An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects MongoDB Server v4.2 versions prior to 4.2.1; MongoDB Server v4.0 versions prior to 4.0.13; MongoDB Server v3.6 versions prior to 3.6.15 and MongoDB Server v3.4 versions prior to 3.4.24.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HMongodb
APPMongodb3.4.0 – 3.4.24 (bez)3.6.0 – 3.6.15 (bez)4.0.0 – 4.0.13 (bez)4.2.0 – 4.2.1 (bez)
Powiązane podatności
Heap Buffer Overflow w MongoDB (tryb compute) podczas przetwarzania BSON
MongoDB: podatność w kompresji protokołu sieciowego — DoS i modyfikacja pamięci
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by ...
MongoDB: DoS poprzez wyrażenie agregacji $_internalIndexKey z compound wildcard index
MongoDB – wyczerpanie pamięci przez wyrażenia generujące duże tablice (DoS)