{"id":"GHSA-rxg9-xrhp-64gj","summary":".NET Core Remote Code Execution Vulnerability","details":"A remote code execution vulnerability exists when parsing certain types of graphics files. This vulnerability only exists on systems running on MacOS or Linux. This CVE ID is unique from CVE-2021-26701.","aliases":["BIT-dotnet-2021-24112","BIT-dotnet-sdk-2021-24112","CVE-2021-24112"],"modified":"2024-11-29T05:26:26.867037Z","published":"2022-05-24T17:43:19Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-10-25T17:35:53Z","nvd_published_at":"2021-02-25T23:15:00Z","cwe_ids":[],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-24112"},{"type":"WEB","url":"https://github.com/dotnet/announcements/issues/176"},{"type":"WEB","url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-24112"}],"affected":[{"package":{"name":"System.Drawing.Common","ecosystem":"NuGet","purl":"pkg:nuget/System.Drawing.Common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.7.2"}]}],"versions":["4.0.0","4.5.0","4.5.0-preview1-25718-03","4.5.0-preview1-25914-04","4.5.0-preview1-26216-02","4.5.0-preview2-26406-04","4.5.0-rc1","4.5.1","4.5.2","4.6.0","4.6.1","4.6.2","4.7.0","4.7.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rxg9-xrhp-64gj/GHSA-rxg9-xrhp-64gj.json"}},{"package":{"name":"System.Drawing.Common","ecosystem":"NuGet","purl":"pkg:nuget/System.Drawing.Common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.0.3"}]}],"versions":["5.0.0","5.0.1","5.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rxg9-xrhp-64gj/GHSA-rxg9-xrhp-64gj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}