First published: Mon Sep 10 2018(Updated: )
_bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read via a crafted bson buffer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libbson | <1.13.0 | 1.13.0 |
Mongodb Libbson | =1.12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-16790.
The severity of CVE-2018-16790 is high with a severity value of 8.1.
The software affected by CVE-2018-16790 includes libbson version 1.12.0 and MongoDB mongo-c-driver.
To fix CVE-2018-16790, you should update libbson to version 1.13.0 or higher.
The Common Weakness Enumeration (CWE) ID for CVE-2018-16790 is CWE-125.