USN-6904-1: PyMongo vulnerability
It was discovered that PyMongo incorrectly handled certain BSON. An attacker could possibly use this issue to read sensitive information or cause a crash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6904-1?
The severity of USN-6904-1 is classified as important due to the potential for an attacker to read sensitive information or cause application crashes.
How do I fix USN-6904-1?
To fix USN-6904-1, you should upgrade to the recommended packages: python3-bson and python3-bson-ext version 3.11.0-1ubuntu0.24.04.1 for Ubuntu 24.04.
Which software is affected by USN-6904-1?
USN-6904-1 affects the python3-bson and python3-bson-ext packages across multiple Ubuntu versions including 24.04, 22.04, 20.04, and 18.04.
What issues does USN-6904-1 address?
USN-6904-1 addresses issues related to improper handling of BSON in PyMongo that can lead to information disclosure and crashes.
Is there a workaround for USN-6904-1?
There is no specific workaround for USN-6904-1; upgrading to the patched versions is the only recommended action.