CVE-2010-4159
published 2010-11-17CVE-2010-4159: Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier allows local users to gain privileges via a Trojan horse shared library in the…
PriorityP418medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.35%
27.8th percentile
Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Affected
71 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mono | < mono 2.6.7-4 (bookworm) | mono 2.6.7-4 (bookworm) |
| mono | mono | <= 2.6.7 | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Mono vulnerabilities
vendor_ubuntu·2012-07-25·CVSS 6.9
CVE-2010-4159 [MEDIUM] Mono vulnerabilities
Title: Mono vulnerabilities
Summary: Mono could be made to expose sensitive information over the network.
It was discovered that the Mono System.Web library incorrectly filtered
certain error messages related to forbidden files. If a user were tricked
into opening a specially crafted URL, an attacker could possibly exploit
this to conduct cross-site scripting (XSS) attacks. (CVE-2012-3382)
It was discovered that the Mono System.Web library incorrectly handled the
EnableViewStateMac property. If a user were tricked into opening a
specially crafted URL, an attacker could possibly exploit this to conduct
cross-site scripting (XSS) attacks. This issue only affected Ubuntu
10.04 LTS. (CVE-2010-4159)
Instructions: After a standard system update you need to restart Mono applications to
make a
Debian
CVE-2010-4159: mono - Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier...
vendor_debian·2010·CVSS 6.9
CVE-2010-4159 [MEDIUM] CVE-2010-4159: mono - Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier...
Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Scope: local
bookworm: resolved (fixed in 2.6.7-4)
bullseye: resolved (fixed in 2.6.7-4)
forky: resolved (fixed in 2.6.7-4)
sid: resolved (fixed in 2.6.7-4)
trixie: resolved (fixed in 2.6.7-4)
GHSA
GHSA-7g38-2ph5-vm4v: Untrusted search path vulnerability in metadata/loader
ghsa_unreviewed·2022-05-17
CVE-2010-4159 [MEDIUM] GHSA-7g38-2ph5-vm4v: Untrusted search path vulnerability in metadata/loader
Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier allows local users to gain privileges via a Trojan horse shared library in the current working directory.
OSV
CVE-2010-4159: Untrusted search path vulnerability in metadata/loader
osv·2010-11-17·CVSS 6.9
CVE-2010-4159 [MEDIUM] CVE-2010-4159: Untrusted search path vulnerability in metadata/loader
Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier allows local users to gain privileges via a Trojan horse shared library in the current working directory.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4159 mono: untrusted search path vulnerability
bugzilla·2010-11-17·CVSS 6.9
CVE-2010-4159 [MEDIUM] CVE-2010-4159 mono: untrusted search path vulnerability
CVE-2010-4159 mono: untrusted search path vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4159 to
the following vulnerability:
Name: CVE-2010-4159
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4159
Assigned: 20101104
Reference: MLIST:[mono-patches] 20101012 [mono/mono] d3985be4: Search for dllimported shared libs in the base directory, not cwd.
Reference: URL: http://lists.ximian.com/pipermail/mono-patches/2010-October/177900.html
Reference: MLIST:[oss-security] 20101110 CVE request: mono loading shared libs from cwd
Reference: URL: http://marc.info/?l=oss-security&m=128939873515821&w=2
Reference: MLIST:[oss-security] 20101110 Re: CVE request: mono loading shared libs from cwd
Reference: URL: http://marc.info/?l=oss-security&m=128939912716
Bugzilla
CVE-2010-4159 mono: untrusted search path vulnerability [fedora-all]
bugzilla·2010-11-17·CVSS 6.9
CVE-2010-4159 [MEDIUM] CVE-2010-4159 mono: untrusted search path vulnerability [fedora-all]
CVE-2010-4159 mono: untrusted search path vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=654403
Please note: this issue affects multiple suppo
http://lists.ximian.com/pipermail/mono-patches/2010-October/177900.htmlhttp://marc.info/?l=oss-security&m=128939873515821&w=2http://marc.info/?l=oss-security&m=128939912716499&w=2http://marc.info/?l=oss-security&m=128941802415318&w=2http://secunia.com/advisories/42174http://www.mandriva.com/security/advisories?name=MDVSA-2010:240http://www.mono-project.com/Vulnerabilities#Mono_Runtime_Insecure_Native_Library_Loadinghttp://www.securityfocus.com/bid/44810http://www.vupen.com/english/advisories/2010/3059https://bugzilla.novell.com/show_bug.cgi?id=641915https://github.com/mono/mono/commit/8e890a3bf80a4620e417814dc14886b1bbd17625http://lists.ximian.com/pipermail/mono-patches/2010-October/177900.htmlhttp://marc.info/?l=oss-security&m=128939873515821&w=2http://marc.info/?l=oss-security&m=128939912716499&w=2http://marc.info/?l=oss-security&m=128941802415318&w=2http://secunia.com/advisories/42174http://www.mandriva.com/security/advisories?name=MDVSA-2010:240http://www.mono-project.com/Vulnerabilities#Mono_Runtime_Insecure_Native_Library_Loadinghttp://www.securityfocus.com/bid/44810http://www.vupen.com/english/advisories/2010/3059https://bugzilla.novell.com/show_bug.cgi?id=641915https://github.com/mono/mono/commit/8e890a3bf80a4620e417814dc14886b1bbd17625
2010-11-17
Published