[ubuntu/oracular-security] dotnet9 9.0.100-9.0.0-0ubuntu1~24.10.1 (Accepted)

Ian Constantin ian.constantin at canonical.com
Tue Nov 12 19:16:16 UTC 2024


dotnet9 (9.0.100-9.0.0-0ubuntu1~24.10.1) oracular; urgency=medium

  * New upstream release (LP: #2087880)
  * SECURITY UPDATE: privilege escalation
    - CVE-2024-43498: an authenticated attacker could create a malicious
      extension and then wait for an authenticated user to create a new Visual
      Studio project that uses that extension. The result is that the attacker
      could gain the privileges of the user.
  * SECURITY UPDATE: denial of service
    - CVE-2024-43499: a remote unauthenticated attacker could exploit this
      vulnerability by sending specially crafted requests to a .NET vulnerable
      webapp or loading a specially crafted file into a vulnerable desktop app.
  * debian/rules, debian/eng/source_build_artifact_path.py: temporarily disable
    strict RID matching to solve build issue on plucky due to binary copying
    during archive opening.
  * debian/eng/dotnet-version.py: temporarily add '-rtm' to
    DOTNET_DEB_VERSION_RUNTIME_ONLY and DOTNET_DEB_VERSION_SDK_ONLY to fix
    version ordering issue with final release.

Date: 2024-11-12 02:44:11.690163+00:00
Changed-By: Dominik Viererbe <dominik.viererbe at canonical.com>
Signed-By: Ian Constantin <ian.constantin at canonical.com>
https://launchpad.net/ubuntu/+source/dotnet9/9.0.100-9.0.0-0ubuntu1~24.10.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the oracular-changes mailing list