Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-6383

Опубликовано: 03 июл. 2024
Источник: debian

Описание

The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory. This issue affects libbson versions prior to 1.27.1

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libbson-xs-perlremovedpackage
libbson-xs-perlfixed0.8.4-2+deb12u1bookwormpackage
mongo-c-driverfixed1.27.1-1package
mongo-c-driverfixed1.23.1-1+deb12u1bookwormpackage

Примечания

  • https://jira.mongodb.org/browse/CDRIVER-5628

  • Fixed by: https://github.com/mongodb/mongo-c-driver/commit/1d642e461e7c0e26abe3a90c7bbac081ac4a0053 (1.28.0)

  • Fixed by: https://github.com/mongodb/mongo-c-driver/commit/7c34461863211be172e6317221d72e4429bed45e (1.27.1)

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 лет назад

The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory. This issue affects libbson versions prior to 1.27.1

CVSS3: 5.3
nvd
около 2 лет назад

The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory. This issue affects libbson versions prior to 1.27.1

CVSS3: 5.3
github
около 2 лет назад

The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory. This issue affects libbson versions prior to 1.27.1

CVSS3: 5.3
fstec
около 2 лет назад

Уязвимость функции bson_string_append библиотеки libbson драйвера системы управления базами данных MongoDB C Driver, позволяющая нарушителю вызвать отказ в обслуживании или повредить память

CVSS3: 5.3
redos
3 месяца назад

Уязвимость mongo-c-driver