{
  "threat_severity" : "Moderate",
  "public_date" : "2019-05-14T00:00:00Z",
  "bugzilla" : {
    "description" : "dotnet: timeouts for regular expressions are not enforced",
    "id" : "1705506",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1705506"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-400",
  "details" : [ "A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981." ],
  "affected_release" : [ {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:1.0::el7",
    "package" : "rh-dotnet21-0:2.1-10.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:1.0::el7",
    "package" : "rh-dotnet21-dotnet-0:2.1.507-2.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:1.0::el7",
    "package" : "rh-dotnet22-0:2.2-7.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:1.0::el7",
    "package" : "rh-dotnet22-curl-0:7.61.1-2.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:1.0::el7",
    "package" : "rh-dotnet22-dotnet-0:2.2.107-2.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:1.0::el7",
    "package" : "rh-dotnetcore10-dotnetcore-0:1.0.16-1.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:1.0::el7",
    "package" : "rh-dotnetcore11-dotnetcore-0:1.1.13-1.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:1.1::el7",
    "package" : "rh-dotnet21-0:2.1-10.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:1.1::el7",
    "package" : "rh-dotnet21-dotnet-0:2.1.507-2.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:1.1::el7",
    "package" : "rh-dotnet22-0:2.2-7.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:1.1::el7",
    "package" : "rh-dotnet22-curl-0:7.61.1-2.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:1.1::el7",
    "package" : "rh-dotnet22-dotnet-0:2.2.107-2.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:1.1::el7",
    "package" : "rh-dotnetcore10-dotnetcore-0:1.0.16-1.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:1.1::el7",
    "package" : "rh-dotnetcore11-dotnetcore-0:1.1.13-1.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:2.1::el7",
    "package" : "rh-dotnet21-0:2.1-10.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:2.1::el7",
    "package" : "rh-dotnet21-dotnet-0:2.1.507-2.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:2.1::el7",
    "package" : "rh-dotnet22-0:2.2-7.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:2.1::el7",
    "package" : "rh-dotnet22-curl-0:7.61.1-2.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:2.1::el7",
    "package" : "rh-dotnet22-dotnet-0:2.2.107-2.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:2.1::el7",
    "package" : "rh-dotnetcore10-dotnetcore-0:1.0.16-1.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:2.1::el7",
    "package" : "rh-dotnetcore11-dotnetcore-0:1.1.13-1.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:2.2::el7",
    "package" : "rh-dotnet21-0:2.1-10.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:2.2::el7",
    "package" : "rh-dotnet21-dotnet-0:2.1.507-2.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:2.2::el7",
    "package" : "rh-dotnet22-0:2.2-7.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:2.2::el7",
    "package" : "rh-dotnet22-curl-0:7.61.1-2.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:2.2::el7",
    "package" : "rh-dotnet22-dotnet-0:2.2.107-2.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:2.2::el7",
    "package" : "rh-dotnetcore10-dotnetcore-0:1.0.16-1.el7"
  }, {
    "product_name" : ".NET Core on Red Hat Enterprise Linux",
    "release_date" : "2019-05-15T00:00:00Z",
    "advisory" : "RHSA-2019:1236",
    "cpe" : "cpe:/a:redhat:rhel_dotnet:2.2::el7",
    "package" : "rh-dotnetcore11-dotnetcore-0:1.1.13-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2019-05-22T00:00:00Z",
    "advisory" : "RHSA-2019:1259",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "dotnet-0:2.1.507-2.el8_0"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2019-0820\nhttps://nvd.nist.gov/vuln/detail/CVE-2019-0820\nhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0820" ],
  "name" : "CVE-2019-0820",
  "csaw" : false
}