Race condition in the FastCopy optimization in the Array.Copy method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to trigger a buffer overflow and modify internal data structures, and cause a denial of service (plugin crash) or corrupt the internal state of the security manager, via a crafted media file in which a thread makes a change after a type check but before a copy action.
CVSS Details
- CVSS 3.1 Base Score: 7.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-util/mono-debugger.Upgrade dev-lang/mono. | Oct 30, 2017 | Apr 13, 2011 |
| Suse | — | Upgrade moonlight-pluginUpgrade libmoon-develUpgrade moonlight-desktop-develUpgrade moonlight-desktopUpgrade moonlight-toolsUpgrade moonlight-web-develUpgrade libmoon0 | Feb 17, 2015 | Apr 13, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub