Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-3104

Опубликовано: 14 апр. 2017
Источник: debian

Описание

mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mongodbfixed1:3.2.11-1package
mongodbno-dsajessiepackage
mongodbno-dsawheezypackage

Примечания

  • https://jira.mongodb.org/browse/SERVER-24378

  • Marking as fixed with the first 3.x based version in unstable

  • This issue though affect only 2.4 (and possibly older), or 2.6

  • installations, but only in circumstances where they first had a

  • MongoDB 2.4 installation with authentication enabled, upgraded

  • to 2.6, and did not complete a full upgrade

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database.

redhat
около 9 лет назад

mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database.

CVSS3: 7.5
nvd
почти 9 лет назад

mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database.

CVSS3: 7.5
github
больше 3 лет назад

mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database.