7.5
CVSSv2

CVE-2010-4254

Published: 06/12/2010 Updated: 02/02/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Mono, when Moonlight prior to 2.3.0.1 or 2.99.x prior to 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote malicious users to bypass generic constraints, and possibly execute arbitrary code, via a crafted method call.

Vulnerable Product Search on Vulmon Subscribe to Product

mono mono

novell moonlight 2.99.0

novell moonlight

novell moonlight 2.99.7

novell moonlight 2.99.9

novell moonlight 2.99.1

novell moonlight 2.99.2

Vendor Advisories

Debian Bug report logs - #608288 mono: CVE-2010-4254 and CVE-2010-4225 Package: mono; Maintainer for mono is Debian Mono Group <pkg-mono-group@listsaliothdebianorg>; Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Wed, 29 Dec 2010 17:36:05 UTC Severity: serious Tags: security Fixed in version mono/26 ...

Exploits

Sources: wwwchrishowiecom/2010/11/24/mutable-strings-in-mono/ wwwsecurityfocuscom/bid/45051/info Mono and Moonlight is prone to a local privilege-escalation vulnerability Local attackers can exploit this issue to execute arbitrary code with elevated privileges Successful exploits will compromise the affected application and ...