PT-2012-1048 · Mono+1 · Mono+1

Gonzalop

·

Publicado

2012-07-12

·

Atualizado

2013-04-05

·

CVE-2012-3382

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mono versions 2.10.8 and earlier
Description The issue concerns a cross-site scripting (XSS) vulnerability in the ProcessRequest function. This vulnerability allows remote attackers to inject arbitrary web script or HTML via a file with a crafted name and a forbidden extension, which is not properly handled in an error message. Additionally, there are multiple vulnerabilities in the Mono package that can lead to a breach of protected information integrity, and these can be exploited remotely.
Recommendations For Mono versions 2.10.8 and earlier, as a temporary workaround, consider disabling the ProcessRequest function until a patch is available. Restrict access to files with crafted names and forbidden extensions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03131
CVE-2012-3382
DSA-2512-1
SUSE-SU-2012_0928-1

Produtos afetados

Mono
Suse