Skip to content

System.Formats.Asn1:8.0.0 Denial of service vulnerability

High
jstedfast published GHSA-gmc6-fwg3-75m5 Jul 11, 2024

Package

nuget System.Formats.Asn1:8.0.0 (NuGet)

Affected versions

<8.0.1

Patched versions

8.0.1

Description

Summary

Denial of service vulnerability.

Details

See: GHSA-447r-wph3-92pm and dotnet/announcements#312

PoC

Update System.Security.Cryptography.Pkcs to 8.0.1 so that the transitive dependency with the issue gets updated

Impact

Denial of service vulnerability. Affects MimeKit (>= v3.0.0 and <= v4.7.0) when used to decrypt or verify incoming S/MIME messages as well as importing 3rd-party X.509 certificates for use with encrypting outgoing S/MIME messages.

Severity

High

CVE ID

CVE-2024-38095

Weaknesses

No CWEs

Credits