UBUNTU-CVE-2019-20925
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-20925
UBUNTU-CVE-2019-20925
Summary:
Details: An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects MongoDB Server v4.2 versions prior to 4.2.1; MongoDB Server v4.0 versions prior to 4.0.13; MongoDB Server v3.6 versions prior to 3.6.15 and MongoDB Server v3.4 versions prior to 3.4.24.
References: https://ubuntu.com/security/CVE-2019-20925, https://jira.mongodb.org/browse/SERVER-43751, https://ubuntu.com/security/notices/USN-5101-1, https://www.cve.org/CVERecord?id=CVE-2019-20925
Affected packages
Package
Name: mongodb
Purl: pkg:deb/ubuntu/mongodb@1:3.6.3-0ubuntu1.4?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
