AlmaLinux 2263 Published by

A dotnet7.0 security, bug fix, and enhancement update has been released for AlmaLinux 9.



ALSA-2022:8434 Moderate: dotnet7.0 security, bug fix, and enhancement update


Type:
security

Severity:
moderate

Release date:
2022-11-17

Description
New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 7.0.100 RC 2 and .NET Runtime 7.0.0 RC 2.
The following packages have been upgraded to a later upstream version: dotnet7.0 (7.0.100). (BZ#2134641)
Security Fix(es):
* dotnet: Nuget cache poisoning on Linux via world-writable cache directory (CVE-2022-41032)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References:
RHSA-2022:8434
CVE-2022-41032
ALSA-2022:8434

Updates packages:
aspnetcore-runtime-7.0-7.0.0-0.5.rc2.el9_1.s390x.rpm
dotnet-targeting-pack-7.0-7.0.0-0.5.rc2.el9_1.s390x.rpm
netstandard-targeting-pack-2.1-7.0.100-0.5.rc2.el9_1.s390x.rpm
dotnet-apphost-pack-7.0-7.0.0-0.5.rc2.el9_1.s390x.rpm
dotnet-sdk-7.0-7.0.100-0.5.rc2.el9_1.s390x.rpm
dotnet-runtime-7.0-7.0.0-0.5.rc2.el9_1.s390x.rpm
aspnetcore-targeting-pack-7.0-7.0.0-0.5.rc2.el9_1.s390x.rpm
dotnet-templates-7.0-7.0.100-0.5.rc2.el9_1.s390x.rpm
dotnet-hostfxr-7.0-7.0.0-0.5.rc2.el9_1.s390x.rpm
dotnet-host-7.0.0-0.5.rc2.el9_1.s390x.rpm
dotnet-apphost-pack-7.0-7.0.0-0.5.rc2.el9_1.x86_64.rpm
dotnet-host-7.0.0-0.5.rc2.el9_1.x86_64.rpm
netstandard-targeting-pack-2.1-7.0.100-0.5.rc2.el9_1.x86_64.rpm
dotnet-templates-7.0-7.0.100-0.5.rc2.el9_1.x86_64.rpm
aspnetcore-runtime-7.0-7.0.0-0.5.rc2.el9_1.x86_64.rpm
dotnet-hostfxr-7.0-7.0.0-0.5.rc2.el9_1.x86_64.rpm
dotnet-runtime-7.0-7.0.0-0.5.rc2.el9_1.x86_64.rpm
dotnet-targeting-pack-7.0-7.0.0-0.5.rc2.el9_1.x86_64.rpm
dotnet-sdk-7.0-7.0.100-0.5.rc2.el9_1.x86_64.rpm
aspnetcore-targeting-pack-7.0-7.0.0-0.5.rc2.el9_1.x86_64.rpm
dotnet-targeting-pack-7.0-7.0.0-0.5.rc2.el9_1.aarch64.rpm
dotnet-templates-7.0-7.0.100-0.5.rc2.el9_1.aarch64.rpm
dotnet-apphost-pack-7.0-7.0.0-0.5.rc2.el9_1.aarch64.rpm
aspnetcore-runtime-7.0-7.0.0-0.5.rc2.el9_1.aarch64.rpm
dotnet-hostfxr-7.0-7.0.0-0.5.rc2.el9_1.aarch64.rpm
aspnetcore-targeting-pack-7.0-7.0.0-0.5.rc2.el9_1.aarch64.rpm
dotnet-sdk-7.0-7.0.100-0.5.rc2.el9_1.aarch64.rpm
dotnet-runtime-7.0-7.0.0-0.5.rc2.el9_1.aarch64.rpm
dotnet-host-7.0.0-0.5.rc2.el9_1.aarch64.rpm
netstandard-targeting-pack-2.1-7.0.100-0.5.rc2.el9_1.aarch64.rpm
dotnet-apphost-pack-7.0-7.0.0-0.5.rc2.el9_1.ppc64le.rpm
netstandard-targeting-pack-2.1-7.0.100-0.5.rc2.el9_1.ppc64le.rpm
dotnet-templates-7.0-7.0.100-0.5.rc2.el9_1.ppc64le.rpm
dotnet-runtime-7.0-7.0.0-0.5.rc2.el9_1.ppc64le.rpm
dotnet-sdk-7.0-7.0.100-0.5.rc2.el9_1.ppc64le.rpm
aspnetcore-runtime-7.0-7.0.0-0.5.rc2.el9_1.ppc64le.rpm
dotnet-hostfxr-7.0-7.0.0-0.5.rc2.el9_1.ppc64le.rpm
dotnet-host-7.0.0-0.5.rc2.el9_1.ppc64le.rpm
aspnetcore-targeting-pack-7.0-7.0.0-0.5.rc2.el9_1.ppc64le.rpm
dotnet-targeting-pack-7.0-7.0.0-0.5.rc2.el9_1.ppc64le.rpm
dotnet-sdk-7.0-source-built-artifacts-7.0.100-0.5.rc2.el9_1.ppc64le.rpm
dotnet-sdk-7.0-source-built-artifacts-7.0.100-0.5.rc2.el9_1.x86_64.rpm
dotnet-sdk-7.0-source-built-artifacts-7.0.100-0.5.rc2.el9_1.aarch64.rpm
dotnet-sdk-7.0-source-built-artifacts-7.0.100-0.5.rc2.el9_1.s390x.rpm

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

  ALSA-2022:8434 Moderate: dotnet7.0 security, bug fix, and enhancement update