LWN.net Logo

mono and mono-debugger: multiple vulnerabilities

Package(s):mono and mono-debugger CVE #(s):CVE-2010-3332 CVE-2010-3369 CVE-2010-4225
Created:June 22, 2012 Updated:June 27, 2012
Description:

From the Gentoo advisory:

A remote attacker could execute arbitrary code, bypass general constraints, obtain the source code for .aspx applications, obtain other sensitive information, cause a Denial of Service, modify internal data structures, or corrupt the internal state of the security manager.

A local attacker could entice a user into running Mono debugger in a directory containing a specially crafted library file to execute arbitrary code with the privileges of the user running Mono debugger.

A context-dependant attacker could bypass the authentication mechanism provided by the XML Signature specification.

Alerts:
Gentoo 201206-13 2012-06-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds