PT-2015-1052 · Mongodb · Mongodb

Published

2015-02-25

·

Updated

2026-02-25

·

CVE-2015-1609

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions MongoDB versions prior to 2.4.13 MongoDB versions 2.6.x prior to 2.6.8
Description The issue allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request. This can be exploited by sending a specially formed string in the UTF-8 format, leading to a denial of service.
Recommendations For MongoDB versions prior to 2.4.13, update to version 2.4.13 or later. For MongoDB versions 2.6.x prior to 2.6.8, update to version 2.6.8 or later.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09907
CVE-2015-1609
MGASA-2015-0130
USN-8064-1

Affected Products

Mongodb