CVE-2010-4254
Summary
| CVE | CVE-2010-4254 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-12-06 13:44:00 UTC |
| Updated | 2011-02-02 06:59:00 UTC |
| Description | Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and possibly execute arbitrary code, via a crafted method call. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mono | Mono | All | All | All | All |
| Application | Mono | Mono | All | All | All | All |
| Application | Novell | Moonlight | 2.99.0 | All | All | All |
| Application | Novell | Moonlight | 2.99.1 | All | All | All |
| Application | Novell | Moonlight | 2.99.2 | All | All | All |
| Application | Novell | Moonlight | 2.99.7 | All | All | All |
| Application | Novell | Moonlight | 2.99.9 | All | All | All |
| Application | Novell | Moonlight | 2.99.0 | All | All | All |
| Application | Novell | Moonlight | 2.99.1 | All | All | All |
| Application | Novell | Moonlight | 2.99.2 | All | All | All |
| Application | Novell | Moonlight | 2.99.7 | All | All | All |
| Application | Novell | Moonlight | 2.99.9 | All | All | All |
| Application | Novell | Moonlight | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Handle invalid instantiation of generic methods. · mono/mono@cf1ec14 · GitHub | CONFIRM | github.com | Patch |
| Moonlight Generic Constraints Bypass Vulnerability - Advisories - Community | SECUNIA | secunia.com | Vendor Advisory |
| Handle invalid instantiation of generic methods. · mono/mono@4905ef1 · GitHub | CONFIRM | github.com | Patch |
| Mono/Moonlight Generic Type Argument Local Privilege Escalation | EXPLOIT-DB | www.exploit-db.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2011:001 | SUSE | lists.opensuse.org | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:024 | SUSE | lists.opensuse.org | |
| Mono/Moonlight Generic Type Argument Local Privilege Escalation Vulnerability | BID | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Bug 654136 – Insufficient validation of generic type arguments during reflection allows violation of the type system | CONFIRM | bugzilla.novell.com | |
| SUSE update for multiple packages - Advisories - Community | SECUNIA | secunia.com | |
| Vulnerabilities - Mono | CONFIRM | www.mono-project.com | |
| Access Denied | CONFIRM | bugzilla.novell.com | |
| Handle invalid instantiation of generic methods. · mono/mono@65292a6 · GitHub | CONFIRM | github.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.