First published: Tue Oct 29 2019(Updated: )
Kevin Backhouse discovered an integer overflow in bson_ensure_space, as used in whoopsie.
Credit: security@ubuntu.com security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Whoopsie Project Whoopsie | ||
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.04 | |
Canonical Ubuntu Linux | =19.10 | |
ubuntu/whoopsie | <0.2.62ubuntu0.2 | 0.2.62ubuntu0.2 |
ubuntu/whoopsie | <0.2.64ubuntu0.2 | 0.2.64ubuntu0.2 |
ubuntu/whoopsie | <0.2.66ubuntu0.1 | 0.2.66ubuntu0.1 |
ubuntu/whoopsie | <0.2.68 | 0.2.68 |
ubuntu/whoopsie | <0.2.68 | 0.2.68 |
ubuntu/whoopsie | <0.2.68 | 0.2.68 |
ubuntu/whoopsie | <0.2.68 | 0.2.68 |
ubuntu/whoopsie | <0.2.68 | 0.2.68 |
ubuntu/whoopsie | <0.2.68 | 0.2.68 |
ubuntu/whoopsie | <0.2.68 | 0.2.68 |
ubuntu/whoopsie | <0.2.68 | 0.2.68 |
ubuntu/whoopsie | <0.2.68 | 0.2.68 |
ubuntu/whoopsie | <0.2.52.5ubuntu0.2 | 0.2.52.5ubuntu0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11484 is an integer overflow vulnerability in bson_ensure_space, as used in whoopsie.
CVE-2019-11484 has a severity rating of 7.8 (high).
The software affected by CVE-2019-11484 includes Whoopsie Project Whoopsie and Canonical Ubuntu Linux versions 16.04, 18.04, 19.04, and 19.10.
To fix CVE-2019-11484, it is recommended to update the affected software to the latest version provided by the vendor.
For more information about CVE-2019-11484, you can refer to the following sources: [link1](http://packetstormsecurity.com/files/172858/Ubuntu-Apport-Whoopsie-DoS-Integer-Overflow.html), [link2](https://usn.ubuntu.com/usn/usn-4170-1), [link3](https://usn.ubuntu.com/usn/usn-4170-2).