A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated malicious user to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
microsoft visual_studio_2017 - |
||
microsoft nuget 4.9.4 |
||
microsoft nuget 4.3.1 |
||
microsoft nuget 4.4.2 |
||
microsoft nuget 4.7.2 |
||
microsoft nuget 4.8.2 |
||
microsoft nuget 4.5.2 |
||
microsoft nuget 4.6.3 |
||
mono-project mono framework 5.18.0.223 |
||
mono-project mono framework 5.20.0 |
||
microsoft .net_core_sdk 1.1 |
||
microsoft .net_core_sdk 2.1.500 |
||
microsoft .net_core_sdk 2.2.100 |
||
redhat enterprise linux 8.0 |
||
redhat enterprise linux eus 8.1 |
||
redhat enterprise linux eus 8.2 |
||
redhat enterprise linux eus 8.4 |
||
redhat enterprise linux server aus 8.2 |
||
redhat enterprise linux server aus 8.4 |
||
redhat enterprise linux server tus 8.2 |
||
redhat enterprise linux server tus 8.4 |
This month the vendor has patched 64 vulnerabilities, 17 of which are rated Critical.
Posted: 13 Mar, 201920 Min ReadThreat Intelligence SubscribeFollowtwitterfacebooklinkedinMicrosoft Patch Tuesday – March 2019This month the vendor has patched 64 vulnerabilities, 17 of which are rated Critical.As always, customers are advised to follow these security best practices: Install vendor patches as soon as they are available. Run all software with the least privileges required while still maintaining functionality. Avoid handlin...
DHCP client has trio of remote-code exec vulns – plus SAP, Adobe issue updates
Patch Tuesday It's the second Tuesday of the month, and you know what that means: a fresh dump of security fixes from Microsoft, Adobe and others. The March edition of Patch Tuesday includes fixes for 64 CVE-listed vulnerabilities, while Adobe addressed a pair of bugs in Photoshop and Digital Editions. Even SAP has got in on the game. You should review the updates, test them if necessary or able to, and install them as soon as possible, to avoid running into miscreants exploiting them to comprom...