CVE Vulnerabilities

CVE-2013-2132

Published: Aug 15, 2013 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an invalid DBRef.

Affected Software

Name Vendor Start Version End Version
Mongodb Mongodb * 2.5.1 (including)
Mongodb Mongodb 1.2.0 (including) 1.2.0 (including)
Mongodb Mongodb 1.4.0 (including) 1.4.0 (including)
Mongodb Mongodb 1.6.0 (including) 1.6.0 (including)
Mongodb Mongodb 1.8.0 (including) 1.8.0 (including)
Mongodb Mongodb 2.0.0 (including) 2.0.0 (including)
Mongodb Mongodb 2.2.0 (including) 2.2.0 (including)
Mongodb Mongodb 2.4.0 (including) 2.4.0 (including)
Mongodb Mongodb 2.4.1 (including) 2.4.1 (including)
Mongodb Mongodb 2.4.2 (including) 2.4.2 (including)
Mongodb Mongodb 2.4.3 (including) 2.4.3 (including)
Mongodb Mongodb 2.4.4 (including) 2.4.4 (including)
Mongodb Mongodb 2.4.5 (including) 2.4.5 (including)
Mongodb Mongodb 2.5.0 (including) 2.5.0 (including)
Red Hat Enterprise MRG 2 RedHat mongodb-0:1.6.4-6.el6 *
Red Hat Enterprise MRG 2 RedHat pymongo-0:1.9-11.el6 *
Pymongo Ubuntu precise *
Pymongo Ubuntu quantal *
Pymongo Ubuntu raring *
Pymongo Ubuntu upstream *

References