CVE-2011-0992
Publication date 13 April 2011
Last updated 24 July 2024
Ubuntu priority
Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service (plugin crash) or obtain sensitive information via vectors related to member data in a resurrected MonoThread instance.
Status
Package | Ubuntu Release | Status |
---|---|---|
mono | ||
14.04 LTS trusty |
Not affected
|
|
Notes
mdeslaur
upstream note: The bug (and fix) is in mono source code but can only be exploited (by untrusted applications) when used by Moonlight. Setting severity to negligible.
References
Related Ubuntu Security Notices (USN)
- USN-2547-1
- Mono vulnerabilities
- 24 March 2015