Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-16790

Опубликовано: 10 сент. 2018
Источник: debian
EPSS Низкий

Описание

_bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read via a crafted bson buffer.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libbsonremovedpackage
libbsonno-dsastretchpackage
libbson-xs-perlremovedpackage
libbson-xs-perlfixed0.8.4-2+deb12u1bookwormpackage
mongo-c-driverfixed1.13.0-1package

Примечания

  • https://jira.mongodb.org/browse/CDRIVER-2819

  • https://github.com/mongodb/mongo-c-driver/commit/0d9a4d98bfdf4acd2c0138d4aaeb4e2e0934bd84

EPSS

Процентиль: 66%
0.00529
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 7 лет назад

_bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read via a crafted bson buffer.

CVSS3: 6.3
redhat
около 7 лет назад

_bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read via a crafted bson buffer.

CVSS3: 8.1
nvd
около 7 лет назад

_bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read via a crafted bson buffer.

CVSS3: 8.1
github
больше 3 лет назад

_bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read via a crafted bson buffer.

CVSS3: 8.4
redos
9 дней назад

Множественные уязвимости libbson

EPSS

Процентиль: 66%
0.00529
Низкий