CVE-2018-16790

_bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read via a crafted bson buffer.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mongodb:libbson:1.12.0:*:*:*:*:*:*:*

History

21 Nov 2024, 03:53

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=1627923#c3 - Issue Tracking, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=1627923#c3 - Issue Tracking, Third Party Advisory
References () https://github.com/mongodb/mongo-c-driver/commit/0d9a4d98bfdf4acd2c0138d4aaeb4e2e0934bd84 - Patch () https://github.com/mongodb/mongo-c-driver/commit/0d9a4d98bfdf4acd2c0138d4aaeb4e2e0934bd84 - Patch
References () https://jira.mongodb.org/browse/CDRIVER-2819 - Issue Tracking, Third Party Advisory () https://jira.mongodb.org/browse/CDRIVER-2819 - Issue Tracking, Third Party Advisory

Information

Published : 2018-09-10 05:29

Updated : 2024-11-21 03:53


NVD link : CVE-2018-16790

Mitre link : CVE-2018-16790

CVE.ORG link : CVE-2018-16790


JSON object : View

Products Affected

mongodb

  • libbson
CWE
CWE-125

Out-of-bounds Read