CVE-2019-2392: $mod can result in undefined behavior
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use the $mod operator to overflow negative values. This issue affects: MongoDB Inc. MongoDB Server v4.4 versions prior to 4.4.1; v4.2 versions prior to 4.2.9; v4.0 versions prior to 4.0.20; v3.6 versions prior to 3.6.20.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-2392.
What is the severity of CVE-2019-2392?
The severity of CVE-2019-2392 is medium, with a severity value of 6.5.
What software versions are affected by CVE-2019-2392?
CVE-2019-2392 affects MongoDB Server v4.4 versions prior to 4.4.1; v4.2 versions prior to 4.2.9; v4.0 versions prior to 4.0.20; v3.6 versions prior to 3.6.20.
How can this vulnerability be exploited?
This vulnerability can be exploited by a user authorized to perform database queries by issuing specially crafted queries that use the $mod operator to overflow negative values.
Is there a fix available for CVE-2019-2392?
Yes, the fix for CVE-2019-2392 is included in MongoDB Server version 4.4.1, 4.2.9, 4.0.20, and 3.6.20.