Описание
MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.
A flaw was found in the way MongoDB processed certain BSON-serialized UTF-8 strings. A remote, unauthenticated attacker could use this flaw to crash a mongod server via a specially crafted BSON message.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse) | mongodb | Fix deferred | ||
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | mongodb | Fix deferred | ||
| Red Hat OpenShift Enterprise 2 | mongodb | Will not fix | ||
| Red Hat OpenStack Platform 4 | mongodb | Will not fix | ||
| Red Hat Software Collections | mongodb24-mongodb | Will not fix | ||
| Red Hat Subscription Asset Manager | mongodb | Will not fix | ||
| Red Hat Satellite 6.2 for RHEL 6 | createrepo_c | Fixed | RHBA-2016:1500 | 27.07.2016 |
| Red Hat Satellite 6.2 for RHEL 6 | facter | Fixed | RHBA-2016:1500 | 27.07.2016 |
| Red Hat Satellite 6.2 for RHEL 6 | gperftools | Fixed | RHBA-2016:1500 | 27.07.2016 |
| Red Hat Satellite 6.2 for RHEL 6 | hiera | Fixed | RHBA-2016:1500 | 27.07.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS2
Связанные уязвимости
MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.
MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.
MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers t ...
MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.
Уязвимость системы управления базами данных MongoDB, позволяющая удалённому злоумышленнику вызвать отказ в обслуживании
EPSS
5 Medium
CVSS2