bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an invalid DBRef.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mongodb | Mongodb | * | 2.5.1 (including) |
Mongodb | Mongodb | 1.2.0 (including) | 1.2.0 (including) |
Mongodb | Mongodb | 1.4.0 (including) | 1.4.0 (including) |
Mongodb | Mongodb | 1.6.0 (including) | 1.6.0 (including) |
Mongodb | Mongodb | 1.8.0 (including) | 1.8.0 (including) |
Mongodb | Mongodb | 2.0.0 (including) | 2.0.0 (including) |
Mongodb | Mongodb | 2.2.0 (including) | 2.2.0 (including) |
Mongodb | Mongodb | 2.4.0 (including) | 2.4.0 (including) |
Mongodb | Mongodb | 2.4.1 (including) | 2.4.1 (including) |
Mongodb | Mongodb | 2.4.2 (including) | 2.4.2 (including) |
Mongodb | Mongodb | 2.4.3 (including) | 2.4.3 (including) |
Mongodb | Mongodb | 2.4.4 (including) | 2.4.4 (including) |
Mongodb | Mongodb | 2.4.5 (including) | 2.4.5 (including) |
Mongodb | Mongodb | 2.5.0 (including) | 2.5.0 (including) |
Red Hat Enterprise MRG 2 | RedHat | mongodb-0:1.6.4-6.el6 | * |
Red Hat Enterprise MRG 2 | RedHat | pymongo-0:1.9-11.el6 | * |
Pymongo | Ubuntu | precise | * |
Pymongo | Ubuntu | quantal | * |
Pymongo | Ubuntu | raring | * |
Pymongo | Ubuntu | upstream | * |