CVE-2012-3543
published 2015-03-24CVE-2012-3543: mono vulnerabilities It was discovered that the Mono TLS implementation was vulnerable to the SKIP-TLS vulnerability. A remote attacker could possibly use this…
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.58%
83.4th percentile
mono vulnerabilities
It was discovered that the Mono TLS implementation was vulnerable to the
SKIP-TLS vulnerability. A remote attacker could possibly use this issue
to perform client impersonation attacks. (CVE-2015-2318)
It was discovered that the Mono TLS implementation was vulnerable to the
FREAK vulnerability. A remote attacker or a machine-in-the-middle could
possibly use this issue to force the use of insecure ciphersuites.
(CVE-2015-2319)
It was discovered that the Mono TLS implementation still supported a
fallback to SSLv2. This update removes the functionality as use of SSLv2 is
known to be insecure. (CVE-2015-2320)
It was discovered that Mono incorrectly handled memory in certain
circumstances. A remote attacker could possibly use this issue to cause
Mono to crash, resulting in a denial of service, or to obtain sensitive
information. This issue only applied to Ubuntu 12.04 LTS. (CVE-2011-0992)
It was discovered that Mono incorrectly handled hash collisions. A remote
attacker could possibly use this issue to cause Mono to crash, resulting in
a denial of service. This issue only applied to Ubuntu 12.04 LTS.
(CVE-2012-3543)
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mono | < mono 2.10.8.1-7 (bookworm) | mono 2.10.8.1-7 (bookworm) |
| mono | mono | >= 0 < 3.2.8+dfsg-4ubuntu1.1 | 3.2.8+dfsg-4ubuntu1.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.8MEDIUM
vendor_debian7.5HIGH
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
mono vulnerabilities
osv·2015-03-24·CVSS 5.8
CVE-2015-2318 [MEDIUM] mono vulnerabilities
mono vulnerabilities
It was discovered that the Mono TLS implementation was vulnerable to the
SKIP-TLS vulnerability. A remote attacker could possibly use this issue
to perform client impersonation attacks. (CVE-2015-2318)
It was discovered that the Mono TLS implementation was vulnerable to the
FREAK vulnerability. A remote attacker or a machine-in-the-middle could
possibly use this issue to force the use of insecure ciphersuites.
(CVE-2015-2319)
It was discovered that the Mono TLS implementation still supported a
fallback to SSLv2. This update removes the functionality as use of SSLv2 is
known to be insecure. (CVE-2015-2320)
It was discovered that Mono incorrectly handled memory in certain
circumstances. A remote attacker could possibly use this issue to cause
Mono to crash, resulting
Ubuntu
Mono vulnerabilities
vendor_ubuntu·2015-03-24·CVSS 5.8
CVE-2011-0992 [MEDIUM] Mono vulnerabilities
Title: Mono vulnerabilities
Summary: Several security issues were fixed in Mono.
It was discovered that the Mono TLS implementation was vulnerable to the
SKIP-TLS vulnerability. A remote attacker could possibly use this issue
to perform client impersonation attacks. (CVE-2015-2318)
It was discovered that the Mono TLS implementation was vulnerable to the
FREAK vulnerability. A remote attacker or a machine-in-the-middle could
possibly use this issue to force the use of insecure ciphersuites.
(CVE-2015-2319)
It was discovered that the Mono TLS implementation still supported a
fallback to SSLv2. This update removes the functionality as use of SSLv2 is
known to be insecure. (CVE-2015-2320)
It was discovered that Mono incorrectly handled memory in certain
circumstances. A remote attacker co
Debian
CVE-2012-3543: mono - mono 2.10.x ASP.NET Web Form Hash collision DoS
vendor_debian·2012·CVSS 7.5
CVE-2012-3543 [HIGH] CVE-2012-3543: mono - mono 2.10.x ASP.NET Web Form Hash collision DoS
mono 2.10.x ASP.NET Web Form Hash collision DoS
Scope: local
bookworm: resolved (fixed in 2.10.8.1-7)
bullseye: resolved (fixed in 2.10.8.1-7)
forky: resolved (fixed in 2.10.8.1-7)
sid: resolved (fixed in 2.10.8.1-7)
trixie: resolved (fixed in 2.10.8.1-7)
No detection rules found.
Bugzilla
CVE-2012-3543 mono: Hash collision issue
bugzilla·2012-08-30·CVSS 7.8
CVE-2012-3543 [HIGH] CVE-2012-3543 mono: Hash collision issue
CVE-2012-3543 mono: Hash collision issue
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-3414 to the following vulnerability:
The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka "Collisions in HashTable May Cause DoS Vulnerability."
It has been reported:
[1] http://www.openwall.com/lists/oss-security/2012/08/28/12
that the very same issue is present also in Mono .NET implementation too.
The CVE identifier of CVE-2
Bugzilla
CVE-2012-3543 mono: Hash collision issue [epel-all]
bugzilla·2012-08-30·CVSS 7.5
CVE-2012-3543 [HIGH] CVE-2012-3543 mono: Hash collision issue [epel-all]
CVE-2012-3543 mono: Hash collision issue [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=853107
Please not
Bugzilla
CVE-2012-3543 mono: Hash collision issue [fedora-all]
bugzilla·2012-08-30·CVSS 7.5
CVE-2012-3543 [HIGH] CVE-2012-3543 mono: Hash collision issue [fedora-all]
CVE-2012-3543 mono: Hash collision issue [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=853107
Please n
2015-03-24
Published