CVE-2011-0991

NameCVE-2011-0991
DescriptionUse-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to finalizing and then resurrecting a DynamicMethod instance.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mono (PTS)stretch4.6.2.7+dfsg-1fixed
buster5.18.0.240+dfsg-3fixed
bookworm, sid, bullseye6.8.0.105+dfsg-3.2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
monosource(unstable)(not affected)

Notes

- mono <not-affected> (Moonlight no longer present in Debian)

Search for package or bug name: Reporting problems