CVE-2010-4254
published 2010-12-06CVE-2010-4254: Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers…
PriorityP356high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
13.65%
96.0th percentile
Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and possibly execute arbitrary code, via a crafted method call.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| novell | moonlight | <= 2.3.0 | — |
| novell | moonlight | — | — |
| novell | moonlight | — | — |
| novell | moonlight | — | — |
| novell | moonlight | — | — |
| novell | moonlight | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Bugzilla
CVE-2010-4254 mono: vulnerability when Moonlight is used may allow arbitrary code execution
bugzilla·2010-12-04·CVSS 7.5
CVE-2010-4254 [HIGH] CVE-2010-4254 mono: vulnerability when Moonlight is used may allow arbitrary code execution
CVE-2010-4254 mono: vulnerability when Moonlight is used may allow arbitrary code execution
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4254 to
the following vulnerability:
Name: CVE-2010-4254
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4254
Assigned: 20101116
Reference: CONFIRM: http://www.mono-project.com/Vulnerabilities#Moonlight_Generic_Constraints_Bypass_Vulnerability
Reference: CONFIRM: https://bugzilla.novell.com/show_bug.cgi?id=654136
Reference: CONFIRM: https://bugzilla.novell.com/show_bug.cgi?id=655847
Reference: CONFIRM: https://github.com/mono/mono/commit/4905ef1130feb26c3150b28b97e4a96752e0d399
Reference: CONFIRM: https://github.com/mono/mono/commit/65292a69c837b8a5f7a392d34db63de592153358
Reference: CONFIRM: https://github.com/mono/m
Bugzilla
CVE-2010-4254 mono: vulnerability when Moonlight is used may allow arbitrary code execution [fedora-all]
bugzilla·2010-12-04·CVSS 7.5
CVE-2010-4254 [HIGH] CVE-2010-4254 mono: vulnerability when Moonlight is used may allow arbitrary code execution [fedora-all]
CVE-2010-4254 mono: vulnerability when Moonlight is used may allow arbitrary code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=659910
Please not
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.htmlhttp://secunia.com/advisories/42373http://secunia.com/advisories/42877http://www.exploit-db.com/exploits/15974http://www.mono-project.com/Vulnerabilities#Moonlight_Generic_Constraints_Bypass_Vulnerabilityhttp://www.securityfocus.com/bid/45051http://www.vupen.com/english/advisories/2011/0076https://bugzilla.novell.com/show_bug.cgi?id=654136https://bugzilla.novell.com/show_bug.cgi?id=655847https://github.com/mono/mono/commit/4905ef1130feb26c3150b28b97e4a96752e0d399https://github.com/mono/mono/commit/65292a69c837b8a5f7a392d34db63de592153358https://github.com/mono/mono/commit/cf1ec146f7c6acdc6697032b3aaafc68ffacdcachttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.htmlhttp://secunia.com/advisories/42373http://secunia.com/advisories/42877http://www.exploit-db.com/exploits/15974http://www.mono-project.com/Vulnerabilities#Moonlight_Generic_Constraints_Bypass_Vulnerabilityhttp://www.securityfocus.com/bid/45051http://www.vupen.com/english/advisories/2011/0076https://bugzilla.novell.com/show_bug.cgi?id=654136https://bugzilla.novell.com/show_bug.cgi?id=655847https://github.com/mono/mono/commit/4905ef1130feb26c3150b28b97e4a96752e0d399https://github.com/mono/mono/commit/65292a69c837b8a5f7a392d34db63de592153358https://github.com/mono/mono/commit/cf1ec146f7c6acdc6697032b3aaafc68ffacdcac
2010-12-06
Published