{
    "CVE_data_meta": {
        "ASSIGNER": "secure@microsoft.com",
        "ID": "CVE-2010-3332",
        "STATE": "PUBLIC"
    },
    "affects": {
        "vendor": {
            "vendor_data": [
                {
                    "product": {
                        "product_data": [
                            {
                                "product_name": "n/a",
                                "version": {
                                    "version_data": [
                                        {
                                            "version_value": "n/a"
                                        }
                                    ]
                                }
                            }
                        ]
                    },
                    "vendor_name": "n/a"
                }
            ]
        }
    },
    "data_format": "MITRE",
    "data_type": "CVE",
    "data_version": "4.0",
    "description": {
        "description_data": [
            {
                "lang": "eng",
                "value": "Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka \"ASP.NET Padding Oracle Vulnerability.\""
            }
        ]
    },
    "problemtype": {
        "problemtype_data": [
            {
                "description": [
                    {
                        "lang": "eng",
                        "value": "n/a"
                    }
                ]
            }
        ]
    },
    "references": {
        "reference_data": [
            {
                "name": "http://www.ekoparty.org/juliano-rizzo-2010.php",
                "refsource": "MISC",
                "url": "http://www.ekoparty.org/juliano-rizzo-2010.php"
            },
            {
                "name": "oval:org.mitre.oval:def:12365",
                "refsource": "OVAL",
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12365"
            },
            {
                "name": "ADV-2010-2751",
                "refsource": "VUPEN",
                "url": "http://www.vupen.com/english/advisories/2010/2751"
            },
            {
                "name": "http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryId/2799/Oracle-Padding-Vulnerability-in-ASP-NET.aspx",
                "refsource": "MISC",
                "url": "http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryId/2799/Oracle-Padding-Vulnerability-in-ASP-NET.aspx"
            },
            {
                "name": "http://weblogs.asp.net/scottgu/archive/2010/09/18/important-asp-net-security-vulnerability.aspx",
                "refsource": "CONFIRM",
                "url": "http://weblogs.asp.net/scottgu/archive/2010/09/18/important-asp-net-security-vulnerability.aspx"
            },
            {
                "name": "http://www.troyhunt.com/2010/09/fear-uncertainty-and-and-padding-oracle.html",
                "refsource": "MISC",
                "url": "http://www.troyhunt.com/2010/09/fear-uncertainty-and-and-padding-oracle.html"
            },
            {
                "name": "41409",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/41409"
            },
            {
                "name": "43316",
                "refsource": "BID",
                "url": "http://www.securityfocus.com/bid/43316"
            },
            {
                "name": "http://www.mono-project.com/Vulnerabilities#ASP.NET_Padding_Oracle",
                "refsource": "CONFIRM",
                "url": "http://www.mono-project.com/Vulnerabilities#ASP.NET_Padding_Oracle"
            },
            {
                "name": "http://www.microsoft.com/technet/security/advisory/2416728.mspx",
                "refsource": "CONFIRM",
                "url": "http://www.microsoft.com/technet/security/advisory/2416728.mspx"
            },
            {
                "name": "1024459",
                "refsource": "SECTRACK",
                "url": "http://securitytracker.com/id?1024459"
            },
            {
                "name": "http://blogs.technet.com/b/srd/archive/2010/09/17/understanding-the-asp-net-vulnerability.aspx",
                "refsource": "CONFIRM",
                "url": "http://blogs.technet.com/b/srd/archive/2010/09/17/understanding-the-asp-net-vulnerability.aspx"
            },
            {
                "name": "http://isc.sans.edu/diary.html?storyid=9568",
                "refsource": "MISC",
                "url": "http://isc.sans.edu/diary.html?storyid=9568"
            },
            {
                "name": "ADV-2010-2429",
                "refsource": "VUPEN",
                "url": "http://www.vupen.com/english/advisories/2010/2429"
            },
            {
                "name": "MS10-070",
                "refsource": "MS",
                "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-070"
            },
            {
                "name": "http://www.theinquirer.net/inquirer/news/1732956/security-researchers-destroy-microsoft-aspnet-security",
                "refsource": "MISC",
                "url": "http://www.theinquirer.net/inquirer/news/1732956/security-researchers-destroy-microsoft-aspnet-security"
            },
            {
                "name": "http://threatpost.com/en_us/blogs/new-crypto-attack-affects-millions-aspnet-apps-091310",
                "refsource": "MISC",
                "url": "http://threatpost.com/en_us/blogs/new-crypto-attack-affects-millions-aspnet-apps-091310"
            },
            {
                "name": "http://twitter.com/thaidn/statuses/24832350146",
                "refsource": "MISC",
                "url": "http://twitter.com/thaidn/statuses/24832350146"
            },
            {
                "name": "http://pentonizer.com/general-programming/aspnet-poet-vulnerability-what-else-can-i-do/",
                "refsource": "MISC",
                "url": "http://pentonizer.com/general-programming/aspnet-poet-vulnerability-what-else-can-i-do/"
            },
            {
                "name": "ms-aspdotnet-padding-info-disclosure(61898)",
                "refsource": "XF",
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/61898"
            }
        ]
    }
}