Описание
An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.
A flaw was found in the bson module contained in the python-pymongo package. A malformed BSON file may trigger an exception, leading to a denial of service and eventually sensitive memory data exposure.
Отчет
Only RHEL-8 is impacted by this vulnerability as python-pymongo
is not packaged in RHEL-7 or RHEL-9.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 8 | python27:2.7/python-pymongo | Fix deferred | ||
Red Hat OpenStack Platform 16.1 | openstack-panko | Fix deferred | ||
Red Hat OpenStack Platform 16.2 | openstack-panko | Fix deferred | ||
Red Hat OpenStack Platform 17.1 | python-pymongo | Affected | ||
Red Hat Satellite 6 | python-pymongo | Not affected | ||
Red Hat Enterprise Linux 8 | python36 | Fixed | RHSA-2025:8419 | 03.06.2025 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.7 Medium
CVSS3
Связанные уязвимости
An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.
An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.
An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier ...
EPSS
4.7 Medium
CVSS3