CVE-2015-2318
published 2018-01-08CVE-2015-2318: The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging…
PriorityP340high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
1.97%
78.2th percentile
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | mono | < mono 3.2.8+dfsg-10 (bookworm) | mono 3.2.8+dfsg-10 (bookworm) |
| mono-project | mono | < 3.12.1 | 3.12.1 |
| mono | mono | >= 0 < 3.2.8+dfsg-10 | 3.2.8+dfsg-10 |
| mono | mono | >= 0 < 3.2.8+dfsg-10 | 3.2.8+dfsg-10 |
| mono | mono | >= 0 < 3.2.8+dfsg-10 | 3.2.8+dfsg-10 |
| mono | mono | >= 0 < 3.2.8+dfsg-10 | 3.2.8+dfsg-10 |
| mono | mono | >= 0 < 3.2.8+dfsg-4ubuntu1.1 | 3.2.8+dfsg-4ubuntu1.1 |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xv64-wpfr-x2m3: The TLS stack in Mono before 3
ghsa_unreviewed·2022-05-14
CVE-2015-2318 [HIGH] CWE-295 GHSA-xv64-wpfr-x2m3: The TLS stack in Mono before 3
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.
OSV
CVE-2015-2318: The TLS stack in Mono before 3
osv·2018-01-08·CVSS 8.1
CVE-2015-2318 [HIGH] CVE-2015-2318: The TLS stack in Mono before 3
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.
OSV
mono vulnerabilities
osv·2015-03-24·CVSS 5.8
CVE-2015-2318 [MEDIUM] mono vulnerabilities
mono vulnerabilities
It was discovered that the Mono TLS implementation was vulnerable to the
SKIP-TLS vulnerability. A remote attacker could possibly use this issue
to perform client impersonation attacks. (CVE-2015-2318)
It was discovered that the Mono TLS implementation was vulnerable to the
FREAK vulnerability. A remote attacker or a machine-in-the-middle could
possibly use this issue to force the use of insecure ciphersuites.
(CVE-2015-2319)
It was discovered that the Mono TLS implementation still supported a
fallback to SSLv2. This update removes the functionality as use of SSLv2 is
known to be insecure. (CVE-2015-2320)
It was discovered that Mono incorrectly handled memory in certain
circumstances. A remote attacker could possibly use this issue to cause
Mono to crash, resulting
Ubuntu
Mono vulnerabilities
vendor_ubuntu·2015-03-24·CVSS 5.8
CVE-2011-0992 [MEDIUM] Mono vulnerabilities
Title: Mono vulnerabilities
Summary: Several security issues were fixed in Mono.
It was discovered that the Mono TLS implementation was vulnerable to the
SKIP-TLS vulnerability. A remote attacker could possibly use this issue
to perform client impersonation attacks. (CVE-2015-2318)
It was discovered that the Mono TLS implementation was vulnerable to the
FREAK vulnerability. A remote attacker or a machine-in-the-middle could
possibly use this issue to force the use of insecure ciphersuites.
(CVE-2015-2319)
It was discovered that the Mono TLS implementation still supported a
fallback to SSLv2. This update removes the functionality as use of SSLv2 is
known to be insecure. (CVE-2015-2320)
It was discovered that Mono incorrectly handled memory in certain
circumstances. A remote attacker co
Debian
CVE-2015-2318: mono - The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduc...
vendor_debian·2015·CVSS 8.1
CVE-2015-2318 [HIGH] CVE-2015-2318: mono - The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduc...
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.
Scope: local
bookworm: resolved (fixed in 3.2.8+dfsg-10)
bullseye: resolved (fixed in 3.2.8+dfsg-10)
forky: resolved (fixed in 3.2.8+dfsg-10)
sid: resolved (fixed in 3.2.8+dfsg-10)
trixie: resolved (fixed in 3.2.8+dfsg-10)
No detection rules found.
No public exploits indexed.
http://www.mono-project.com/news/2015/03/07/mono-tls-vulnerability/http://www.openwall.com/lists/oss-security/2015/03/17/9http://www.securityfocus.com/bid/73253http://www.ubuntu.com/usn/USN-2547-1https://bugzilla.redhat.com/show_bug.cgi?id=1202869https://github.com/mono/mono/commit/1509226c41d74194c146deb173e752b8d3cdeec4https://mitls.org/pages/attacks/SMACK#skiphttps://www.debian.org/security/2015/dsa-3202http://www.mono-project.com/news/2015/03/07/mono-tls-vulnerability/http://www.openwall.com/lists/oss-security/2015/03/17/9http://www.securityfocus.com/bid/73253http://www.ubuntu.com/usn/USN-2547-1https://bugzilla.redhat.com/show_bug.cgi?id=1202869https://github.com/mono/mono/commit/1509226c41d74194c146deb173e752b8d3cdeec4https://mitls.org/pages/attacks/SMACK#skiphttps://www.debian.org/security/2015/dsa-3202
2018-01-08
Published