Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and possibly execute arbitrary code, via a crafted method call.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-util/mono-debugger.Upgrade dev-lang/mono. | Oct 30, 2017 | Dec 6, 2010 |
| Suse | — | Upgrade moonlight-pluginUpgrade moonlight-toolsUpgrade libmoon-develUpgrade moonlight-desktopUpgrade moonlight-web-develUpgrade moonlight-desktop-develUpgrade libmoon0 | Feb 17, 2015 | Dec 6, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub