CVE-2013-3969: Medium severity mongodb vulnerability
The find prototype in scripting/enginev8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and server crash) or possibly execute arbitrary code via an invalid RefDB object.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3969?
CVE-2013-3969 is classified as a critical vulnerability due to its potential for remote code execution and denial of service.
How do I fix CVE-2013-3969?
To resolve CVE-2013-3969, upgrade MongoDB to version 2.4.5 or later, which includes the necessary security patches.
Who is affected by CVE-2013-3969?
CVE-2013-3969 affects all versions of MongoDB from 2.4.0 to 2.4.4.
What type of vulnerability is CVE-2013-3969?
CVE-2013-3969 is a denial of service vulnerability that can be exploited through an uninitialized pointer dereference.
Can CVE-2013-3969 lead to data compromise?
Yes, CVE-2013-3969 could potentially allow an attacker to execute arbitrary code, leading to data compromise.