—
PYSEC-2013-30
Quick fix
PYSEC-2013-30 — pymongo: upgrade to the fixed version with the command below.
pip install --upgrade 'pymongo>=a060c15ef87e0f0e72974c7c0e57fe811bbd06a2'Details
bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/pymongo
Introduced in:
0Fixed in: a060c15ef87e0f0e72974c7c0e57fe811bbd06a2Fix
pip install --upgrade 'pymongo>=a060c15ef87e0f0e72974c7c0e57fe811bbd06a2'References
- http://www.securityfocus.com/bid/60252[WEB]
- http://lists.opensuse.org/opensuse-updates/2013-06/msg00180.html[WEB]
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=710597[WEB]
- http://www.osvdb.org/93804[WEB]
- https://github.com/mongodb/mongo-python-driver/commit/a060c15ef87e0f0e72974c7c0e57fe811bbd06a2[FIX]
- http://ubuntu.com/usn/usn-1897-1[WEB]
- http://www.debian.org/security/2013/dsa-2705[ADVISORY]
- http://seclists.org/oss-sec/2013/q2/447[WEB]
- https://jira.mongodb.org/browse/PYTHON-532[WEB]
- https://github.com/advisories/GHSA-x33v-f3gp-gw2c[ADVISORY]