CVE-2010-4254
Publication date 6 December 2010
Last updated 24 July 2024
Ubuntu priority
Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and possibly execute arbitrary code, via a crafted method call.
Status
Package | Ubuntu Release | Status |
---|---|---|
mono | ||
Notes
mdeslaur
upstream note: The bug (and fix) is in mono source code but can only be exploited (by untrusted applications) when used by Moonlight. Setting severity to negligile.