CVE-2024-6381
02.07.2024, 18:15
The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson versions prior to 1.26.2Enginsight
| Vendor | Product | Version |
|---|---|---|
| mongodb | libbson | 𝑥 < 1.26.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libbson |
| ||||||||||||||||||
| mongo-c-driver |
|
Common Weakness Enumeration