIGNATURE-----