CVE Vulnerabilities

CVE-2013-2132

Published: Aug 15, 2013 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an invalid DBRef.

Affected Software

Name Vendor Start Version End Version
Mongodb Mongodb * 2.5.1 (including)
Mongodb Mongodb 1.2.0 (including) 1.2.0 (including)
Mongodb Mongodb 1.4.0 (including) 1.4.0 (including)
Mongodb Mongodb 1.6.0 (including) 1.6.0 (including)
Mongodb Mongodb 1.8.0 (including) 1.8.0 (including)
Mongodb Mongodb 2.0.0 (including) 2.0.0 (including)
Mongodb Mongodb 2.2.0 (including) 2.2.0 (including)
Mongodb Mongodb 2.4.0 (including) 2.4.0 (including)
Mongodb Mongodb 2.4.1 (including) 2.4.1 (including)
Mongodb Mongodb 2.4.2 (including) 2.4.2 (including)
Mongodb Mongodb 2.4.3 (including) 2.4.3 (including)
Mongodb Mongodb 2.4.4 (including) 2.4.4 (including)
Mongodb Mongodb 2.4.5 (including) 2.4.5 (including)
Mongodb Mongodb 2.5.0 (including) 2.5.0 (including)

References