oss-sec mailing list archives

CVE-2009-0689 discovered in Mono prior to 4.2


From: Jo Shields <directhex () apebox org>
Date: Sat, 19 Dec 2015 21:45:01 +0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Dear all,

Security researchers at NCC Group have discovered that CVE-2009-0689, a
definite DOS (and possible arbitrary code execution) in various
applications' string-to-double parser implementations, also applies to
Mono versions prior to 4.2.

A fix is available
at https://gist.github.com/directhex/01e853567fd2cc74ed39 and should
apply cleanly to all versions of Mono you might care about.

This fix should be applied to all Mono packages prior to 4.2 (everything
except Debian Unstable, Ubuntu 16.04, and Arch, from a quick look)

Attached is the disclosure as-received by us, which includes a minimal
test case to demonstrate the vulnerability.

Thanks to Peter McLarnan <Peter.McLarnan@nccgroup.trust> and Andy
Schmitz <andy.schmitz@nccgroup.trust>

Apologies for the lateness in sending this, I sent it to the wrong
list & didn't notice until pointed out to me recently.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJWdc/dAAoJEMkPnLkOH60MQ3kH/3hNr7Fx/XOc+ql1UJ9LwEP0
+oPLCTPOEfG6b448oISDvVhxJaKkCpmMSKHjrcY80ig+dKm7qLp9o3sWRSzBmjA/
lXVIiHeU11KTsAlgMamNminL+kqNm8H7FlEAoqJIudb2pzkfUrEwLya3+rSnZe54
FBt0uGuHx3eF7ms8BTo3vEtQlhMsiYJh78sKCGNUSqLZ5ObGqLXoKiZq/J1JtZ/w
G5kRRD2GpyoIMsaneejBzqH7XF1GTvbSlEiWRScslRAXpj9y59ssHDDHi4FhIrSS
vPn0s+biTS3bsH9/H33uwcDPh65UaNha+J+opKZd5MMUqtoBERs6vHyGpaCNNPI=
=uXMH
-----END PGP SIGNATURE-----

Attachment: mono_disclosure.txt
Description:

Attachment: mono_disclosure.txt.sig
Description:


Current thread: