6.9
CVSSv2

CVE-2010-4159

Published: 17/11/2010 Updated: 09/12/2010
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and previous versions allows local users to gain privileges via a Trojan horse shared library in the current working directory.

Vulnerable Product Search on Vulmon Subscribe to Product

mono mono 1.1.8.1

mono mono 1.1.17

mono mono 1.1.10

mono mono 1.1.10.1

mono mono 1.0.6

mono mono 1.1.13.6

mono mono 1.1.3

mono mono 1.0.5

mono mono 1.2.4

mono mono 1.2.3.1

mono mono 2.4

mono mono 2.2

mono mono 1.1.13.2

mono mono 1.1.11

mono mono 1.1.12

mono mono 1.1.15

mono mono 1.1.16

mono mono 1.0.1

mono mono 1.1.13

mono mono 1.1.8.3

mono mono 1.1.17.1

mono mono 1.1.13.4

mono mono 1.1.6

mono mono 1.1.2

mono mono 1.2.5.2

mono mono 1.1.9

mono mono 1.1.18

mono mono 1.1.7

mono mono 1.0

mono mono 1.1.9.1

mono mono 1.1.1

mono mono 1.0.2

mono mono 1.2.5.1

mono mono 2.0.1

mono mono 1.9.1

mono mono 1.1.17.2

mono mono 2.4.3

mono mono 1.1.13.8.1

mono mono 1.1.14

mono mono 1.2.2.1

mono mono 1.2.3

mono mono

mono mono 2.6.4

mono mono 1.2.5

mono mono 2.4.2.1

mono mono 2.4.2

mono mono 2.0

mono mono 1.1.12.1

mono mono 1.1.16.1

mono mono 1.2

mono mono 1.1.4

mono mono 1.1.8

mono mono 1.1.13.7

mono mono 1.1.9.2

mono mono 1.0.4

mono mono 1.1.5

mono mono 1.9

mono mono 1.2.6

mono mono 2.4.2.3

mono mono 2.4.2.2

mono mono 1.1.13.5

mono mono 1.1.13.8

mono mono 1.2.1

mono mono 1.2.2

mono mono 2.6.3

mono mono 2.6

Vendor Advisories

Debian Bug report logs - #605097 CVE-2010-4159 Package: mono; Maintainer for mono is Debian Mono Group <pkg-mono-group@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sat, 27 Nov 2010 12:15:08 UTC Severity: grave Tags: security Fixed in version mono/267-4 Done: Mirco Bauer <mee ...
Mono could be made to expose sensitive information over the network ...