CVE-2013-2132: Null Pointer Dereference
Published Jun 1, 2013
·Updated
bson/cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."
Affected Software
22 affected componentsFixes available
pip/pymongo<2.5.2
2.5.2
debian/2.2-4<=undefined
debian/2.5-1<=undefined
debian/pymongo
3.11.0-13.11.0-1+deb11u13.11.0-1+deb12u14.10.1-2
MongoDB MongoDB<=2.5.1
MongoDB MongoDB=1.2.0
MongoDB MongoDB=1.4.0
MongoDB MongoDB=1.6.0
MongoDB MongoDB=1.8.0
MongoDB MongoDB=2.0.0
MongoDB MongoDB=2.2.0
MongoDB MongoDB=2.4.0
MongoDB MongoDB=2.4.1
MongoDB MongoDB=2.4.2
MongoDB MongoDB=2.4.3
MongoDB MongoDB=2.4.4
MongoDB MongoDB=2.4.5
MongoDB MongoDB=2.5.0
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=12.10
Canonical Ubuntu Linux=13.04
openSUSE openSUSE=12.3
Remediation
Event History
Aug 15, 2013
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:55 PM
RemedyDescriptionSeverityAffected Software
May 14, 2022
Advisory Published
via GitHub·02:10 AM
Frequently Asked Questions
1
What is the severity of CVE-2013-2132?
CVE-2013-2132 is classified as a denial of service vulnerability due to a NULL pointer dereference.
2
How do I fix CVE-2013-2132?
To fix CVE-2013-2132, update the pymongo package to version 2.5.2 or later.
3
What software is affected by CVE-2013-2132?
CVE-2013-2132 affects pymongo versions before 2.5.2 and several versions of MongoDB.
4
Can CVE-2013-2132 cause any data loss?
CVE-2013-2132 primarily leads to a denial of service but does not inherently cause data loss.
5
Is CVE-2013-2132 specific to certain operating systems?
CVE-2013-2132 is not specific to any operating system, as it affects the pymongo library used across various platforms.