CVE-2011-0992

CWE-3998 documents7 sources
Severity
5.8MEDIUM
EPSS
1.3%
top 19.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 13
Latest updateMay 17

Description

Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service (plugin crash) or obtain sensitive information via vectors related to member data in a resurrected MonoThread instance.

CVSS vector

AV:N/AC:M/C:P/I:N/A:PExploitability: 8.6 | Impact: 4.9

Affected Packages2 packages

Ubuntumono< 3.2.8+dfsg-4ubuntu1
NVDnovell/moonlight6 versions+5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5v2g-vp3m-c3jg: Use-after-free vulnerability in Mono, when Moonlight 22022-05-17
CVEList
CVE-2011-0992: Use-after-free vulnerability in Mono, when Moonlight 22011-04-13
OSV
CVE-2011-0992: Use-after-free vulnerability in Mono, when Moonlight 22011-04-13

📋Vendor Advisories

2
Ubuntu
Mono vulnerabilities2015-03-24
Debian
CVE-2011-0992: mono - Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x bef...2011

💬Community

2
Bugzilla
CVE-2011-0989 CVE-2011-0990 CVE-2011-0991 CVE-2011-0992 mono: multiple vulnerabilities fixed in 2.4.1/3.99.32011-04-08
Bugzilla
CVE-2011-0992 mono: information leak due to improper thread finalization [fedora-all]2011-04-08
CVE-2011-0992 (MEDIUM CVSS 5.8) | Use-after-free vulnerability in Mon | cvebase.io