CVE-2011-0992: Use After Free
Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service (plugin crash) or obtain sensitive information via vectors related to member data in a resurrected MonoThread instance.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0992?
CVE-2011-0992 has a medium severity rating due to its potential for denial of service and data exposure.
How do I fix CVE-2011-0992?
To fix CVE-2011-0992, update your Novell Moonlight or Mono to the latest stable version that is not vulnerable.
What are the affected versions for CVE-2011-0992?
CVE-2011-0992 affects Moonlight versions 2.0 to 2.4.1 and 3.x up to 3.99.3.
What types of attacks can exploit CVE-2011-0992?
CVE-2011-0992 can be exploited through remote attacks that cause a plugin crash or leak sensitive information.
Is CVE-2011-0992 a remote vulnerability?
Yes, CVE-2011-0992 is a remote vulnerability that allows attackers to manipulate the Mono environment without physical access.