In MongoDB libbson 1.7.0, the bson_iter_codewscope function in bson-iter.c miscalculates a bson_utf8_validate length argument, which allows remote attackers to cause a denial of service (heap-based buffer over-read in the bson_utf8_validate function in bson-utf8.c), as demonstrated by bson-to-json.c.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-libbson-xs-perl | May 12, 2025 | May 12, 2025 | |
| Freebsd | freebsd-upgrade-package-libbson | Sep 26, 2017 | Sep 26, 2017 | |
| Mongodb | mongodb-upgrade-latest | Oct 31, 2019 | Sep 9, 2017 | |
| Ubuntu | ubuntu-pro-upgrade-libbson-1-0-0 | Mar 22, 2023 | Sep 9, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub