PT-2021-7949 · Microsoft+3 · Visual Studio+4

Published

2021-08-10

·

Updated

2024-03-06

·

CVE-2021-34485

CVSS v3.1

5.0

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions .NET Core versions prior to 5.0.9 .NET Core versions prior to 3.1.18 .NET Core versions prior to 2.1.29 Visual Studio (affected versions not specified)
Description The issue is related to insufficient protection of sensitive data in Microsoft Visual Studio and .NET Core. Exploitation of this issue may allow an attacker to disclose protected information. The vulnerability exists when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS.
Recommendations For .NET 5.0, download and install Runtime 5.0.9 or SDK 5.0.206 (for Visual Studio 2019 v16.8) or SDK 5.0.303 (for Visual Studio 2019 V16.10) from https://dotnet.microsoft.com/download/dotnet-core/5.0. For .NET Core 3.1, download and install Runtime 3.1.18 or SDK 3.1.118 (for Visual Studio 2019 v16.4) or 3.1.412 (for Visual Studio 2019 v16.7 or later) from https://dotnet.microsoft.com/download/dotnet-core/3.1. For .NET Core 2.1, download and install Runtime 2.1.29 or SDK 2.1.525 (for Visual Studio 2019 v15.9) or 2.1.817 from https://dotnet.microsoft.com/download/dotnet-core/2.1.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1269
ALT-PU-2022-1270
ALT-PU-2022-1272
ALT-PU-2022-1273
ALT-PU-2022-1274
ALT-PU-2022-1275
ALT-PU-2022-1276
ALT-PU-2022-1352
ALT-PU-2022-1353
ALT-PU-2022-1354
ALT-PU-2022-1355
ALT-PU-2022-1357
ALT-PU-2022-1358
ALT-PU-2022-1360
ALT-PU-2022-1544
ALT-PU-2022-1545
ALT-PU-2022-1548
ALT-PU-2022-1549
ALT-PU-2022-1550
ALT-PU-2022-1551
BDU:2023-06551
BIT-DOTNET-2021-34485
BIT-DOTNET-SDK-2021-34485
CESA-2021_3142
CESA-2021_3145
CESA-2021_3148
CVE-2021-34485
GHSA-VGWQ-HFQC-58WV
RHSA-2021:3142
RHSA-2021:3143
RHSA-2021:3144
RHSA-2021:3145
RHSA-2021:3147
RHSA-2021:3148
RHSA-2021_3142
RHSA-2021_3145
RHSA-2021_3148

Affected Products

Alt Linux
Centos
Net Core
Red Hat
Visual Studio