Back to Database
Status published
Medium
CVE-2010-4159
Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and...
Vulnerability Description
Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-4159
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/mono/mono/commit/8e890a3bf80a4620e417814dc14886b1bbd17625
- http://www.vupen.com/english/advisories/2010/3059
- http://lists.ximian.com/pipermail/mono-patches/2010-October/177900.html
- http://marc.info/?l=oss-security&m=128941802415318&w=2
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:240
- http://www.mono-project.com/Vulnerabilities#Mono_Runtime_Insecure_Native_Library_Loading
- http://secunia.com/advisories/42174
- https://bugzilla.novell.com/show_bug.cgi?id=641915
- http://www.securityfocus.com/bid/44810
- http://marc.info/?l=oss-security&m=128939912716499&w=2
- http://marc.info/?l=oss-security&m=128939873515821&w=2
More from mono
View All →CVE-2020-12473
MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by...
High
7.2
CVE-2020-12472
MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog...
Medium
5.4
CVE-2020-12471
MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or...
Critical
9.8
CVE-2020-12470
MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by...
High
7.2
CVE-2012-3543
mono 2.10.x ASP.NET Web Form Hash collision DoS...
High
7.5
Affected Vendor
mono
View all reports →Affected Software
mono
Vulnerable Versions:
0, 1.0, 1.0.1, 1.0.2, 1.0.4, 1.0.5, 1.0.6, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 1.1.8.1, 1.1.8.3, 1.1.9, 1.1.9.1, 1.1.9.2, 1.1.10, 1.1.10.1, 1.1.11, 1.1.12, 1.1.12.1, 1.1.13, 1.1.13.2, 1.1.13.4, 1.1.13.5, 1.1.13.6, 1.1.13.7, 1.1.13.8, 1.1.13.8.1, 1.1.14, 1.1.15, 1.1.16, 1.1.16.1, 1.1.17, 1.1.17.1, 1.1.17.2, 1.1.18, 1.2, 1.2.1, 1.2.2, 1.2.2.1, 1.2.3, 1.2.3.1, 1.2.4, 1.2.5, 1.2.5.1, 1.2.5.2, 1.2.6, 1.9, 1.9.1, 2.0, 2.0.1, 2.2, 2.4, 2.4.2, 2.4.2.1, 2.4.2.2, 2.4.2.3, 2.4.3, 2.6, 2.6.3, 2.6.4
Timeline
Official Publish:
November 17th, 2010
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.