CVE Vulnerabilities

CVE-2019-20925

Incorrect Comparison

Published: Nov 24, 2020 | Modified: Jan 23, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects MongoDB Server v4.2 versions prior to 4.2.1; MongoDB Server v4.0 versions prior to 4.0.13; MongoDB Server v3.6 versions prior to 3.6.15 and MongoDB Server v3.4 versions prior to 3.4.24.

Weakness

The product compares two entities in a security-relevant context, but the comparison is incorrect, which may lead to resultant weaknesses.

Affected Software

Name Vendor Start Version End Version
Mongodb Mongodb 3.4.0 (including) 3.4.24 (excluding)
Mongodb Mongodb 3.6.0 (including) 3.6.15 (excluding)
Mongodb Mongodb 4.0.0 (including) 4.0.13 (excluding)
Mongodb Mongodb 4.2.0 (including) 4.2.1 (excluding)
Mongodb Ubuntu bionic *
Mongodb Ubuntu focal *
Mongodb Ubuntu trusty *
Mongodb Ubuntu upstream *

Extended Description

This Pillar covers several possibilities:

References