PT-2013-4695 · Microsoft · .Net Framework
Published
2013-10-09
·
Updated
2018-10-12
·
CVE-2013-3861
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft .NET Framework versions 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5
Description
A denial of service issue exists, allowing remote attackers to cause an application crash or hang via crafted character sequences in JSON data. This could enable an attacker to cause a server or application to crash or become unresponsive.
Recommendations
For Microsoft .NET Framework versions 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5, consider restricting the processing of JSON data from untrusted sources until a fix is available. As a temporary workaround, implement input validation to detect and prevent crafted character sequences in JSON data.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
.Net Framework