CVE-2015-2319
published 2018-01-08CVE-2015-2319: The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic…
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
3.15%
86.5th percentile
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mono | < mono 3.2.8+dfsg-10 (bookworm) | mono 3.2.8+dfsg-10 (bookworm) |
| mono-project | mono | < 3.12.1 | 3.12.1 |
| mono | mono | >= 0 < 3.2.8+dfsg-10 | 3.2.8+dfsg-10 |
| mono | mono | >= 0 < 3.2.8+dfsg-10 | 3.2.8+dfsg-10 |
| mono | mono | >= 0 < 3.2.8+dfsg-10 | 3.2.8+dfsg-10 |
| mono | mono | >= 0 < 3.2.8+dfsg-10 | 3.2.8+dfsg-10 |
| mono | mono | >= 0 < 3.2.8+dfsg-4ubuntu1.1 | 3.2.8+dfsg-4ubuntu1.1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.8MEDIUM
vendor_ubuntu5.8MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rpmm-5q5g-56vf: The TLS stack in Mono before 3
ghsa_unreviewed·2022-05-14·CVSS 4.3
CVE-2015-2319 [MEDIUM] CWE-295 GHSA-rpmm-5q5g-56vf: The TLS stack in Mono before 3
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.
OSV
CVE-2015-2319: The TLS stack in Mono before 3
osv·2018-01-08·CVSS 4.3
CVE-2015-2319 [MEDIUM] CVE-2015-2319: The TLS stack in Mono before 3
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.
OSV
mono vulnerabilities
osv·2015-03-24·CVSS 5.8
CVE-2015-2318 [MEDIUM] mono vulnerabilities
mono vulnerabilities
It was discovered that the Mono TLS implementation was vulnerable to the
SKIP-TLS vulnerability. A remote attacker could possibly use this issue
to perform client impersonation attacks. (CVE-2015-2318)
It was discovered that the Mono TLS implementation was vulnerable to the
FREAK vulnerability. A remote attacker or a machine-in-the-middle could
possibly use this issue to force the use of insecure ciphersuites.
(CVE-2015-2319)
It was discovered that the Mono TLS implementation still supported a
fallback to SSLv2. This update removes the functionality as use of SSLv2 is
known to be insecure. (CVE-2015-2320)
It was discovered that Mono incorrectly handled memory in certain
circumstances. A remote attacker could possibly use this issue to cause
Mono to crash, resulting
Ubuntu
Mono vulnerabilities
vendor_ubuntu·2015-03-24·CVSS 5.8
CVE-2011-0992 [MEDIUM] Mono vulnerabilities
Title: Mono vulnerabilities
Summary: Several security issues were fixed in Mono.
It was discovered that the Mono TLS implementation was vulnerable to the
SKIP-TLS vulnerability. A remote attacker could possibly use this issue
to perform client impersonation attacks. (CVE-2015-2318)
It was discovered that the Mono TLS implementation was vulnerable to the
FREAK vulnerability. A remote attacker or a machine-in-the-middle could
possibly use this issue to force the use of insecure ciphersuites.
(CVE-2015-2319)
It was discovered that the Mono TLS implementation still supported a
fallback to SSLv2. This update removes the functionality as use of SSLv2 is
known to be insecure. (CVE-2015-2320)
It was discovered that Mono incorrectly handled memory in certain
circumstances. A remote attacker co
Debian
CVE-2015-2319: mono - The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to cond...
vendor_debian·2015·CVSS 4.3
CVE-2015-2319 [MEDIUM] CVE-2015-2319: mono - The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to cond...
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.
Scope: local
bookworm: resolved (fixed in 3.2.8+dfsg-10)
bullseye: resolved (fixed in 3.2.8+dfsg-10)
forky: resolved (fixed in 3.2.8+dfsg-10)
sid: resolved (fixed in 3.2.8+dfsg-10)
trixie: resolved (fixed in 3.2.8+dfsg-10)
No detection rules found.
No public exploits indexed.
http://www.mono-project.com/news/2015/03/07/mono-tls-vulnerability/http://www.openwall.com/lists/oss-security/2015/03/17/9http://www.securityfocus.com/bid/73250http://www.ubuntu.com/usn/USN-2547-1https://bugzilla.redhat.com/show_bug.cgi?id=1202869https://github.com/mono/mono/commit/9c38772f094168d8bfd5bc73bf8925cd04faad10https://mitls.org/pages/attacks/SMACK#freakhttps://www.debian.org/security/2015/dsa-3202http://www.mono-project.com/news/2015/03/07/mono-tls-vulnerability/http://www.openwall.com/lists/oss-security/2015/03/17/9http://www.securityfocus.com/bid/73250http://www.ubuntu.com/usn/USN-2547-1https://bugzilla.redhat.com/show_bug.cgi?id=1202869https://github.com/mono/mono/commit/9c38772f094168d8bfd5bc73bf8925cd04faad10https://mitls.org/pages/attacks/SMACK#freakhttps://www.debian.org/security/2015/dsa-3202
2018-01-08
Published