Triggering arbitrary code execution was possible due to .desktop files registered as application/x-ms-dos-executable MIME handlers in the open source .NET framework Mono. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3343-1
Several security issues were fixed in Mono.. =========================================================================Ubuntu Security Notice USN-2547-1 March 24, 2015 mono vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: Several security issues were fixed in Mono. Software Description: - mono: Mono is a platform for running and developing applications Details: It was discovered that the Mono TLS implementation was vulnerable to the SKIP-TLS vulnerability. A remote attacker could possibly use this issue to perform client impersonation attacks. (CVE-2015-2318) It was discovered that the Mono TLS implementation was vulnerable to the FREAK vulnerability. A remote attacker or a man in the middle could possibly use this issue to force the use of insecure ciphersuites. (CVE-2015-2319) It was discovered that the Mono TLS implementation still supported a fallback to SSLv2. This update removes the functionality as use of SSLv2 is known to be insecure. (CVE-2015-2320) It was discovered that Mono incorrectly handled memory in certain circumstances. A remote attacker could possibly use this issue to cause Mono to crash, resulting in a denial of service, or to obtain sensitive information. This issue only applied to Ubuntu 12.04 LTS. (CVE-2011-0992) It was discovered that Mono incorrectly handled hash collisions. A remote attacker could possibly use this issue to cause Mono to crash, resulting in a denial of service. This issue only applied to Ubuntu 12.04 LTS. (CVE-2012-3543) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: libmono-2.0-1 3.2.8+dfsg-4ubuntu2.1 mono-runtime 3.2.8+dfsg-4ubuntu2.1 Ubuntu 14.04 LTS: libmono-2.0-1 3.2.8+dfsg-4ubuntu1.1 mono-runtime 3.2.8+dfsg-4ubuntu1.1 Ubuntu 12.04 LTS: libmono-2.0-1 2.10.8.1-1ubuntu2.3 mono-runtime 2.10.8.1-1ubuntu2.3 After a standard system update you need to restart Mono applications to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2547-1 CVE-2011-0992, CVE-2012-3543, CVE-2015-2318, CVE-2015-2319, CVE-2015-2320 Package Information: https://launchpad.net/ubuntu/+source/mono/3.2.8+dfsg-4ubuntu2.1 https://launchpad.net/ubuntu/+source/mono/3.2.8+dfsg-4ubuntu1.1 https://launchpad.net/ubuntu/+source/mono/2.10.8.1-1ubuntu2.3 . Several vulnerabilities in Mono have been addressed for Ubuntu versions 14.10, 14.04 LTS, and 12.04 LTS. Ensure your system is up-to-date to maintain security.. Mono Security Issues, Ubuntu Security Advisory, TLS Update Information, Mono Update Steps, Client Impersonation Risk. . Severity: Critical. LinuxSecurity.com Team
Researchers at INRIA and Xamarin discovered several vulnerabilities in mono, a platform for running and developing applications based on the ECMA/ISO Standards. Mono's TLS stack contained several problems that hampered its capabilities: those issues could lead to client . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3202-1
A hash collision vulnerability in Mono allows remote attackers to cause a Denial of Service condition.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201405-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Mono: Denial of Service Date: May 18, 2014 Bugs: #433768 ID: 201405-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A hash collision vulnerability in Mono allows remote attackers to cause a Denial of Service condition. Background ========= Mono is an open source implementation of Microsoft's .NET Framework. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-lang/mono < 2.10.9-r2 > = 2.10.9-r2 Description ========== Mono does not properly randomize hash functions for form posts to protect against hash collision attacks. Impact ===== A remote attacker could send specially crafted parameters, possibly resulting in a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All Mono users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-lang/mono-2.10.9-r2" References ========= [ 1 ] CVE-2012-3543 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-3543 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201405-16 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security ofour users' machines is of utmost importance to us. Any security concerns should be addressed to
Marcus Meissner discovered that the web server included in Mono performed insufficient sanitising of requests, resulting in cross-site scripting. For the stable distribution (squeeze), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2512-1
It was discovered that the XML HMAC signature system did not correctly check certain lengths. If an attacker sent a truncated HMAC, it could bypass authentication, leading to potential privilege escalation. (CVE-2009-0217) [More...]. ==========================================================Ubuntu Security Notice USN-826-1 August 26, 2009 mono vulnerabilities CVE-2008-3422, CVE-2008-3906, CVE-2009-0217 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: libmono-security1.0-cil 1.2.6+dfsg-6ubuntu3.1 libmono-security2.0-cil 1.2.6+dfsg-6ubuntu3.1 libmono-system-web1.0-cil 1.2.6+dfsg-6ubuntu3.1 libmono-system-web2.0-cil 1.2.6+dfsg-6ubuntu3.1 Ubuntu 8.10: libmono-security1.0-cil 1.9.1+dfsg-4ubuntu2.1 libmono-security2.0-cil 1.9.1+dfsg-4ubuntu2.1 libmono-system-web1.0-cil 1.9.1+dfsg-4ubuntu2.1 libmono-system-web2.0-cil 1.9.1+dfsg-4ubuntu2.1 Ubuntu 9.04: libmono-security1.0-cil 2.0.1-4ubuntu0.1 libmono-security2.0-cil 2.0.1-4ubuntu0.1 libmono-system-web1.0-cil 2.0.1-4ubuntu0.1 libmono-system-web2.0-cil 2.0.1-4ubuntu0.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: It was discovered that the XML HMAC signature system did not correctly check certain lengths. If an attacker sent a truncated HMAC, it could bypass authentication, leading to potential privilege escalation. (CVE-2009-0217) It was discovered that Mono did not properly escape certain attributes in the ASP.net class libraries which could result in browsers becoming vulnerable to cross-site scripting attacks when processing the output.With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, or steal confidential data (such as passwords), within the same domain. This issue only affected Ubuntu 8.04 LTS. (CVE-2008-3422) It was discovered that Mono did not properly filter CRLF injections in the query string. If a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, steal confidential data (such as passwords), or perform cross-site request forgeries. This issue only affected Ubuntu 8.04 LTS. (CVE-2008-3906) Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 69922 a9f0b7017f1c264c002fec03aa2af27a Size/MD5: 2885 2a013aa7ffaa95a6a323b44f67ef41a9 Size/MD5: 23282797 46667182b67ad6074b3082ba52a40816 Architecture independent packages: Size/MD5: 4592 70ce7132c11000c70fb9f83961902680 Size/MD5: 4574 86a992b028bc55226285913b6e31841b Size/MD5: 21862 63ec66d4b3c9cb7730d9deccfb45b679 Size/MD5: 21632 9224f108dfc6cffd2822d0395170f13d Size/MD5: 723680 215e49510489481560c462c297c170ad Size/MD5: 874162 80773912f121eb2745d897f4dfd26a5c Size/MD5: 29842 0c41cf7a4db89c05c4c22a73331547ec Size/MD5: 31962 a40b6f953d7e3ae09c7d451b86e0c526 Size/MD5: 19442 7c48f80cbbd80fcd9ad9fd2094592fc2 Size/MD5: 44072 20a777649b60054c24651e9702fa31f6 Size/MD5: 44144 73d580b1720db5d9cd3b25b88bf0074b Size/MD5: 83258 3825cb06b5c4959a6c877b66bc951655 Size/MD5: 114922 5388582dab941c1ab4166357e0081a2a Size/MD5: 115766 ac6951c45fd957ed7c7a5527aad1913f Size/MD5: 58564 63a7c3e90433ab9fef04d26ee4fd0fec Size/MD5: 58626 4ccc6c18a00a476faff57f55d7bf9459 Size/MD5: 346945b21c963d6735281e0715f3c3f9dee1c Size/MD5: 67344 c1f53590e145bf96a86f0acca44fccc2 Size/MD5: 223690 dd55758872bca6c341176d99d88398ad Size/MD5: 290902 623a2cde52aa1cecd27f6afa224e52a5 Size/MD5: 60952 fbfbdc15cbedda5d137aefa0a148cc0c Size/MD5: 69642 68244b848bd0f349c2a96300f8fe6d0e Size/MD5: 397614 4300e6ba0e0d3d76d4a072fe6af86d06 Size/MD5: 808330 6c89c227a87f17333d5878463bf7f00a Size/MD5: 906060 85b4302b4d9efcb12b6fb12d53604176 Size/MD5: 1389958 fb434a8ff3527608cd0c98a8775c6ba2 Size/MD5: 899068 117af06dd2a99e51d0c36d2dadf7d497 Size/MD5: 1220636 7c1702946a318a962ed6f74e096aa6f8 Size/MD5: 375762 b6be1c2b82515f4dd8ec6cac79e7a8f9 Size/MD5: 212948 57caf99f17cf64720cf9706f244d5726 Size/MD5: 358566 faa7d9add05dfd54e4ad217457d164d1 Size/MD5: 185312 7b78c3b6a18a9aafc6235cff86748367 Size/MD5: 11846384 b486669448799d4bb4636326a2470c9c Size/MD5: 14236 19e39a5501554f02ff921b26ac7e115e Size/MD5: 357470 631dc951215756f01d01daa1bd2f2078 Size/MD5: 323864 6b9d89cb54551d0e39d4d8441be7c114 Size/MD5: 43902 df23574ff1eae86bf33686865d5b2cfb Size/MD5: 43978 713c88034f98663229712b846611f1ac Size/MD5: 111668 cb2a3481cab9ef76674a8f8430d534d1 Size/MD5: 757308 fb45358ccded34de7e2942db22b34a54 Size/MD5: 7340 db01aff901f11e55b75245c5fa622d03 Size/MD5: 7602 84ce98ed2e6a2d4e8c95261dcacb52ca Size/MD5: 30250 91d8047e8011751146654b0ca26810f4 Size/MD5: 186390 6cf010807929a609d70533b3fac0c2d6 Size/MD5: 374870 f6d8b4d5a8dba98e8a5562254ddd72ad Size/MD5: 378894 4f8998db05fa3d0f04f659082df23b79 Size/MD5: 101488 50a25efa5823f05a001e6111101e3035 Size/MD5: 101552 ca377aed627d91b992a53df68a1b3f85 Size/MD5: 113890070ecb284ece134e7b421e20e7529daf Size/MD5: 130086 a59153c5b873f66bd32378060d4950b2 Size/MD5: 130100 09e0e43699182baa95f37c492f4ef7ec Size/MD5: 66356 e5d9f31836975751ccd5179d5a783069 Size/MD5: 66452 d0cab4cdaa0c48de0e0ed12cc8bf196f Size/MD5: 53368 46dc60f898d7a9fd1d5c6ec1b4f80627 Size/MD5: 53572 32bf235b600aea7531db43ab09c3da30 Size/MD5: 83748 07054722fd153b85c7eeb649834bd23d Size/MD5: 48578 52105d95a7312b279fc26db161254b4f Size/MD5: 48646 9842ec235c32dbe56b0781af0aa2ef48 Size/MD5: 19260 2fa786cfa9674fff4195fda49030db1a Size/MD5: 19224 d4a55eb941260965e50723e655d610c8 Size/MD5: 27346 616303a28f96d9c60c5d4df92f540c42 Size/MD5: 27414 b42e870b3586b6b1209cb0b374b55ab9 Size/MD5: 240436 ca83f7dbeb5f19cf9186bd9d447db97c Size/MD5: 9220 c8eca197304c211266a91364b7b00770 Size/MD5: 9270 b04ad66a1b5c9ce00f3bd0047d5e0935 Size/MD5: 8390 17271dd10c6c86743b7b2de3e2089a28 Size/MD5: 344898 9bf5aaa52c99aeed25381c7ad78d2644 Size/MD5: 23792 fdd1f87e54cc58ad68ccdf372885e7ef Size/MD5: 19080 5c071db78077424db6bcdcb8ded9d98b amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 1264548 ec574ae7338bb2e9a96d58a1660215cf Size/MD5: 1976760 af8e15588a1721885392000492a29683 Size/MD5: 917954 6ac8fe695cbca0cea07938b4cc93d336 Size/MD5: 115544 8cc0f866786aaf875bc20fe371cdef7a Size/MD5: 70068 ee7c3aaebe1435a6223f40efb1244d0b Size/MD5: 1863192 2a78ce51bd46262b59d467f7c7a5436a Size/MD5: 819158 3bbad38dd0bc9d185592e9bc89176439 Size/MD5: 25752 2ad000fc8dd3ca805ee9f18772bc2d3b Size/MD5: 658778 3b73db21553d28dd3100793b89f9315e i386 architecture (x86 compatible Intel/AMD): Size/MD5: 1186212 d3d3f460e50d6df695fa1bee44c8fbe5 Size/MD5: 1888386 957414e738ddc610060b0570da6db58c Size/MD5: 872166 b1a06d9a3aea68033160f828d2247fd8 Size/MD5: 115020 467890dbad51fd4e083bd8e933cd6ec3 Size/MD5: 63400 5edf0b4b6b2811847d4617c3410ab1e9 Size/MD5: 1769422 6d357678fc63ffd413e6e731c03f79ad Size/MD5: 759054 57d212d929847593de3f26017384f117 Size/MD5: 25752 56e8684e0d91578ee48e5da6ee12e485 Size/MD5: 624008 01cfe65a58a4b09705b1759e4589c60b lpia architecture (Low Power Intel Architecture): Size/MD5: 1178852 71606045cfca7f900066101299c909c7 Size/MD5: 1917278 d7c0db6cc163352fe1e35289814441eb Size/MD5: 868490 8ff985bb13ded63bf94ae77a789b2ec1 Size/MD5: 114952 71687943731701b84c833b58168f5869 Size/MD5: 64102 fa779fe853121472f9e2cba6bed66ffd Size/MD5: 1791814 e99f9d0d28b7bcd9e21ff3c2c5fa2efc Size/MD5: 763266 1a2eea1aba1824f242953a5bfedd1ecf Size/MD5: 25752 cdcf279856fdf54c6056dda394a3814b Size/MD5: 619750 c053015879c4266f2780e196ec645db9 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 1232348 0e54b2235b491ea5dcc7453700dcfd4f Size/MD5: 1894932 b60139893b4c7e590eac14e5aa6ebb4a Size/MD5: 902618 839652db0bb89e11f30ef8316c5ab18e Size/MD5: 118552 2da1e61013a3c67fec76125a08ed61aa Size/MD5: 68818 59a4ef82179374eb4ea275620329c836 Size/MD5: 1770266 a6d05351e1c3712780e98fb8df4290bd Size/MD5: 790438 79233483445a22ef62658013477aded4 Size/MD5: 25756 361c05e081e840536adbebda432b23ce Size/MD5: 660760 f20c006ef1f1ed7996606a5177096d65 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 1218244 35782472f6a4a6df6253bce358439df0 Size/MD5: 1788590 5b9868304da9f1538ad83fa1bc0d66a2 Size/MD5: 874174 1ff378d2ec82758585e365dbb4029cf7 Size/MD5: 115508 60170f6b2dcb9ec2445060c479cd7066 Size/MD5: 66004 34202aa75fae3ecb7332c61310cda937 Size/MD5: 1662110 0302daeb36a5a838f9704a0f1e15246c Size/MD5: 760130 e6dff766dfb986535a0b413849306efb Size/MD5: 25754 279dec99754e0961854f26d83f1cb45a Size/MD5: 621334 d836ab8252f23bdbefd26e55e6fffc0c Updated packages for Ubuntu 8.10: Source archives: Size/MD5: 142716 55055b28f4744e1ff3f14b33d36ee648 Size/MD5: 3304 e29e7a0315b0251c416efd1816370932 Size/MD5: 23719608 1526faad813bab17de2dc8b3749a9e66 Architecture independent packages: Size/MD5: 4608 ba84b01f31935d5801d90ba7d64241ec Size/MD5: 4594 109fb75abd6c4f6c169dad93399a085a Size/MD5: 21820 28f5a94851f7a7b0144bba34e62a0fef Size/MD5: 21618 b8239fd3c557909f250b67005d0093b4 Size/MD5: 723020 227cd4cd0daf8b97ae8e07860f3804f4 Size/MD5: 879634 444238109068ee27d479fb1736ddb246 Size/MD5: 30164 e9f1df0cf051712ac05c750cdaa3a8a4 Size/MD5: 32326 e1ab73fc3bcfeda57bff6168fc7870cb Size/MD5: 375204 377036d48be91ac772d7bb3d85bd6740 Size/MD5: 379448 be24d4b708a11331b06f7bb398c2d3c9 Size/MD5: 32474 a175690f60b58eed9e728b25a374b16d Size/MD5: 56850 18771aa7acbceac85d42a8468aecaa3a Size/MD5: 44076 bf48d7c99a66e297503766b1200ae8a0 Size/MD5: 44180 7a28c85cf33296559f4abb3537a0baa4 Size/MD5: 83778 977a95f88917d1ef9dc7d5095621c545 Size/MD5: 115190 eca21c1cf8ab1aa1cb19f45245bb954b Size/MD5: 116060 020c569dc609a558eb7ee9ca9a272607 Size/MD5: 58570 4d7e7bd3141b2184eb671815af1ff9fc Size/MD5: 58614 4bb1ff9aee869728c21510c5c6b6ea2d Size/MD5: 34552 82e62dfbab99c5c3ec42b21c4b74deec Size/MD5: 67434 3f2170d30c2b27834944263c1e683134 Size/MD5: 223494 dd0cd9819d848c5930708deabfc5ad91 Size/MD5: 290508a6e3fe39752f60fa6686eaf2b8ae611e Size/MD5: 60970 85c78b1c7aa0a6e7deaf55262f1f364e Size/MD5: 69776 c10ab6339fab783c61fe28d0a8de93c4 Size/MD5: 400694 12b0c7e4382a4329c710218c6dcd73e3 Size/MD5: 838736 5388b76a521d5439ee2f2150f98ebafd Size/MD5: 908262 d72c4d8d59ea5b3c4dd2c85c3abaa87e Size/MD5: 1440136 a5abb120bd7d61ca67c4e0f230f0ba00 Size/MD5: 917098 41e6e975f89325352d2e8b8897bd88d2 Size/MD5: 1253716 9062d36cc6998a4c5504d2302cdd7511 Size/MD5: 375828 655edcc09b42d23127574a96d98ebb87 Size/MD5: 219342 f631697c79fea2f4e30538c382c29380 Size/MD5: 360138 7845462c8f5592ea7b5514bd07e9721d Size/MD5: 185742 7e66eaa7e0d3c5f4fefa3f89adb3555e Size/MD5: 12052524 50f736d1caaecb1c603f5193104dc151 Size/MD5: 14488 8146b51c3b93994d1c6889474b3a7dcd Size/MD5: 361700 6aa99259f9de25b4f4c01bf761e8fbcd Size/MD5: 341054 64f22cab2a995b6b1d026550c43eddf3 Size/MD5: 43824 081cb1b0e10e866957fb2e758377e1f7 Size/MD5: 43908 eec7078c19eabe038c803026cc3b26d1 Size/MD5: 112680 8b848544232a3285d84dcdaf7ca38873 Size/MD5: 733262 8782488d4718b67e6302ce8320280511 Size/MD5: 7374 93f8ca4771039b6ccd337a2e1d725124 Size/MD5: 7632 32b567df7ca758bb14617642ecca9247 Size/MD5: 30176 7ad521e398c3de81781878ff3ff47749 Size/MD5: 186304 7bfb7a681e9af810733b7a02acf6c880 Size/MD5: 101508 9e38ecae09aeb22db794e18e7bbecfe4 Size/MD5: 101646 2027beb1beaf5b08de3b92336312a76a Size/MD5: 114026 b1c0fab6991156034701d404075d1c20 Size/MD5: 130140 95f7baaa88b0055912157519dd324562 Size/MD5: 130172 eab4f191c4ebe9848ad9b9f66a8c85cc Size/MD5: 66254 7124894562b7dfc5d8b09dc8d9fd4f28 Size/MD5: 66386 9f178b2533c66cd45061395b11901597 Size/MD5: 5317489dc9e4629bf8b4d8cf597653089b692 Size/MD5: 53362 bb9554c7cbd4efc76d839bdc2bfe01bf Size/MD5: 84278 cadf61981c1d49635e5741ebca4202f5 Size/MD5: 48572 f13eee5764378f96a2fcd2f02155709f Size/MD5: 48654 6bd4d7986efd49e65ecd6f35ddf9b66b Size/MD5: 19224 fc685b422ca23ded50722c52a3936015 Size/MD5: 19220 2da7e294b0bb2b92b0710a3049587c7a Size/MD5: 27396 2f4ac0a232ed3bebf7ffeed96cc4aa5e Size/MD5: 27438 d3accf89497c1b2c3ab81c19029470b1 Size/MD5: 255264 cceb7ccbf7cfb1dfdcbd4c69353aad84 Size/MD5: 9202 24c8d1a6a920bc38ab9f1f829ddec2b0 Size/MD5: 9256 c8efbaae4422d131be5ac8496b14f069 Size/MD5: 8776 7285175c5b2db0981ef1831907c5b39f Size/MD5: 349084 5a08e7cdf64c7d5829c2e5e70006b564 Size/MD5: 23812 e618c69db95f9b43c2243c02f9e4b0f5 Size/MD5: 19098 47331c3a616db4b99ee05442b09d692f amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 1329156 e90bd6aded66a9aaead145cf5bcdec1a Size/MD5: 2094958 1e1107cd773e567a205799b5c18e5074 Size/MD5: 975630 043d6712d05e6ca7028ef59fe23620d6 Size/MD5: 118598 b859999b55da0311cdfd7b3b12bd34ef Size/MD5: 73340 28f28260b0bdc2ce119990af4eb8d12b Size/MD5: 1974944 cfdded783fb02f0ec97febda747e12f1 Size/MD5: 864200 c037016f891b08de3ea2a3030bbd4e3f Size/MD5: 27634 9e1b32ee13c2880d44d6495408c59e92 Size/MD5: 710838 b729b1024dfdbf2cb9f16f45e0452ef6 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 1251248 5af8423736f98ebfb7fc6a2f25b0c7d6 Size/MD5: 2008266 0a5f8749e0c8202438b2c3078348980e Size/MD5: 922620 daf2c6dee9b8ede760941b01959f09a0 Size/MD5: 118202 9f21e4a3376df36b0c5e578cd76b3f21 Size/MD5: 65882 91c5378509f5829f3cf202aff8002c58 Size/MD5: 1875754 afac0a0da241aa5d2a443a2d180b344d Size/MD5: 801934 f8b677ac56ac8e0b7161072e37b5241c Size/MD5: 27634 7bcbe2d4bf28667373b2bd13bf5ba1df Size/MD5: 666672 1555d0dfba01e49acf019d18ba62402d lpia architecture (Low Power Intel Architecture): Size/MD5: 1237868 214ee8a34fe0b7acb451252ae589a3b9 Size/MD5: 2038160 2ca4c54f3884bb3d012314523800bebc Size/MD5: 916130 1e52a6d6d99ecfd3216eed4fee47ab5b Size/MD5: 118116 3c3097f7402dc834b334dacbd98be0b1 Size/MD5: 66452 31c62575257d172699d1c0d7c9483a4f Size/MD5: 1904820 c73638664ef8bdd47d3091cf0c3170bb Size/MD5: 801994 5b8cab920c58034a9c9494d5872b903b Size/MD5: 27632 d1fea4d77901e3053f70ba8700ef54d4 Size/MD5: 662516 2703fc59ad0e076f6e588fe7be944d08 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 1287952 69ea69df4de529145fb662e3394e1b96 Size/MD5: 1988920 53d9d7b2163514565c052a9d143fde3b Size/MD5: 945090 04978c0a91e67254d71c2d0a4c785a80 Size/MD5: 121264 26ff9e29a5c6904d166d13f7723372e8 Size/MD5: 71498 58ecec1d4fe7b0361a4be8a4c55e7621 Size/MD5: 1856128 727f21779d893530b8594ff4e8003570 Size/MD5: 821648 7a02163e9cdaaed844ec84ce4567498f Size/MD5: 27634 cc73501908d8da970ef5b0018c303388 Size/MD5: 697630 258332fe397ec096e4672369268ead68 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 1278588 ffa34e6f45622971614e4ef5818f30c9 Size/MD5: 1864962 40e7832e6dce92b774dd3b0d3e350803 Size/MD5: 910730 a898d3835d2824c1c2c66b2c2cfc0ea2 Size/MD5: 118868 cb145574e6337d6c26c8e346235c4ad3 Size/MD5: 68968 19cfb0564815c1e030bad7043b4dc4cc Size/MD5: 1736930 48b9057cf4d3921c1156cf54605b54d0 Size/MD5: 791486 8bcbd64a55c3f258ce50a41d796e6d09 Size/MD5: 27634 60c423a30d6c04b36f2dfd1cb8aa1b30 Size/MD5: 66479646dc7209764410c09aefd556e6945ca8 Updated packages for Ubuntu 9.04: Source archives: Size/MD5: 81497 18b836002d03c7d0ad6fc1c51bca4923 Size/MD5: 3496 dab82b37cd6d98297e718202caffe5f1 Size/MD5: 25715385 bd9b9582262d3f90dd32e1b5a0c8325c Architecture independent packages: Size/MD5: 33304 bc105dc4753e5942ce9697e34928423d Size/MD5: 51172 b430565b92be5b52594054ef94babef4 Size/MD5: 755000 4249aa19472b3ca5934f6d7bc1b53890 Size/MD5: 912214 25a27b1d105c7427f8b4fbdae37d6433 Size/MD5: 58580 9cfb09a2350201c67d41549a096aa0be Size/MD5: 61906 6c2885cca752890f20fd0ad1660c710c Size/MD5: 115522 5cf9c84eb8bef10298b0b297ab1c261b Size/MD5: 116164 4690202c4c8eaef2e68dcc831bd0506c Size/MD5: 49502 f2193b88024e7389eb79dcfb0034a4a4 Size/MD5: 49562 8e68739733328ee73377e80de969e122 Size/MD5: 404500 4aa95b7b0db27dbc83ee41fe9533c5ba Size/MD5: 408614 3b9e40be47ec9ceb17f47760fea8e0c9 Size/MD5: 85378 7f32e491fc2e5c9c642e82f179451dd7 Size/MD5: 72792 6bd0ff35d72dda1b3ff4804216750327 Size/MD5: 72870 8a8b0b7dca429f3d8fee99776c5abc32 Size/MD5: 102982 ba1b2cc9dd7c01de6c225a5b3dd55b12 Size/MD5: 103174 2c1801da3bbe6ffe05792792a4e99e43 Size/MD5: 112560 2aad883913b958d93e9ac00daee549d6 Size/MD5: 112990 c501fc024ee0fe7d68343c19f36727e0 Size/MD5: 144536 c3a51ec1c29a252cb8cf25fb9da20459 Size/MD5: 145466 c7dcdebc5a7601cf468019ba27cb33bd Size/MD5: 87094 d63a3dad0c8df58f531e3b98939506d0 Size/MD5: 87192 67d357922f070a24b0e6bc08de1ab8eb Size/MD5: 63392 da04afd99584cd6d0e4db4b59776d145 Size/MD5: 95814 f97de022f597a8eab94c5414e8ac896a Size/MD5: 253702 cbd06748305544e327e7c3ad9e154ed1 Size/MD5: 346642 1284d6717f94624161c298a7a18857d5 Size/MD5: 108408 f9a0159cfb5dd03fa1ace653a46e2040 Size/MD5: 113196 e9e1c05748f9f9ceda0b0593587af0f3 Size/MD5: 437970 5396833080baaf29e8d4ca0818114ebd Size/MD5: 1207474 6528a046269872d7380c5b9b4fb6da65 Size/MD5: 948444 fd294ccb2f6eea6044abcffb206eb66e Size/MD5: 1498498 8448f63b4088681399915a90f22bb6d2 Size/MD5: 81798 1a97f9c608052aa9b6e0be460eb3e626 Size/MD5: 1195414 55aee52fb41adff512c9861bcf58c179 Size/MD5: 227584 21af0db284c585fc9acbc1548f4b89b0 Size/MD5: 68818 0f836e5ec5bb88fe371e5b64b87b7363 Size/MD5: 193828 f572b326b2546c99b737d1291f196a7f Size/MD5: 42576 a9d6e8b8119cc5b8e667466113aa288a Size/MD5: 224510 6e5d9348558436115dcb77e992737d60 Size/MD5: 42636 9725b3003d8bc1e4568b4f680b99588c Size/MD5: 248018 eea7c2385884d34ff2afbf3ca979a923 Size/MD5: 34702 cee3e3a6d6a7508987587d1e2c4612ed Size/MD5: 399130 169cccc6ffdb7c749c2605af59707494 Size/MD5: 380522 c632eff352a48a414ea2efc6d2083807 Size/MD5: 33296 bc92f9401cc9605c27d15f8160f53d37 Size/MD5: 72268 ecc81fb0e7d400e1fa3d4239e958131f Size/MD5: 72352 8bd72c497c63f6ed98f035fe268978ad Size/MD5: 135666 2882bd9d9c78cf9d2772662082fde9bc Size/MD5: 51280 ac9b0e10ade7ff656b10772db2ca82ed Size/MD5: 764502 64176bdee1e6976112058270573b1987 Size/MD5: 36024 8bf56c97d0d4e71c1a8e880fe5a1c036 Size/MD5: 36386 695118d8529dda1429b5010687008413 Size/MD5: 58954 53eb0ec00b948c26f08ab7436327c3d0 Size/MD5: 214822 31e79e0272d6cdf07cf65cc895966951 Size/MD5: 130180 47c548ec132a28165df94bb3802b94de Size/MD5: 130332 a4a6878d1ad60227c997fe073a997c28 Size/MD5: 143290 cfe92cc572c4c3ce69a3d60b2ec2ff72 Size/MD5: 158684 970166e8fdb49bbeb8ea46b5e1647e78 Size/MD5: 158800dfbca7240d1a705be0661b46d4c1b877 Size/MD5: 94652 6526f5a0a445aa57193d78cce4c85eca Size/MD5: 94814 d0af2a0c64c7de2165104237ba91be88 Size/MD5: 82568 2112261cc36a9d355743aaefe5495013 Size/MD5: 82516 bb00ab1a4aa0f0674e70491cceb64810 Size/MD5: 77020 c5021bcf77df3d55677d079e59f29ed4 Size/MD5: 77076 3fb54b6aab36c3315cd2fa5e8ead3724 Size/MD5: 47522 b4a2487592242cf7cb84946248bc9ee5 Size/MD5: 47688 bf08521afc8f259511f51c6e4e6aacd3 Size/MD5: 56002 f147cd22bd6271e81007a049aba4b895 Size/MD5: 56126 602b076c396f66899c4ba09181e24bac Size/MD5: 361332 a8da43bffc4f1d6f80b0b99f27b9b71a Size/MD5: 852504 33c55b11c703efb31a24ee37b1d85128 Size/MD5: 37592 59547a486e90218c1a3c835d116e8e25 Size/MD5: 37636 c4370e81aec4254e94781e52bc7304f9 Size/MD5: 7337830 4247a37d9190c7676d36aa53f7741274 Size/MD5: 37248 5aa3314c73173339cdfdf8fe7df198ec Size/MD5: 385512 264f9bf3aa5cf1581fc5a0ae318a322c Size/MD5: 52154 958ee1216c007b7edc54ac6a3d707cae Size/MD5: 47006 2282d3e50bcfd1ebcc35a18fb89108d3 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 1562250 72be1a9e4223fd13cc5351433655d39b Size/MD5: 2297668 d636e50c2b899078ed8f2f1226da63cd Size/MD5: 1106762 850fbdee7e0d35767bcf3830f47fa94f Size/MD5: 29564 c9673ec8356404d6f01bf903c36ec8a2 Size/MD5: 121816 2c2f0d074832952602c5306f209d5247 Size/MD5: 75276 35f8727c950f15b226e32a7d8a5741df Size/MD5: 2165622 ec089784e5c4bca250a99107247019ae Size/MD5: 999962 b5112892b7f9570c43c7d600da83ca2a Size/MD5: 29558 4742f569a80eaff6b473e58dc1c30c6b Size/MD5: 787764 9ca8238776ecfdf17889a924cca57fad Size/MD5: 29564 000412964d8e5a49d23dc35ac62d8485 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 1452870 c061ecd44231b5e448a07684288a09bd Size/MD5: 2200324 0a61ae250f0514e33d5b4680657fff7f Size/MD5: 1047484 ddc62b01733e12b346f6abfa211d0340 Size/MD5: 29560 7b4b5461c4b8003656632592973273d9 Size/MD5: 121434 e5f501499402beafcb0d80bb1c6310be Size/MD5: 67810 50e2c2c273d20c68fa3f1a6d0e6fb381 Size/MD5: 2055110 d6bc7f4f23fb7ebf7978c0da9d9839c9 Size/MD5: 924300 586119e15638d780d9010126e7d0f5bd Size/MD5: 29550 d879b6a5b5338a7ee5814615cd351b41 Size/MD5: 743582 4e5ee28dc7d3be711951ab88e4b120a4 Size/MD5: 29560 9201916479d6adc1921fc2ca4b836b7d lpia architecture (Low Power Intel Architecture): Size/MD5: 1442798 4d1eb0ca174982579284acd78c995cdf Size/MD5: 2233698 cd135d64be73483384a1d1bc8c2f7c67 Size/MD5: 1039538 c9740c6851c6e69f25ddc8a47bdfd0d6 Size/MD5: 29558 515159eb4873b4f9f87a95247f9bf334 Size/MD5: 121370 527fa244d119328d6fbd7759e41b92c8 Size/MD5: 68372 061eedfdcafe8e298a5f695d17ac7085 Size/MD5: 2089888 4a4a6e3e9a229f1b74adec5bee4dd9e1 Size/MD5: 925340 aabb963031d7ce490195abe51e941cb4 Size/MD5: 29550 9339541a0f459d934c1c39452079a464 Size/MD5: 736122 3693473a91795fadb62761d8243f3208 Size/MD5: 29562 2faaa997337a8b5b11fdd1ecc0a3aa93 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 1540582 6880db7f7559fe7b96d10ba6d0aa529d Size/MD5: 2175780 5426529b1f143163e5086b4d69d35571 Size/MD5: 1084078 45ece5563209bcb315eb1c3254f12e8c Size/MD5: 29568 10baf819e9178629420c19ccf246760f Size/MD5: 124400 9892656651a7e298b915b202db77069a Size/MD5: 73426 0164e28e888cad71b6938d06d45a9176 Size/MD5: 2027816 1c407e1ff9aceda7c6f38261d0707afe Size/MD5: 953918 ca11363160ede056b58db5a16c511eed Size/MD5: 295620848cbff7f39bcbb946a506d498353bd Size/MD5: 780586 9184b1d7c661e4c247a4faf7cbbb7083 Size/MD5: 29570 0fdfea27d1983a1a987806af6ba19268 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 1465574 2dbd371627ab55972c1a8d3c463e6319 Size/MD5: 2034544 8cafe3862c007a27a0528b606195ea96 Size/MD5: 1047948 7fdb6d51ed881544130b8e969b32111a Size/MD5: 29566 c4ad59d6ade09d5868ff605ec52c0deb Size/MD5: 121940 41bb30940f2add0a6564fa90a8dab111 Size/MD5: 70864 c6a9a0a2f5c309be6e4ac9d662428b60 Size/MD5: 1892098 726669f094a63e0ca42de3e4f519ca2e Size/MD5: 921950 f37bf3368437ebe22ad5a15fb3d59ee0 Size/MD5: 29558 f70b34a9c6ff48e318ef18b83d8e4fff Size/MD5: 749296 706f1054245161eff927d1565ca16e2a Size/MD5: 29566 fe5a94944020e3203226cd9f2870cba2 . Keep an eye on critical Ubuntu mono security patches that target vulnerabilities in authentication processes and cross-site scripting (XSS) issues.. Ubuntu Security, Mono Issues, Authentication Flaws, XSS Risks, Security Updates. . Severity: Important. LinuxSecurity.com Team
It was discovered that Mono did not correctly bounds check certain BigInteger actions. Remote attackers could exploit this to crash a Mono application or possibly execute arbitrary code with user privileges. . =========================================================== Ubuntu Security Notice USN-553-1 December 04, 2007 mono vulnerability CVE-2007-5197 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 6.10 Ubuntu 7.04 Ubuntu 7.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: mono-classlib-1.0 1.1.13.6-0ubuntu3.3 mono-classlib-2.0 1.1.13.6-0ubuntu3.3 Ubuntu 6.10: libmono-corlib1.0-cil 1.1.17.1-1ubuntu7.2 libmono-corlib2.0-cil 1.1.17.1-1ubuntu7.2 libmono-security1.0-cil 1.1.17.1-1ubuntu7.2 libmono-security2.0-cil 1.1.17.1-1ubuntu7.2 Ubuntu 7.04: libmono-corlib1.0-cil 1.2.3.1-1ubuntu1.1 libmono-corlib2.0-cil 1.2.3.1-1ubuntu1.1 libmono-security1.0-cil 1.2.3.1-1ubuntu1.1 libmono-security2.0-cil 1.2.3.1-1ubuntu1.1 Ubuntu 7.10: libmono-corlib1.0-cil 1.2.4-6ubuntu6.1 libmono-corlib2.0-cil 1.2.4-6ubuntu6.1 libmono-security1.0-cil 1.2.4-6ubuntu6.1 libmono-security2.0-cil 1.2.4-6ubuntu6.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: It was discovered that Mono did not correctly bounds check certain BigInteger actions. Remote attackers could exploit this to crash a Mono application or possibly execute arbitrary code with user privileges. Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 49205 1dd67806aca65f9361028e09dd03374e Size/MD5: 1047a78873c6a8c209662c0d876b6d879a3e Size/MD5: 18217583 330cc66c6a44525950daf10c4f17c10e Architecture independent packages: Size/MD5: 42114 d9468aca47cdaef7bfdc3cce1ab2f2bf Size/MD5: 3794920 6cc59c95508bd9971f33719d37c20f81 Size/MD5: 4560272 17398de3e2656fb89d09b1f2f8449864 Size/MD5: 5218626 393b657ce1a38b1a603fe23c65993f64 Size/MD5: 53358 723395e2e1f222bfda76dc881faef388 Size/MD5: 841202 cea877947f3960d4b28414aed8f17ad2 Size/MD5: 1415996 695b57669b478e29e68ec5bb8bdb736f Size/MD5: 4568630 0abb3f2083eb50f89e1f758e2da17aca amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 1127758 68aa6fa0b32092840b1eeba9d530e796 Size/MD5: 866158 930b1cfe55381048bcb8ca0cf277635e Size/MD5: 116086 05bb9c092fc343d2870ac40acd3ff5f1 Size/MD5: 42138 d3a0fdb1fbc5f6e508dd222af772b208 Size/MD5: 57718 6855145c4a21b5966149e8516357f371 Size/MD5: 12924 85c5ed6db4e482004dec0a86f456b891 Size/MD5: 1117728 b057e33056ef185d7c72fc94f4076b73 Size/MD5: 1208 ea00401b7fa2d180d4507a5903472170 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 1017424 16e907d0f4ec705f9e531472e902ea7b Size/MD5: 780644 82da2e40c22753a239720611c7094592 Size/MD5: 115642 ad5db117ef1b99b8ee937e8d4ec5041f Size/MD5: 42138 968053c1fa8d5b5104a20b570854c363 Size/MD5: 50780 9e696c5849576ce3a85b618c34cf99f9 Size/MD5: 12730 0f18bcb2b428d26286d015b60a2fc3c1 Size/MD5: 1015064 f73e6b95ae74a07f3c40f441b733e65c Size/MD5: 1208 500c384bf6d5d4eed02feaf667a027f2 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 1085244 9f50d724650b2a00e51a5186e59b10c1 Size/MD5: 816340 204552b8905f11d0d68aae4cafe6c5cc Size/MD5: 116566 56709bac6e14736ba40bd995745aec32 Size/MD5: 4214294156ecc65848493f8190978616178c0 Size/MD5: 56740 dde3a83d8d71856ef698291b25ba337c Size/MD5: 14786 8d1d24e6f51fa89bf77833643de98804 Size/MD5: 1103068 c20e394ee7afc1fefc7d87faf36941ec Size/MD5: 1212 85908383bd359508935165abf7c42b1c sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 1093166 5c4426b8b9257626a2c062aa27afbd1b Size/MD5: 821034 af19fe8fbea0ad717c22f12999907874 Size/MD5: 116192 7a99a9e1ae39d3252773278c26aff72d Size/MD5: 42144 592ae4e7234298d2352c050c668fc2f4 Size/MD5: 53732 d4fc061bb08f6fca1ef10a9c146a84ba Size/MD5: 12994 295d1cc07863114a07d0976ea4da1830 Size/MD5: 1049890 f5a689933567a3d7aa0c1704f4a30e13 Size/MD5: 1208 dfc76b9be008e2b9c80b011e18011180 Updated packages for Ubuntu 6.10: Source archives: Size/MD5: 41312 761b5ee11516721281e3737689a150d9 Size/MD5: 2303 d7723dce32256359d24e4cd19bb55673 Size/MD5: 19352812 072cb3de1f19cbebd6034f7a5cff1292 Architecture independent packages: Size/MD5: 19790 15e0f64abeed5625ae9bfed7c1ade144 Size/MD5: 19722 50f1745598427a9adfbcd2968e128866 Size/MD5: 45368 12f39fd312390e3035820c3ba7ada2e3 Size/MD5: 1845318 df586b0e7e6f00321154765fdd8b7eda Size/MD5: 2087008 5042bd84c67fba984f7f791758eaadf8 Size/MD5: 64880 4676fc864a6dcd5bba60257ab3edfff8 Size/MD5: 68588 d466f9b2b1bb7ffe347a8fda8f480d68 Size/MD5: 196336 dc8555b7be3afc3fd9843d3748c37e62 Size/MD5: 101046 0a16e0476ee4c19400cdc6d260c4f0b5 Size/MD5: 101084 6376135038f864934af1ba70539a0076 Size/MD5: 178624 db250d8d47d56f9bdc3d22b1e835e5b5 Size/MD5: 247186 000c3ef17b1badea2823b21dec56b2ba Size/MD5: 248396 84529a72091d84042e5491dc7106fa69 Size/MD5: 109776 0f14fb2778f18c5af9e3da93a401df57 Size/MD5: 131990ffd75301c216e462268b375f569e874c Size/MD5: 132042 161561e932f130dda0a84dbf21bd7da9 Size/MD5: 43186 5ef81f1010b2eab0336539d527260476 Size/MD5: 457276 c058bc410de9d9a422404adf22ab4b6e Size/MD5: 522424 ba59d5cf139b8a79cd8e7aa2ab5b62b6 Size/MD5: 118492 c2a5d7eb01f24c1f247466eb58061605 Size/MD5: 773202 467e0113e4e389a6857f05764bf6bf5c Size/MD5: 1414476 e600053c95554f34bd0582aebc4a40fd Size/MD5: 1747350 b9330cb9de197c4e818b80b5cbb9ad6d Size/MD5: 2286512 1237907a09b2823584041d6c8ee266df Size/MD5: 1364488 b4a86de871cf4842dd9857504265cc18 Size/MD5: 1563852 e8ec80ba7e8f32d087beb7fe3469cb33 Size/MD5: 403492 044ba9982ece13b53767ff37d2b92ae8 Size/MD5: 403556 1320f62f1d0f53355e75a1c56a5fead9 Size/MD5: 16016 3f29190d92de418e5833bf8f899a9412 Size/MD5: 29456 13d86792369653fb0dbb492ed4c73ca9 Size/MD5: 839556 5e1edcc01afed0139eacd627b15859a6 Size/MD5: 1012468 f3d80b86c04f92614a9e99f5b9a819f8 Size/MD5: 91286 9ebcae49a4e239bca7ab7e324978689c Size/MD5: 91350 020b3ab54f32f58d6965131d154b6f00 Size/MD5: 226914 31b73ea05e611db804a0e5bbf08cb6e1 Size/MD5: 45176 2bc02e4a3386b96cd62f529c66a1d6a7 Size/MD5: 24138 ee8d322366ac8b89fbf02176e0c56e5f Size/MD5: 24374 aa4b68924bc134150c0ccbaeae6d801e Size/MD5: 295626 de4d6c0e77ea66e4821d359d4cfef7ba Size/MD5: 221816 8762f42ffd5ec70d97b0105c04e8bcbc Size/MD5: 221686 05667dbd304d6b7cbc27fa98d83f9676 Size/MD5: 272484 5ddd4de655090ade578cd223565e9772 Size/MD5: 272532 e4497b1081e51c05c560b30b9b630661 Size/MD5: 130876 4a4e966de77c374b0d8d609bf97a76bb Size/MD5: 131078 714dce4aa31a93e92f6f243e49cd863e Size/MD5: 113288 2509810992723d61580c354a1e71bcd7 Size/MD5: 112780a334b79c178256a777dee3511f0effe4 Size/MD5: 179096 68dac2b4b32c82f731788b8f66ddd0bf Size/MD5: 109852 1aa7647283f490976ec732392e8a9de9 Size/MD5: 43166 663b55d1cfa5ae6b9771a9d713b1ebfc Size/MD5: 48154 792f305b10a01e7f362d1bfb2875836d Size/MD5: 48118 07130f1de310fbd8d42e7e984afce8d3 Size/MD5: 63584 51155730e58f273b5fa04cb6dd701396 Size/MD5: 63572 f5a5308c9c4b3d82bc07e504421f231a Size/MD5: 136064 ce2eea3667131739da8dbe40b16ef383 Size/MD5: 16000 b51dca28ad7b7e0fb1d5e2b86d758ef7 Size/MD5: 26214 466551f27a61092cb3a4437b02b2d2ef amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 1145768 b93d06ccbd8a1da04df3d21525c2d47e Size/MD5: 871572 deab12828a986cd8f8d93ba48b792c21 Size/MD5: 93530 2dbf62f5504cf62fbb08e0bcdfe05149 Size/MD5: 15976 26dcb8aa0aea4c9e848beafa482e4ba6 Size/MD5: 60070 4ac9955d8f4a17a1897ddb6baf474f18 Size/MD5: 753000 aea22983e9ccd961062fc87de02e7f02 Size/MD5: 15948 f9618e3071be58520fbfcefceb1fa2f9 Size/MD5: 1165026 39f30ca8d151f75fda0fe87c64601d20 Size/MD5: 1262 ab352de389f8a3d8c7ef795567b928c4 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 1076022 38d05b28960cacc5528245ab62af274e Size/MD5: 832070 291435407e3c67a2db356b4f914ee19c Size/MD5: 93104 f0cc7968608f2ad6bedf45aad00f9378 Size/MD5: 15982 b7dfed8a7c7c7ecb6f531d76af22dc41 Size/MD5: 53726 4efd6f3f1d8cfe48721c9faa9cc075ca Size/MD5: 697248 3cdf89c0b98ba0258ea11a8471e1d5bf Size/MD5: 15946 bd753c58bfc05f0fd65c292a4d5602b7 Size/MD5: 1107090 5651b5faaba79327ce58024c2a61b4ee Size/MD5: 1260 24efdbd40f336c82e85360a54f82966b powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 1109110 5e33e701a3e6d24f26b150acd2b44247 Size/MD5: 832468 40da31afadf1ee999e56298065b5f9f4 Size/MD5: 93962 467a94dd9e8963f23a1372d74ec7c6e8 Size/MD5: 15982 8b6bea392f883e37bf781bbfbac071d2 Size/MD5: 58782 4b8fdcd301d575963c665a88db727092 Size/MD5: 716252 b8c634dac109aa74da5e71a9032180d3 Size/MD5: 15950 08f08604c506fed9a28b0ed15a0aeb51 Size/MD5: 1160900 a80975550f34d9ab93fb3ee3713c4f39 Size/MD5: 1264 8adcc5f9ac48eb59c9229a11e83e6485 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 1124734 09a0b5466a993d604729cba21f37d9b2 Size/MD5: 839440 ac21c40809f1cc5b5c2a8a3ef9d0abf4 Size/MD5: 93558 887f446378a42bc2b30393619a43c3ac Size/MD5: 15980 7b6ce56af425487ab4ff31732b470a2d Size/MD5: 56260 bbc2661b4048a653db7630756d3d54af Size/MD5: 704902 2c13f7c82a438c5bbb5fb2ea32c72367 Size/MD5: 15950 c51bfa76061a2f4a438f27911af4b584 Size/MD5: 1110200 066875ba92f55267267d57eccfb3fcc5 Size/MD5: 1260 66e49849d82637b28f88e7516cc7a31e Updated packages for Ubuntu 7.04: Source archives: Size/MD5: 47621 cd897f3195db6c081a4e741b7df0edcb Size/MD5: 2452 ca82ee60f2f4e5adf65bc629acf46fcc Size/MD5: 20694945 4e4cdb6f98f1ea62bb1900f214c55e58 Architecture independent packages: Size/MD5: 22014 131b26450f33cf1747afde278c2deec6 Size/MD5: 21946 74d4cd7d1037fa64847519c6df87ff95 Size/MD5: 48860 fde5a1f531f39b3bd89c9b9213ca527f Size/MD5: 48656 956adfd5fd62f4bb8e8dce56bd19e38f Size/MD5: 1879974 88be3dc1d9cec8e85b8ae06ee2bd6c22 Size/MD5: 2144548 6acf9bc711b3b321b5ae174d62d770e4 Size/MD5: 67620 7fb13923a58cfa973ca2dcaf74e06e73 Size/MD5: 71376 ced0bdbc52bce2cba09a07a9e407cd06 Size/MD5: 226586 253cb8946440908cb59b66776e4e6c55 Size/MD5: 103062 a8525a2a52d35dbd3e7b0c4cacc29d56 Size/MD5: 103080 c569ebc6557469234f3cf3c5bcbc0210 Size/MD5: 179986 c974132fa48d5a1c345f38f095facedc Size/MD5: 252394 9838b79dd4b468943f0ab410946f2188 Size/MD5: 253568 bcaaacd962a89669c8d9fe4e4c736054 Size/MD5: 111964 3ffa06961558e4483212fdae835d851a Size/MD5: 134164 f2acbc2443f92184918c3c98ab9de4b6 Size/MD5: 134216 01de9830de8e2a32575c462b2e8d517e Size/MD5: 47110 7a9850142d7626b00794f703e677d478 Size/MD5: 55998 0dc9aa3d14d7718fea1b94bae23d6319 Size/MD5: 462328 72ece8d72a42e54cbc7284dfdbf62e00 Size/MD5: 563166 8a45c1608a35fcadbe051b015d6a4d5a Size/MD5: 121798 eda743d7fc277b8dbc39794dd104c79c Size/MD5: 139712 bf80c1d5d7bd846f17da32f0f7215025 Size/MD5: 791618 333430724f43b5378479fb698ee3e486 Size/MD5: 1575472 e06545176fd76beb8713615af1b5d29c Size/MD5: 1805890 85d9312224d8535dcf21c11512deff1b Size/MD5: 2466720 0b514eb292cd5d5c19896ed164a06249 Size/MD5: 1501014 c9d89231925a26671d3febe9bc1b48d2 Size/MD5: 1902876 8d0b889b8269cffb917120c470d72258 Size/MD5: 412734 e1e5b880522d47c3ff2bb538004ef610 Size/MD5: 412750 d68d7787541b7dff8f3ae0969e6f218c Size/MD5: 31966 5f2e745f03cb1b1ceb153572754069b6 Size/MD5: 882706 4709798914444b14fd520cb62608769b Size/MD5: 1047490 502702aa9438d586db51dc72f9401e8c Size/MD5: 93650 1a90e3cfe65aa520e2f140c7947e0079 Size/MD5: 93726 774841f16232158919895331d72197d0 Size/MD5: 237104 6101a28f5db1f4b1124266d4133f7919 Size/MD5: 26628 ab32b503762f29a97c455dcd554db885 Size/MD5: 26840 8b6b9efd3f1e2c9b77adec4132ed0dd6 Size/MD5: 298346 6222f6db6eb1a7c0f737c869155fda22 Size/MD5: 224878 7c248f659a539d9ff3fa0b2efa0520a4 Size/MD5: 224932 22d807e0c75c244ae139357bcdac8c96 Size/MD5: 2748200b9ca8e261b75d57069d5405b289947b Size/MD5: 274870 7321cff315431388d206f2f2bfd7e63a Size/MD5: 134646 8c508cf0406ff01dcfc844de50c54b49 Size/MD5: 134652 326a757a35c0474a997aa56ab0291f16 Size/MD5: 116912 f3ff44891c6da327f90d96a4cfe6b108 Size/MD5: 116434 0a9a02bad925f1319ed8ff0da213fa53 Size/MD5: 180480 b5d28848cdcd72a5e50f8316c4742f83 Size/MD5: 112032 e1c4d93a198e6c75e37da02f3ecf7ae2 Size/MD5: 50764 65f91893ff401482619b1f71b075105b Size/MD5: 50710 7ef70b0eaca84db0819fd5e5473c108a Size/MD5: 66280 5b8e417874db9e04f7d49f85fe318c9c Size/MD5: 66302 7fda24b95fda25d3a312f93c67e821de Size/MD5: 28590 b598c3db33e847a3137408a6c1c9b393 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 1160054 9793f7913c45c9c5ad2201b289b453d5 Size/MD5: 872514 9c86734c35784d72af074e32bd7f7d8e Size/MD5: 98922 101a536adcb35a8681c99e1e08f6347d Size/MD5: 18162 c5a85008ea6779a153ed1d9ee601442e Size/MD5: 62514 a139c143e11ea35a0a3716edc6387ca7 Size/MD5: 761144 87853b5708df1ad7ecdccc70c83cefec Size/MD5: 18124 91d4159f6231ea9275abdfd97c58ea07 Size/MD5: 1158330 21d562a70c2c5068c33af3e77b12f0fb Size/MD5: 1254 4c07d8202a0b2ebb14338edf1c53ef24 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 1076874 7578be98742ad2b74cddb564f8792470 Size/MD5: 800388 b761b2d4f9c9b94ecfb9e44862b4c276 Size/MD5: 98560 d32ba6bab17821c834b3613bdff55ee4 Size/MD5: 18156 e391379b597aeedd8a17fcc64f63b6d0 Size/MD5: 55968 4caf0a4657ae9c1e1a934c0b91a437e6 Size/MD5: 688846 a27b4cc0a303d04e8509a0bbbdb4e8e8 Size/MD5: 18128 0c2d17599aae62bec7d950a2c21710d7 Size/MD5: 1077216 4e64f4e62fb07d0427565a4d0280ed96 Size/MD5: 1256 af5d4000f80483ae05fba499a9bdb542 powerpcarchitecture (Apple Macintosh G3/G4/G5): Size/MD5: 1095250 d73a18c74c51788d7b6861dc4bf6ade7 Size/MD5: 821034 747e67a32d87c933003991b5e8ab1f6f Size/MD5: 99572 52474d115b4cf8fe5c1391a3d3a29496 Size/MD5: 18160 5d5c7ed5c8c249235df305bc01064d37 Size/MD5: 61562 fd0fcf3feb6b48d7e6ac2d968cd38717 Size/MD5: 682356 51f11710215f146cc2b3f6070b4c5a10 Size/MD5: 18130 4fdda57d271510d5d8f657ef227e025e Size/MD5: 1090966 44e365a5c6271cf4f7f18979ff6ca0ae Size/MD5: 1256 0d7432eff9d7712adfddb7b459fe1ed8 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 1151818 6885ab67def02ab6fe377cca6c887fca Size/MD5: 825326 5c11f932a69fa2ce7f88b2214f69819f Size/MD5: 99036 eaaddf39abd6aa3754a1850a8283fae8 Size/MD5: 18164 488fd864d5fa1158a3f86aec7475eb80 Size/MD5: 58562 bd5284e8679124b4e80572cde9467e37 Size/MD5: 702520 124fb06bca6d2f991a119878169c166c Size/MD5: 18130 4ea1951f47a5af86282bbbea9115e39e Size/MD5: 1093254 4a8e0cea9ec1508681837a9b9ecfabd4 Size/MD5: 1256 f4be19c54303dd9c469ffd9d1fe0c0fd Updated packages for Ubuntu 7.10: Source archives: Size/MD5: 57734 d130b3126e9f5f7bf2a8b1a02a2c6527 Size/MD5: 2484 e7027c6ee6f8c2a03c6ac657b0942553 Size/MD5: 22003350 933804f591cce706c7c8e2e43b0c0161 Architecture independent packages: Size/MD5: 4562 f524bc67ee8fc58f665b31a2d1e343b3 Size/MD5: 4538 e58206ccd96536ffd2b5116281122699 Size/MD5: 19230 96fdefee8bd93395a04fc5aaee61cb53 Size/MD5: 19078 0c3ddc8dbe1126079d91a7d746f7f8c2 Size/MD5: 1085538 6ec480375f85c6aab45050b9e2ef742e Size/MD5: 1222200 0e3d7c8481ee74d62b1d87f0cf717196 Size/MD5: 28048 b2b1d9458df367ad48839e037f353039 Size/MD5: 29632 a478e5939afe8914c7553029aae87a92 Size/MD5: 113434 d864c7956b19b7bd18358d9d9c5e7991 Size/MD5: 44050 9bdd5eccc1f71831703348891c1b0deb Size/MD5: 44144 a77d4e685cf811d2ac44b21b3af677ae Size/MD5: 83340 64f61cf09a8f249bc39c76a9e7f782f5 Size/MD5: 114074 25f6bf54d6f280f6fa4797210f945438 Size/MD5: 114774 6263b62ead55fc1ac8a6c6a1123c96b1 Size/MD5: 48544 a1725e7618dd3ebadabb23e17f9f1d48 Size/MD5: 58608 dd83d32101afbcf922ec188aeaa98ce2 Size/MD5: 58674 2b5e45fc0f6b6a926e454b93bfccf38d Size/MD5: 34502 ab48fe6e5da5998070b870a675d5e186 Size/MD5: 67036 235f3c55b2403093065c92676f6b4841 Size/MD5: 221936 f9e87d67bc0829b8cdc8ef942b14aa8d Size/MD5: 278826 d738e1b755fdf4c3e2538da4ce4b577a Size/MD5: 60466 011b7885b9c468a999423d245899389b Size/MD5: 69254 f263009a6a735abc5e2f32ebc046f756 Size/MD5: 389644 05fccce9fccec4ce6e20917b6816b50a Size/MD5: 793396 3fad16266a872d219e62b9d58036cac8 Size/MD5: 896328 719c356ebf4707e949e9dbadbd1f4728 Size/MD5: 1316912 eb2c23eaeeb7afb5b7e3a0bf2da68067 Size/MD5: 852100 c094f90fa8d708ad9c0ef57ef7bef922 Size/MD5: 1046878 c22ee62fb5c3a766fd17ed5aaca9ea05 Size/MD5: 212064 640eaef5f37177a52d8b27478f3a5bfe Size/MD5: 212662 354751e62bcadc90a6a965f4a729b0c4 Size/MD5: 9778254 1087f0938f08a6d48cb19664f2690462 Size/MD5: 14182 8526ff35afd2cafb1b93616b9a1c3bf7 Size/MD5: 511850 421b0534237a5522bffafcd8e71690e4 Size/MD5: 645124 5d294ac914fe57e9f6a4de27c6bc25ef Size/MD5: 43894 3a5bd6fed94e1e12fc3c8f4f4274d682 Size/MD5: 43980 4e535c74196c95f4fa4e94c342a7a038 Size/MD5: 111768 a6fa060f2ac14da94b08a2427be49ace Size/MD5: 7254 ef75957c3836080328e4b56f5ad45d6f Size/MD5: 7516 f07ccf0bae57e1517093d29729a35616 Size/MD5: 186410aac1f920872c34533238dae85ac3ef6e Size/MD5: 100192 c1eae4b2839bc6c0a6a5ee9802110c32 Size/MD5: 100302 4a9854539a44f3af406416bbea83588a Size/MD5: 130092 30b325738787551426b18a39a8482583 Size/MD5: 130132 724abd7fd9be417060b4ff6cafa89445 Size/MD5: 66320 b9ccac4b75eb03f19c34c2b196867615 Size/MD5: 66412 c6a1882596fb19e8fd7aac76d0a6a47a Size/MD5: 52966 a2c7092fdb79163579fafe02c23a6c41 Size/MD5: 52764 6cf7d5b74c48b69beef85d95fb13384f Size/MD5: 83840 9a0a89774757d88e79149f7b0e0ae7c1 Size/MD5: 48640 63fadd29661e21bd017888d4df9e556c Size/MD5: 19176 3789917bf0f032fd91fe8a5390e64512 Size/MD5: 19100 bfc918fa7117cef040dc5d948615cf1e Size/MD5: 27236 637f00080a5b150f087ec76088fb21c9 Size/MD5: 27316 e161a39081b74d5ff4051e298d7daf97 Size/MD5: 7928 890a484b67740c8ffb09416c3cd893cc amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 1158028 d54c2f6c309349e300956801dccf8559 Size/MD5: 1265758 b3382448cc43ab386d3a1252e2b0d993 Size/MD5: 847918 f80ccd0ab9c150186e9def2460430a36 Size/MD5: 108942 75d3063e242314d3957b2fb2ec44a9b0 Size/MD5: 1150 37d83f0c80c8fc5773ba1f347f12fd6b Size/MD5: 40452 497f955e865ba15898c4b5572f646f3b Size/MD5: 1201042 e6b94b487c929d5822a01a54f4639a3b Size/MD5: 771332 36fc03f7aad5a009a07c4df662967fb5 Size/MD5: 1118 b16051b3ee35866420f50d23425d0a4e Size/MD5: 1096836 282a37113b7e9adcece3f42667c3a314 Size/MD5: 1334 207093360b3af234f2caad6234915e04 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 1070838 485668cadf1da2a56f708a454beacca6 Size/MD5: 1225082 67b485465b897adb1532273580cc2bec Size/MD5: 768100 750445bf7425b43bf412a0f119e24ec2 Size/MD5: 108502 c3b8d104babd4d98192d59bf9e15ce4f Size/MD5: 1152 f43a6c9b38334d84d8d4a8764d54c660 Size/MD5: 33486 a5e3658a55768d0b9ffbf258086cbe60 Size/MD5: 1153972 103bd3aa6bc8b07689b7db1eb1b92b46 Size/MD5: 695556 6132c1b2b642ee0824c3e7cca1f5eb8d Size/MD5: 1118 2f5bf7e24ad487835129dc97a3fce438 Size/MD5: 1010288 caae8f119ecc89aa33e04386445c0462 Size/MD5: 1336 5bc806294d4e94106c1784b2d0536def powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 1087460 737e85350c7d6f37e73f8772a1fc14ee Size/MD5: 1214254 0d66654f94b9478c9b77b06f9329f880 Size/MD5: 781972 e93404211aadfd3b716b1b000d51a498 Size/MD5: 109536 9322000d4e24a14e4432421a47eb9565 Size/MD5: 1152 d8220b2d44c6c664782e8b979cbe04b0 Size/MD5: 39210 b985f6c8fc211930e72f0a60855bde51 Size/MD5: 1134614 8143fe4d2afbbf312b622a2f4373230b Size/MD5: 689300 1855ec4645a2dc5b4f20a7e9f1c65773 Size/MD5: 1118 9c16781882bc0e82b684a095c0d6eeba Size/MD5: 1014066 edd3b4485abf10e035901d5b6032f5d9 Size/MD5: 1336 289bf448e2ac790e891f22de8fd6b214 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 1148500 37d2ed72fd2bea06f4af2497696bce89 Size/MD5: 1191424 998eac8885905bffc96e78972b16ee39 Size/MD5: 794530 fda13024980bfba8bce9bf383c952c27 Size/MD5: 109084 c200383e4679fa090c187f03f6599884 Size/MD5: 1152 7ee75ae78151f41dc06b66f96a8cbd75 Size/MD5: 36338 a39a3d404dafed967bb63b4dd8a92acd Size/MD5: 1105702 cca29346386b38e683cd5ab3bb1d497a Size/MD5: 707764 5252be3f7c6292d42b953f5c40a7949b Size/MD5: 1112 54f526daae560c2f58d4c40b1f6799dd Size/MD5: 1027316 14db895caf9b3dcf25653343a6e12931 Size/MD5: 1338 eb35fae8569fc6aa9310b7709728fd2d . Uncover the Mono flaw in Ubuntu impacting several releases, which allows for remote failures. Immediate updatesadvised!. Mono Vulnerability, Remote Code Execution, Ubuntu Security Alert. . Severity: Critical. LinuxSecurity.com Team
Mono does not properly sanitize pathnames allowing unauthorized information disclosure.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200701-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: Mono: Information disclosure Date: January 16, 2007 Bugs: #159886 ID: 200701-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Mono does not properly sanitize pathnames allowing unauthorized information disclosure. Background ========= Mono provides the necessary software to develop and run .NET client and server applications on various platforms. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-lang/mono < 1.2.2.1 > = 1.2.2.1 Description ========== José Ramón Palanco has discovered that the System.Web class in the XSP for the ASP.NET server 1.1 through 2.0 in Mono does not properly validate or sanitize local pathnames which could allow server-side file content disclosure. Impact ===== An attacker could append a space character to a URI and obtain unauthorized access to the source code of server-side files. An attacker could also read credentials by requesting Web.Config%20 from a Mono server. Workaround ========= There is no known workaround at this time. Resolution ========= All Mono users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-lang/mono-1.2.2.1" References ========= [ 1 ] CVE-2006-6104 https://www.cve.org/CVERecord?id=CVE-2006-6104 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200701-12 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.