Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to finalizing and then resurrecting a DynamicMethod instance.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-lang/mono.Upgrade dev-util/mono-debugger. | Oct 30, 2017 | Apr 13, 2011 |
| Suse | — | Upgrade moonlight-pluginUpgrade moonlight-web-develUpgrade moonlight-toolsUpgrade moonlight-desktopUpgrade libmoon0Upgrade libmoon-develUpgrade moonlight-desktop-devel | Feb 17, 2015 | Apr 13, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub