Upstream information

CVE-2013-2132 at MITRE

Description

bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."

SUSE information

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.30
Vector AV:N/AC:M/Au:N/C:N/I:N/A:P
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
SUSE Bugzilla entry: 822798 [CLOSED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5
  • python-pymongo >= 2.6.3-2.20
Patchnames:
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5 GA python-pymongo
SUSE OpenStack Cloud 6
  • python-pymongo >= 3.0.3-1.1
Patchnames:
SUSE OpenStack Cloud 6 GA python-pymongo
openSUSE 13.2
  • python-pymongo >= 2.7.2-2.1.4
Patchnames:
openSUSE 13.2 GA python-pymongo
openSUSE Tumbleweed
  • python-pymongo >= 3.1.1-1.5
  • python3-pymongo >= 3.4.0-1.1
Patchnames:
openSUSE Tumbleweed GA python-pymongo