Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 10: DLA-3343-1 Critical Vulnerability in Mono Execution Risk

debian lts
Calendar Grey February 25, 2023
Dist Debian Esm H88
An important Debian LTS alert about Mono highlights vulnerabilities that permit unauthorized code execution. Users must upgrade promptly to maintain security
Triggering arbitrary code execution was possible due to .desktop files registered as application/x-ms-dos-executable MIME handlers in the open source .NET framework Mono

Summary

For Debian 10 buster, this problem has been fixed in version
5.18.0.240+dfsg-3+deb10u1.

We recommend that you upgrade your mono packages.

For the detailed security status of mono please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/mono

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: mono
Version: 5.18.0.240+dfsg-3+deb10u1
CVE ID: CVE-2023-26314
Debian Bug: 972146

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here