CVE-2012-3543: Input Validation
Published Nov 21, 2019
·Updated
mono 2.10.x ASP.NET Web Form Hash collision DoS
Affected Software
6 affected componentsFixes available
mono-project Mono>=2.10<=2.10.12
Canonical Ubuntu Linux=12.04
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/mono
6.8.0.105+dfsg-3.3~deb11u16.8.0.105+dfsg-3.3+deb12u16.12.0.199+dfsg-66.14.1+ds2-1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Nov 21, 2019
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Feb 18, 2026
Data Sourced
via Debian·01:49 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2012-3543?
CVE-2012-3543 refers to a vulnerability in mono 2.10.x ASP.NET Web Forms that can be exploited to cause a denial-of-service (DoS) attack by leveraging hash collisions.
2
How severe is CVE-2012-3543?
CVE-2012-3543 has a severity rating of 7.5 (High) based on the CVSS v3.0 scoring system.
3
What software versions are affected by CVE-2012-3543?
The affected software for CVE-2012-3543 includes mono 2.10.x, as well as specific versions of Debian and Ubuntu Linux distributions.
4
How can I mitigate CVE-2012-3543?
To mitigate CVE-2012-3543, it is recommended to update the affected software to version 5.18.0.240+dfsg-3 or higher.
5
Where can I find more information about CVE-2012-3543?
More information about CVE-2012-3543 can be found on the Debian Security Tracker, Openwall mailing list, and SecurityFocus.