In MongoDB libbson 1.7.0, the bson_iter_codewscope function in bson-iter.c miscalculates a bson_utf8_validate length argument, which allows remote attackers to cause a denial of service (heap-based buffer over-read in the bson_utf8_validate function in bson-utf8.c), as demonstrated by bson-to-json.c.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libbson-xs-perl | May 12, 2025 | May 12, 2025 |
| Freebsd | — | Upgrade libbson | Sep 26, 2017 | Sep 26, 2017 |
| Mongodb | — | Upgrade to the latest version of MongoDB | Oct 31, 2019 | Sep 9, 2017 |
| Ubuntu | — | Upgrade libbson-1.0-0 (Ubuntu Pro) | Mar 22, 2023 | Sep 9, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub