Upstream information

CVE-2013-2132 at MITRE


bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.3
Vector AV:N/AC:M/Au:N/C:N/I:N/A:P
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
SUSE Bugzilla entry: 822798 [VERIFIED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5
  • python-pymongo >= 2.6.3-2.20
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5 GA python-pymongo-2.6.3-2.20
SUSE OpenStack Cloud 6
  • python-pymongo >= 3.0.3-1.1
SUSE OpenStack Cloud 6 GA python-pymongo-3.0.3-1.1
openSUSE Tumbleweed
  • python-pymongo >= 3.1.1-1.5
  • python3-pymongo >= 3.4.0-1.1
  • python36-pymongo >= 3.11.4-1.2
  • python38-pymongo >= 3.11.4-1.2
  • python39-pymongo >= 3.11.4-1.2
openSUSE Tumbleweed GA python-pymongo-3.1.1-1.5
openSUSE Tumbleweed GA python36-pymongo-3.11.4-1.2