CVE-2019-20925: Denial of service via malformed network packet
An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects MongoDB Server v4.2 versions prior to 4.2.1; MongoDB Server v4.0 versions prior to 4.0.13; MongoDB Server v3.6 versions prior to 3.6.15 and MongoDB Server v3.4 versions prior to 3.4.24.
Other sources
An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects: MongoDB Inc. MongoDB Server v4.2 versions prior to 4.2.1; v4.0 versions prior to 4.0.13; v3.6 versions prior to 3.6.15; v3.4 versions prior to 3.4.24.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-20925?
CVE-2019-20925 is a vulnerability that allows an unauthenticated client to trigger denial of service in MongoDB Server versions prior to 4.2.1, 4.0.13, and 3.6.15 by issuing specially crafted wire protocol messages.
How does CVE-2019-20925 affect MongoDB?
CVE-2019-20925 affects MongoDB Server versions prior to 4.2.1, 4.0.13, and 3.6.15 by causing the message decompressor to incorrectly allocate memory, leading to denial of service.
What is the severity of CVE-2019-20925?
CVE-2019-20925 has a severity rating of 7.5 (High).
How can I fix CVE-2019-20925?
To fix CVE-2019-20925, upgrade MongoDB Server to version 4.2.1, 4.0.13, or 3.6.15.
Where can I find more information about CVE-2019-20925?
More information about CVE-2019-20925 can be found at the following reference link: https://jira.mongodb.org/browse/SERVER-43751