CVE-2015-1609: Input Validation
Published Mar 30, 2015
·Updated
MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.
Affected Software
10 affected components
fedoraproject fedora=21
MongoDB MongoDB<=2.4.12
MongoDB MongoDB=2.6.0
MongoDB MongoDB=2.6.1
MongoDB MongoDB=2.6.2
MongoDB MongoDB=2.6.3
MongoDB MongoDB=2.6.4
MongoDB MongoDB=2.6.5
MongoDB MongoDB=2.6.6
MongoDB MongoDB=2.6.7
Event History
Mar 30, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1609?
CVE-2015-1609 is classified as a denial of service vulnerability which can significantly impact the availability of affected MongoDB instances.
2
How do I fix CVE-2015-1609?
To fix CVE-2015-1609, you should update MongoDB to versions 2.4.13 or later, or 2.6.8 or later.
3
What versions of MongoDB are affected by CVE-2015-1609?
CVE-2015-1609 affects MongoDB versions prior to 2.4.13 and 2.6.x prior to 2.6.8.
4
Can CVE-2015-1609 be exploited remotely?
Yes, CVE-2015-1609 allows remote attackers to exploit the vulnerability through a crafted UTF-8 string in a BSON request.
5
Is there a workaround for CVE-2015-1609?
There are no specific workarounds for CVE-2015-1609; the best solution is to upgrade to the patched versions.