DescriptionMongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs780129

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mongodbsourcesqueeze(not affected)
mongodbsourcewheezy(not affected)


[wheezy] - mongodb <not-affected> (BSONElement::validate() checks length, problematic code introduced later)
[squeeze] - mongodb <not-affected> (BSONElement::validate() checks length (db/jsobj.cpp +589))
Fast bson validate introduced with (r2.3.2)

Search for package or bug name: Reporting problems