USN-1517-1: Mono vulnerabilities
25 July 2012
Mono could be made to expose sensitive information over the network.
Releases
Packages
- mono - Mono is a platform for running and developing applications
Details
It was discovered that the Mono System.Web library incorrectly filtered
certain error messages related to forbidden files. If a user were tricked
into opening a specially crafted URL, an attacker could possibly exploit
this to conduct cross-site scripting (XSS) attacks. (CVE-2012-3382)
It was discovered that the Mono System.Web library incorrectly handled the
EnableViewStateMac property. If a user were tricked into opening a
specially crafted URL, an attacker could possibly exploit this to conduct
cross-site scripting (XSS) attacks. This issue only affected Ubuntu
10.04 LTS. (CVE-2010-4159)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 12.04
Ubuntu 11.10
Ubuntu 11.04
Ubuntu 10.04
-
libmono-system-web2.0-cil
-
2.4.4~svn151842-1ubuntu4.1
-
libmono-system-web1.0-cil
-
2.4.4~svn151842-1ubuntu4.1
After a standard system update you need to restart Mono applications to
make all the necessary changes.