{"id":"GHSA-rr3c-f55v-qhv5","summary":"Denial of service vulnerability exists when .NET and .NET Core improperly process XML documents","details":"Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1.1 and 2.0 allow a denial of service vulnerability due to the way XML documents are processed, aka \".NET and .NET Core Denial Of Service Vulnerability\". This CVE is unique from CVE-2018-0765.","aliases":["CVE-2018-0764"],"modified":"2024-12-02T05:51:59.374774Z","published":"2018-10-16T17:34:00Z","database_specific":{"github_reviewed_at":"2020-06-16T21:55:37Z","nvd_published_at":"2018-01-10T01:29:00Z","cwe_ids":[],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-0764"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:0379"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rr3c-f55v-qhv5"},{"type":"WEB","url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0764"},{"type":"WEB","url":"http://www.securityfocus.com/bid/102387"},{"type":"WEB","url":"http://www.securitytracker.com/id/1040152"}],"affected":[{"package":{"name":"System.Security.Cryptography.Xml","ecosystem":"NuGet","purl":"pkg:nuget/System.Security.Cryptography.Xml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.4.2"}]}],"versions":["4.4.0","4.4.0-preview1-25305-02","4.4.0-preview2-25405-01","4.4.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-rr3c-f55v-qhv5/GHSA-rr3c-f55v-qhv5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}