Bugzilla – Bug 739119
VUL-1: CVE-2012-3543: mono-web: hash collision denial of service attacks in ASP.net
Last modified: 2016-12-02 13:16:49 UTC
is public via CVE diff. The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka "Collisions in HashTable May Cause DoS Vulnerability." Reference: CERT-VN: http://www.kb.cert.org/vuls/id/903934 Reference: MISC: http://www.ocert.org/advisories/ocert-2011-003.html Reference: MISC: http://www.nruns.com/_downloads/advisory28122011.pdf Reference: MS: http://technet.microsoft.com/security/bulletin/MS11-100 I have not yet cross checked if it affects Mono ASP.NET, but I guess it does.
bugbot adjusting priority
Dobrin, here is another mono issue (perhaps), but of low severity
Created attachment 499891 [details] Patch for mono master
Created attachment 499892 [details] Patch for mono 2-10
On behalf of Marek Habersack: The attached patches fix the vulnerability - contact us at support@xamarin.com if you have any follow-up questions. The fix was committed to the following Mono branches: master: 2ab1a051058fee5ea3aec2e071fba7000b693488 c3e088bf2fc22d66d0f17b74676de366f661c3eb mono-2-10: 04245de5c480db5dff5983467f7a8606f1321ed6 049bb49f1c5b650166de2a266bc1879c5def0190
thank yoU! reopen for tracking... reassign to me for package building when needed
-> orphaned. please incldue in current mono-core update too.
full git urls: master: https://github.com/mono/mono/commit/2ab1a051058fee5ea3aec2e071fba7000b693488 https://github.com/mono/mono/commit/c3e088bf2fc22d66d0f17b74676de366f661c3eb mono-2.10: https://github.com/mono/mono/commit/04245de5c480db5dff5983467f7a8606f1321ed6 https://github.com/mono/mono/commit/049bb49f1c5b650166de2a266bc1879c5def0190
cve requested
CVE-2012-3543
(In reply to comment #7) > please incldue in current mono-core update too. I am not aware of another current mono-core update.
I assume MArcus pointed to https://swamp.suse.de/webswamp/swamp/template/DisplayWorkflow.vm/workflowid/48165 which is already done. :-\
(so far was not released)
An update workflow for this issue was started. This issue was rated as important. Please submit fixed packages until 2015-11-11. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/62324
None of the patches provided above seems to apply to any of the Mono versions we have on SLE-10-SP3, SLE-11-SP0 and SLE-11-SP2.
An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2016-01-01. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/62382
Hello Reinhard, please review these proposed patches. You will also find them building in ibs: home:AndreasStieger:branches:OBS_Maintained:mono-core
submitted
SUSE-SU-2016:0257-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 739119,958097 CVE References: CVE-2009-0689,CVE-2012-3543 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): mono-core-2.6.7-0.16.1 SUSE Linux Enterprise Software Development Kit 11-SP3 (src): mono-core-2.6.7-0.16.1 SUSE Linux Enterprise Server for VMWare 11-SP3 (src): mono-core-2.6.7-0.16.1 SUSE Linux Enterprise Server 11-SP4 (src): mono-core-2.6.7-0.16.1 SUSE Linux Enterprise Server 11-SP3 (src): mono-core-2.6.7-0.16.1 SUSE Linux Enterprise Desktop 11-SP4 (src): mono-core-2.6.7-0.16.1
SUSE-SU-2016:2958-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 739119,958097 CVE References: CVE-2009-0689,CVE-2012-3543 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): mono-core-2.6.7-0.18.1 SUSE Linux Enterprise Server 11-SP4 (src): mono-core-2.6.7-0.18.1 SUSE Linux Enterprise Server 11-SP3-LTSS (src): mono-core-2.6.7-0.18.1