CVE-2018-16790: High severity mongodb bson vulnerability
Published Sep 10, 2018
·Updated
bsoniternextinternal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read via a crafted bson buffer.
Affected Software
2 affected componentsFixes available
redhat/libbson<1.13.0
1.13.0
MongoDB libbson=1.12.0
Remediation
Event History
Sep 10, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Data Sourced
via NVD·05:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-16790.
2
What is the severity of CVE-2018-16790?
The severity of CVE-2018-16790 is high with a severity value of 8.1.
3
Which software is affected by CVE-2018-16790?
The software affected by CVE-2018-16790 includes libbson version 1.12.0 and MongoDB mongo-c-driver.
4
How can I fix CVE-2018-16790?
To fix CVE-2018-16790, you should update libbson to version 1.13.0 or higher.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-16790?
The Common Weakness Enumeration (CWE) ID for CVE-2018-16790 is CWE-125.