In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade Debian:13
mongo-c-driver
to version 1.27.5-1 or higher.
Note: Versions mentioned in the description apply only to the upstream mongo-c-driver
package and not the mongo-c-driver
package as distributed by Debian
.
See How to fix?
for Debian:13
relevant fixed versions and status.
The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final BSON document which exceeds the maximum allowable size (INT32_MAX), resulting in a segmentation fault and possible application crash. This issue affected libbson versions prior to 1.27.5, MongoDB Server v8.0 versions prior to 8.0.1 and MongoDB Server v7.0 versions prior to 7.0.16