CVE-2015-2319: High severity ubuntu mono vulnerability
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORTRSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-2319?
CVE-2015-2319 is a vulnerability in the TLS stack in Mono before version 3.12.1 that makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic.
What version of Mono is affected by CVE-2015-2319?
Mono versions up to but excluding 3.12.1 are affected by CVE-2015-2319.
What is the severity of CVE-2015-2319?
CVE-2015-2319 has a severity value of 7.5, which is considered high.
How can remote attackers exploit CVE-2015-2319?
Remote attackers can exploit CVE-2015-2319 by conducting cipher-downgrade attacks to EXPORT_RSA ciphers using crafted TLS traffic.
Where can I find more information about CVE-2015-2319?
You can find more information about CVE-2015-2319 at the following references: - http://www.mono-project.com/news/2015/03/07/mono-tls-vulnerability/ - http://www.openwall.com/lists/oss-security/2015/03/17/9 - http://www.securityfocus.com/bid/73250