CVE-2024-6383

The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory. This issue affects libbson versions prior to 1.27.1
Configurations

No configuration.

History

21 Nov 2024, 09:49

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20241004-0001/ -
References () https://jira.mongodb.org/browse/CDRIVER-5628 - () https://jira.mongodb.org/browse/CDRIVER-5628 -

05 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) La función bson_string_append en MongoDB C Driver puede ser vulnerable a un desbordamiento del búfer donde la función podría intentar asignar un búfer demasiado pequeño y puede provocar daños en la memoria del montón vecino. Este problema afecta a las versiones de Libbson anteriores a la 1.27.1.

03 Jul 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-03 22:15

Updated : 2024-11-21 09:49


NVD link : CVE-2024-6383

Mitre link : CVE-2024-6383

CVE.ORG link : CVE-2024-6383


JSON object : View

Products Affected

No product.

CWE
CWE-122

Heap-based Buffer Overflow