Re: [OT] log4j Internet Doom

2021-12-22 Thread mike smith
Two red rated ones.
https://www.cvedetails.com/vulnerability-list/vendor_id-26/product_id-43007/Microsoft-.net-Core.html

On Wed, 22 Dec 2021, 19:33 Greg Keogh,  wrote:

> Word has spread far over the last week. I've had a few queries about
> vulnerabilities in software I've participated in, from semi-IT people in
> large companies. One was asking for some sort of audit and evidence and
> sounded a bit panicky. I've explained that the .NET world is beyond the
> light horizon distant from the Java world. I don't think they know the
> difference between the major software development platforms (and their
> cultures).
>
> Can anyone remember any "significant" vulnerabilities due to .NET in the
> last 20 years. I'll run a search after dinner!
>
> *Greg*
>


Re: [OT] log4j Internet Doom

2021-12-22 Thread Greg Keogh
Word has spread far over the last week. I've had a few queries about
vulnerabilities in software I've participated in, from semi-IT people in
large companies. One was asking for some sort of audit and evidence and
sounded a bit panicky. I've explained that the .NET world is beyond the
light horizon distant from the Java world. I don't think they know the
difference between the major software development platforms (and their
cultures).

Can anyone remember any "significant" vulnerabilities due to .NET in the
last 20 years. I'll run a search after dinner!

*Greg*