The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono CLR interpreter.
2023-02-22T07:15:10.900
2025-03-18T17:15:42.133
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mono-project | mono | 5.18.0.240\+dfsg-3 | Yes |
Application | mono-project | mono | 6.8.0.105\+dfsg-3 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |