The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the FREAK issue, a different vulnerability than CVE-2015-0204.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mono | Mono-project | * | 3.12.1 (excluding) |
Mono | Ubuntu | devel | * |
Mono | Ubuntu | lucid | * |
Mono | Ubuntu | precise | * |
Mono | Ubuntu | trusty | * |
Mono | Ubuntu | upstream | * |
Mono | Ubuntu | utopic | * |