USN-6217-1: .NET vulnerability
11 July 2023
The maximum failed attempts security feature for .NET could be bypassed.
Releases
Packages
Details
McKee-Harris, Matt Cotterell, and Jack Moran discovered that .NET did
not properly update account lockout maximum failed attempts. An
attacker could possibly use this issue to bypass the security feature
and attempt to guess more passwords for an account.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 23.04
-
aspnetcore-runtime-6.0
-
6.0.120-0ubuntu1~23.04.1
-
dotnet-hostfxr-7.0
-
7.0.109-0ubuntu1~23.04.1
-
dotnet-hostfxr-6.0
-
6.0.120-0ubuntu1~23.04.1
-
dotnet-host
-
6.0.120-0ubuntu1~23.04.1
-
aspnetcore-runtime-7.0
-
7.0.109-0ubuntu1~23.04.1
-
dotnet-sdk-6.0
-
6.0.120-0ubuntu1~23.04.1
-
dotnet-sdk-7.0
-
7.0.109-0ubuntu1~23.04.1
-
dotnet6
-
6.0.120-0ubuntu1~23.04.1
-
dotnet7
-
7.0.109-0ubuntu1~23.04.1
-
dotnet-runtime-7.0
-
7.0.109-0ubuntu1~23.04.1
-
dotnet-runtime-6.0
-
6.0.120-0ubuntu1~23.04.1
-
dotnet-host-7.0
-
7.0.109-0ubuntu1~23.04.1
Ubuntu 22.10
-
aspnetcore-runtime-6.0
-
6.0.120-0ubuntu1~22.10.1
-
dotnet-hostfxr-7.0
-
7.0.109-0ubuntu1~22.10.1
-
dotnet-hostfxr-6.0
-
6.0.120-0ubuntu1~22.10.1
-
dotnet-host
-
6.0.120-0ubuntu1~22.10.1
-
aspnetcore-runtime-7.0
-
7.0.109-0ubuntu1~22.10.1
-
dotnet-sdk-6.0
-
6.0.120-0ubuntu1~22.10.1
-
dotnet-sdk-7.0
-
7.0.109-0ubuntu1~22.10.1
-
dotnet6
-
6.0.120-0ubuntu1~22.10.1
-
dotnet7
-
7.0.109-0ubuntu1~22.10.1
-
dotnet-runtime-7.0
-
7.0.109-0ubuntu1~22.10.1
-
dotnet-runtime-6.0
-
6.0.120-0ubuntu1~22.10.1
-
dotnet-host-7.0
-
7.0.109-0ubuntu1~22.10.1
Ubuntu 22.04
-
aspnetcore-runtime-6.0
-
6.0.120-0ubuntu1~22.04.1
-
dotnet-hostfxr-7.0
-
7.0.109-0ubuntu1~22.04.1
-
dotnet-hostfxr-6.0
-
6.0.120-0ubuntu1~22.04.1
-
dotnet-host
-
6.0.120-0ubuntu1~22.04.1
-
aspnetcore-runtime-7.0
-
7.0.109-0ubuntu1~22.04.1
-
dotnet-sdk-6.0
-
6.0.120-0ubuntu1~22.04.1
-
dotnet-sdk-7.0
-
7.0.109-0ubuntu1~22.04.1
-
dotnet6
-
6.0.120-0ubuntu1~22.04.1
-
dotnet7
-
7.0.109-0ubuntu1~22.04.1
-
dotnet-runtime-7.0
-
7.0.109-0ubuntu1~22.04.1
-
dotnet-runtime-6.0
-
6.0.120-0ubuntu1~22.04.1
-
dotnet-host-7.0
-
7.0.109-0ubuntu1~22.04.1
In general, a standard system update will make all the necessary changes.