|
|
Log in / Subscribe / Register

Arch Linux alert ASA-202105-23 (dotnet-sdk-3.1)

From:  Jonas Witschel via arch-security <arch-security@lists.archlinux.org>
To:  arch-security@lists.archlinux.org
Subject:  [ASA-202105-23] dotnet-sdk-3.1: privilege escalation
Date:  Wed, 26 May 2021 12:33:27 +0200
Message-ID:  <20210526103327.sv563j5e6jigwyjh@archlinux.org>
Cc:  Jonas Witschel <diabonas@archlinux.org>

Arch Linux Security Advisory ASA-202105-23 ========================================== Severity: Medium Date : 2021-05-25 CVE-ID : CVE-2021-31204 Package : dotnet-sdk-3.1 Type : privilege escalation Remote : No Link : https://security.archlinux.org/AVG-1945 Summary ======= The package dotnet-sdk-3.1 before version 3.1.15.sdk115-1 is vulnerable to privilege escalation. Resolution ========== Upgrade to 3.1.15.sdk115-1. # pacman -Syu "dotnet-sdk-3.1>=3.1.15.sdk115-1" The problem has been fixed upstream in version 3.1.15.sdk115. Workaround ========== None. Description =========== An elevation of privilege vulnerability exists in .NET 5.0 and .NET Core 3.1 when a user runs a single file application on operating systems based on Linux or macOS. The issue is fixed in .NET 5.0, Runtime 5.0.6 and SDK 5.0.203, as well as .NET Core 3.1, Runtime 3.1.15 and SDK 3.1.115. Impact ====== An attacker could elevate privileges from a crafted single file application. References ========== https://msrc.microsoft.com/update-guide/en-US/vulnerabili... https://github.com/dotnet/announcements/issues/185 https://security.archlinux.org/CVE-2021-31204


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds