Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-2318

Опубликовано: 08 янв. 2018
Источник: debian
EPSS Низкий

Описание

The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
monofixed3.2.8+dfsg-10package

Примечания

  • https://github.com/mono/mono/commit/1509226c41d74194c146deb173e752b8d3cdeec4

  • Patch for versions earlier than 3.4: https://gist.github.com/directhex/f8c6e67f551d8a608154

EPSS

Процентиль: 79%
0.0129
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 8 лет назад

The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.

CVSS3: 8.1
nvd
около 8 лет назад

The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.

CVSS3: 8.1
github
больше 3 лет назад

The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.

suse-cvrf
почти 12 лет назад

Recommended update for mono-core

EPSS

Процентиль: 79%
0.0129
Низкий