Описание
A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| mongo-c-driver | fixed | 2.2.3-1 | package | |
| mongo-c-driver | fixed | 1.30.4-1+deb13u2 | trixie | package |
| mongo-c-driver | fixed | 1.23.1-1+deb12u3 | bookworm | package |
| mongo-c-driver | postponed | bullseye | package |
Примечания
https://jira.mongodb.org/browse/CDRIVER-6251
Fixed by: https://github.com/mongodb/mongo-c-driver/commit/b93ebe6b99e614b49a24316c7a295eb3f08af603 (2.2.3)
Fixed by: https://github.com/mongodb/mongo-c-driver/commit/754232f3cffe924346dcf327f4a723f1a0839420 (1.30.8)
EPSS
Связанные уязвимости
A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.
A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.
A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.
A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.
EPSS