PT-2013-4695 · Microsoft · .Net Framework

Published

2013-10-09

·

Updated

2018-10-12

·

CVE-2013-3861

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Microsoft .NET Framework versions 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5
Description A denial of service issue exists, allowing remote attackers to cause an application crash or hang via crafted character sequences in JSON data. This could enable an attacker to cause a server or application to crash or become unresponsive.
Recommendations For Microsoft .NET Framework versions 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5, consider restricting the processing of JSON data from untrusted sources until a fix is available. As a temporary workaround, implement input validation to detect and prevent crafted character sequences in JSON data.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3861

Affected Products

.Net Framework