Comment 10 for bug 2060260

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package dotnet7 - 7.0.119-0ubuntu1~22.04.1

---------------
dotnet7 (7.0.119-0ubuntu1~22.04.1) jammy-security; urgency=medium

  * New upstream release
  * SECURITY UPDATE: stack buffer overflow
    - CVE-2024-30045: a stack based buffer overflow in the .NET Double Parse
      routine allows for remote code execution.
  * SECURITY UPDATE: resource dead-lock
    - CVE-2024-30046: a dead-lock in Http2OutputProducer.Stop() results in a
      denial of service.

 -- Ian Constantin <email address hidden> Thu, 09 May 2024 15:47:29 +0300