PT-2014-5645 · Mongodb · Mongodb

Published

2014-12-25

·

Updated

2014-12-29

·

CVE-2014-3971

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions MongoDB versions 2.6.0 through 2.6.1
Description The issue allows remote attackers to cause a denial of service by attempting authentication with an invalid X.509 client certificate, leading to a daemon crash. This is due to a problem in the CmdAuthenticate:: authenticateX509 function.
Recommendations For MongoDB versions 2.6.0 through 2.6.1, update to version 2.6.2 or later to resolve the issue.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3971

Affected Products

Mongodb