CVE-2013-1892: Input Validation
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute arbitrary code via a crafted memory address in the first argument.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1892?
CVE-2013-1892 has a moderate severity rating due to its potential to cause denial of service and arbitrary code execution.
How do I fix CVE-2013-1892?
To fix CVE-2013-1892, upgrade MongoDB to version 2.0.9 or later, or 2.2.4 or later.
What versions of MongoDB are affected by CVE-2013-1892?
CVE-2013-1892 affects MongoDB versions below 2.0.9 and 2.2.x below 2.2.4.
What type of attack is possible with CVE-2013-1892?
CVE-2013-1892 allows remote authenticated users to exploit the vulnerability for denial of service or execute arbitrary code.
Is CVE-2013-1892 a local or remote vulnerability?
CVE-2013-1892 is a remote vulnerability that requires authentication to exploit.