CVE-2011-0991: Use After Free
Published Apr 13, 2011
·Updated
Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to finalizing and then resurrecting a DynamicMethod instance.
Affected Software
7 affected components
Novell Moonlight=3.0
Novell Moonlight=2.4
Novell Moonlight=2.31
Novell Moonlight=3.99
Mono Mono
Novell Moonlight=2.3.0
Novell Moonlight=2.0
Remediation
Patch Available
Patch Available
Event History
Apr 13, 2011
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0991?
CVE-2011-0991 is considered a high severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2011-0991?
To fix CVE-2011-0991, you should upgrade to Moonlight version 2.4.1 or later, or to version 3.99.3 or later.
3
What products are affected by CVE-2011-0991?
CVE-2011-0991 affects multiple versions of Novell Moonlight and Mono.
4
Can CVE-2011-0991 be exploited remotely?
Yes, CVE-2011-0991 allows remote attackers to exploit the vulnerability.
5
What kind of impact can CVE-2011-0991 have?
CVE-2011-0991 can lead to denial of service or potentially other unspecified impacts.