[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2009:268 -- Mandriva mono

ID: oval:org.secpod.oval:def:300749Date: (C)2012-01-07   (M)2022-03-02
Class: PATCHFamily: unix




Multiple vulnerabilities has been found and corrected in mono: Multiple cross-site scripting vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted attributes related to HtmlControl.cs , HtmlForm.cs , HtmlInputButton , HtmlInputRadioButton , and HtmlSelect . The XML HMAC signature system did not correctly check certain lengths. If an attacker sent a truncated HMAC, it could bypass authentication, leading to potential privilege escalation . This update fixes these vulnerabilities.

Platform:
Mandriva Linux 2009.0
Mandriva Linux 2008.1
Product:
mono
Reference:
MDVSA-2009:268
CVE-2009-0217
CVE-2008-3422
CVE    2
CVE-2008-3422
CVE-2009-0217
CPE    2
cpe:/o:mandriva:linux:2008.1
cpe:/o:mandriva:linux:2009.0

© SecPod Technologies