UbuntuUpdates.org

Package "dotnet8"




Name: dotnet8

Description:

.NET CLI tools and runtime

Latest version: *DELETED*
Release: mantic (23.10)
Level: updates
Repository: universe
Homepage: https://dot.net

Links


Download "dotnet8"


Other versions of "dotnet8" in Mantic

Repository Area Version
security main 8.0.105-8.0.5-0ubuntu1~23.10.1
updates main 8.0.105-8.0.5-0ubuntu1~23.10.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 8.0.100-8.0.0-0ubuntu1~23.10.1 2023-11-15 09:08:32 UTC

  dotnet8 (8.0.100-8.0.0-0ubuntu1~23.10.1) mantic-security; urgency=medium

  * New upstream release
  * SECURITY UPDATE: security feature bypass
    - CVE-2023-36558: Security Feature Bypass in Blazor forms
  * SECURITY UPDATE: Arbitrary File Write and Deletion
    - CVE-2023-36049: Microsoft .NET FormatFtpCommand CRLF Injection
      Arbitrary File Write and Deletion

 -- Ian Constantin <email address hidden> Mon, 13 Nov 2023 11:10:48 +0200

Source diff to previous version
CVE-2023-36558 ASP.NET Core - Security Feature Bypass Vulnerability
CVE-2023-36049 .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnera ...

Version: 8.0.100-8.0.0~rc2-0ubuntu1 2023-10-19 16:07:10 UTC

  dotnet8 (8.0.100-8.0.0~rc2-0ubuntu1) mantic-security; urgency=medium

  * New upstream release.
  * SECURITY UPDATE: denial of service
    - CVE-2023-44487: Denial of service - Kestrel server.
  * debian/tests/cli-metadata-should-be-correct: updated regex for the Host
    Runtime Version check.

  [ Mateus Rodrigues de Morais ]
  * debian/rules: removed uneeded sym link for
    $(DOTNET_TOP)/source-built-artifacts/Private.SourceBuilt.Prebuilts.*.tar.gz
  * debian/lintian: additional lintian overrides added.

 -- Ian Constantin <email address hidden> Wed, 18 Oct 2023 21:05:17 +0300

CVE-2023-44487 The HTTP/2 protocol allows a denial of service (server resource consum ...



About   -   Send Feedback to @ubuntu_updates