CVE-2011-0990
Estado: ModificadaMedia (5.8)—
Race condition in the FastCopy optimization in the Array.Copy method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to trigger a buffer overflow and modify internal data structures, and cause a denial of service (plugin crash) or corrupt the internal state of the security manager, via a crafted media file in which a thread makes a change after a type check but before a copy action.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P
- Puntuación base: 5.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.16%
- Percentil entre todas las CVEs puntuadas: 82
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-362
Referencias
- http://lists.opensuse.org/opensuse-updates/2011-04/msg00024.html
- http://openwall.com/lists/oss-security/2011/04/06/14
- http://secunia.com/advisories/44002
- http://secunia.com/advisories/44076
- http://www.mono-project.com/Vulnerabilities
- http://www.securityfocus.com/bid/47208
- http://www.vupen.com/english/advisories/2011/0904
- https://bugzilla.novell.com/show_bug.cgi?id=667077
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66625
- https://github.com/mono/mono/commit/2f00e4bbb2137130845afb1b2a1e678552fc8e5c
- http://lists.opensuse.org/opensuse-updates/2011-04/msg00024.html
- http://openwall.com/lists/oss-security/2011/04/06/14
- http://secunia.com/advisories/44002
- http://secunia.com/advisories/44076
- http://www.mono-project.com/Vulnerabilities
- http://www.securityfocus.com/bid/47208
- http://www.vupen.com/english/advisories/2011/0904
- https://bugzilla.novell.com/show_bug.cgi?id=667077
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66625
- https://github.com/mono/mono/commit/2f00e4bbb2137130845afb1b2a1e678552fc8e5c
JSON original (NVD)
Mostrar
{
"id": "CVE-2011-0990",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2011-04-13T21:55:00.783",
"references": [
{
"url": "http://lists.opensuse.org/opensuse-updates/2011-04/msg00024.html",
"source": "cve@mitre.org"
},
{
"url": "http://openwall.com/lists/oss-security/2011/04/06/14",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/44002",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/44076",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.mono-project.com/Vulnerabilities",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/47208",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2011/0904",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.novell.com/show_bug.cgi?id=667077",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/66625",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/mono/mono/commit/2f00e4bbb2137130845afb1b2a1e678552fc8e5c",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2011-04/msg00024.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://openwall.com/lists/oss-security/2011/04/06/14",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/44002",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/44076",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mono-project.com/Vulnerabilities",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/47208",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2011/0904",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.novell.com/show_bug.cgi?id=667077",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/66625",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/mono/mono/commit/2f00e4bbb2137130845afb1b2a1e678552fc8e5c",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-362"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Race condition in the FastCopy optimization in the Array.Copy method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to trigger a buffer overflow and modify internal data structures, and cause a denial of service (plugin crash) or corrupt the internal state of the security manager, via a crafted media file in which a thread makes a change after a type check but before a copy action."
},
{
"lang": "es",
"value": "Condición de carrera en la optimización de FastCopy en el método Array.Copy en metadata/icall.c de Mono, cuando se utiliza Moonlight 2.x anterior a 2.4.1 o 3.x anterior a 3.99.3, permite a atacantes remotos provocar un desbordamiento del búfer y modificar las estructuras internas de datos, también permite provocar una denegación de servicio (caída del plugin) o corromper el estado interno del gestor de seguridad mediante un fichero media manipulado, en el que un hilo realiza un cambio después de una comprobación de escritura pero antes de una acción de copiado."
}
],
"lastModified": "2026-06-16T23:28:24.740",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mono:mono:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E062208D-082B-4BFD-85CA-3848ECE6F8CF"
},
{
"criteria": "cpe:2.3:a:novell:moonlight:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "711824C0-5BFC-4D3A-BAB2-84B8F20BDD7C"
},
{
"criteria": "cpe:2.3:a:novell:moonlight:2.3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C74F2C01-7E26-474A-B8CA-EFCC5C91D83D"
},
{
"criteria": "cpe:2.3:a:novell:moonlight:2.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "704EB745-3307-4903-8B3B-DCC6682EE228"
},
{
"criteria": "cpe:2.3:a:novell:moonlight:2.31:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DB7A6358-630E-43FA-B2B8-C99A8808BB09"
},
{
"criteria": "cpe:2.3:a:novell:moonlight:3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AADDCD5B-D116-4BFC-BD2B-4EB6F4470359"
},
{
"criteria": "cpe:2.3:a:novell:moonlight:3.99:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "21676825-737D-4071-A7F1-BFB6047215F1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}