UBUNTU-CVE-2012-6619

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 06 Mar 2014, 15:55
Last modified:16 Jul 2025, 08:10

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Mar 2014, 15:55
Published
Vulnerability first disclosed
16 Jul 2025, 08:10
Last Modified
Vulnerability information updated

Description

The default configuration for MongoDB before 2.3.2 does not validate objects, which allows remote authenticated users to cause a denial of service (crash) or read system memory via a crafted BSON object in the column name in an insert command, which triggers a buffer over-read.

Affected Systems

  • ubuntumongodb

    < 1:2.4.9-1ubuntu2 | < 1:2.6.10-0ubuntu1 | < 1:3.6.3-0ubuntu1

References (3)