CVE-2015-2319Improper Certificate Validation in Mono

Severity
7.5HIGHNVD
OSV5.8OSV4.3
EPSS
0.9%
top 24.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 8
Latest updateMay 14

Description

The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

debiandebian/mono< mono 3.2.8+dfsg-10 (bookworm)
NVDmono-project/mono< 3.12.1
Debianmono/mono< 3.2.8+dfsg-10+3
Ubuntumono/mono< 3.2.8+dfsg-4ubuntu1.1

🔴Vulnerability Details

3
GHSA
GHSA-rpmm-5q5g-56vf: The TLS stack in Mono before 32022-05-14
OSV
CVE-2015-2319: The TLS stack in Mono before 32018-01-08
OSV
mono vulnerabilities2015-03-24

📋Vendor Advisories

2
Ubuntu
Mono vulnerabilities2015-03-24
Debian
CVE-2015-2319: mono - The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to cond...2015

💬Community

1
Bugzilla
CVE-2015-2318 CVE-2015-2319 CVE-2015-2320 mono: TLS implementation vulnerabilities2015-03-17