PT-2015-1052 · Mongodb · Mongodb

Publicado

2015-02-25

·

Atualizado

2026-02-25

·

CVE-2015-1609

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions MongoDB versions prior to 2.4.13 MongoDB versions 2.6.x prior to 2.6.8
Description The issue allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request. This can be exploited by sending a specially formed string in the UTF-8 format, leading to a denial of service.
Recommendations For MongoDB versions prior to 2.4.13, update to version 2.4.13 or later. For MongoDB versions 2.6.x prior to 2.6.8, update to version 2.6.8 or later.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09907
CVE-2015-1609
MGASA-2015-0130
USN-8064-1

Produtos afetados

Mongodb