CVE-2015-2318: High severity ubuntu mono vulnerability
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.
Other sources
Three flaws were discovered in Mono's TLS implementation:
A TLS impersonation attack was discovered in Mono's TLS stack by researchers at Inria. During checks on our TLS stack, we have discovered two further issues which we have fixed - SSLv2 support, and vulnerability to FREAK. These vulnerabilities affect basically every Mono version ever released.
This is fixed in Mono version 3.12.1:
http://download.mono-project.com/sources/mono/mono-3.12.1.tar.bz2
Upstream patches:
https://github.com/mono/mono/commit/1509226c41d74194c146deb173e752b8d3cdeec4 https://github.com/mono/mono/commit/9c38772f094168d8bfd5bc73bf8925cd04faad10 https://github.com/mono/mono/commit/b371da6b2d68b4cdd0f21d6342af6c42794f998b
Additional Information:
http://seclists.org/oss-sec/2015/q1/772
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2318?
CVE-2015-2318 is classified as a high severity vulnerability due to its potential to enable man-in-the-middle attacks.
How do I fix CVE-2015-2318?
To fix CVE-2015-2318, upgrade your Mono version to at least 3.12.1 or apply any relevant patches provided by your distribution.
Which versions of Mono are affected by CVE-2015-2318?
CVE-2015-2318 affects Mono versions prior to 3.12.1, including several Debian and Red Hat releases.
What type of attack is possible with CVE-2015-2318?
CVE-2015-2318 allows attackers to conduct message skipping attacks to impersonate clients.
Is CVE-2015-2318 a local or remote vulnerability?
CVE-2015-2318 is a remote vulnerability, as it can be exploited over a network.