Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-1892

Опубликовано: 24 мар. 2013
Источник: redhat
CVSS2: 6.8

Описание

MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute arbitrary code via a crafted memory address in the first argument.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1mongodbWill not fix
Red Hat CloudForms Tools 1mongodbWill not fix
RHUI for RHEL 6mongodbWill not fix
Red Hat Enterprise MRG 2mongodbFixedRHSA-2013:117021.08.2013
Red Hat Enterprise MRG 2pymongoFixedRHSA-2013:117021.08.2013

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=927536MongoDB: Server Side JavaScript Includes allow Remote Code Execution

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute arbitrary code via a crafted memory address in the first argument.

nvd
больше 12 лет назад

MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute arbitrary code via a crafted memory address in the first argument.

debian
больше 12 лет назад

MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate ...

github
больше 3 лет назад

MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute arbitrary code via a crafted memory address in the first argument.

6.8 Medium

CVSS2