USN-2547-1
Dashboard / Vulnerabilities / USN-2547-1
USN-2547-1
Summary: mono vulnerabilities
Details: It was discovered that the Mono TLS implementation was vulnerable to the SKIP-TLS vulnerability. A remote attacker could possibly use this issue to perform client impersonation attacks. (CVE-2015-2318) It was discovered that the Mono TLS implementation was vulnerable to the FREAK vulnerability. A remote attacker or a machine-in-the-middle could possibly use this issue to force the use of insecure ciphersuites. (CVE-2015-2319) It was discovered that the Mono TLS implementation still supported a fallback to SSLv2. This update removes the functionality as use of SSLv2 is known to be insecure. (CVE-2015-2320) It was discovered that Mono incorrectly handled memory in certain circumstances. A remote attacker could possibly use this issue to cause Mono to crash, resulting in a denial of service, or to obtain sensitive information. This issue only applied to Ubuntu 12.04 LTS. (CVE-2011-0992) It was discovered that Mono incorrectly handled hash collisions. A remote attacker could possibly use this issue to cause Mono to crash, resulting in a denial of service. This issue only applied to Ubuntu 12.04 LTS. (CVE-2012-3543)
References: https://ubuntu.com/security/notices/USN-2547-1, https://ubuntu.com/security/CVE-2011-0992, https://ubuntu.com/security/CVE-2012-3543, https://ubuntu.com/security/CVE-2015-2318, https://ubuntu.com/security/CVE-2015-2319, https://ubuntu.com/security/CVE-2015-2320
Affected packages
Package
Name: mono
Purl: pkg:deb/ubuntu/[email protected]+dfsg-4ubuntu1.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
