CVE-2010-4254
Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and possibly execute arbitrary code, via a crafted method call.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and possibly execute arbitrary code, via a crafted method call.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 13.65% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- mono/mono · novell/moonlight
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.html
- http://secunia.com/advisories/42373Vendor Advisory
- http://secunia.com/advisories/42877
- http://www.exploit-db.com/exploits/15974
- http://www.mono-project.com/Vulnerabilities#Moonlight_Generic_Constraints_Bypass_Vulnerability
- http://www.securityfocus.com/bid/45051
- http://www.vupen.com/english/advisories/2011/0076
- https://bugzilla.novell.com/show_bug.cgi?id=654136
- https://bugzilla.novell.com/show_bug.cgi?id=655847
- https://github.com/mono/mono/commit/4905ef1130feb26c3150b28b97e4a96752e0d399Patch
- https://github.com/mono/mono/commit/65292a69c837b8a5f7a392d34db63de592153358Patch
- https://github.com/mono/mono/commit/cf1ec146f7c6acdc6697032b3aaafc68ffacdcacPatch
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.html
- http://secunia.com/advisories/42373Vendor Advisory
- http://secunia.com/advisories/42877
- http://www.exploit-db.com/exploits/15974
- http://www.mono-project.com/Vulnerabilities#Moonlight_Generic_Constraints_Bypass_Vulnerability
- http://www.securityfocus.com/bid/45051
- http://www.vupen.com/english/advisories/2011/0076
- https://bugzilla.novell.com/show_bug.cgi?id=654136
- https://bugzilla.novell.com/show_bug.cgi?id=655847
- https://github.com/mono/mono/commit/4905ef1130feb26c3150b28b97e4a96752e0d399Patch
- https://github.com/mono/mono/commit/65292a69c837b8a5f7a392d34db63de592153358Patch
- https://github.com/mono/mono/commit/cf1ec146f7c6acdc6697032b3aaafc68ffacdcacPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.