Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian: DSA-2705-1 Moderate: Pymongo Denial Of Service Threat

debian
Calendar Grey June 10, 2013
Debian Logo
Pymongo encounters a critical patch addressing a potential service disruption threat; upgrade advised for both production and experimental versions.
Jibbers McGee discovered that pymongo, a high-performance schema-free document-oriented data store, is prone to a denial-of-service vulnerability

Summary

Jibbers McGee discovered that pymongo, a high-performance schema-free
document-oriented data store, is prone to a denial-of-service
vulnerability.
An attacker can remotely trigger a NULL pointer dereference causing MongoDB
to crash.


The oldstable distribution (squeeze), is not affected by this issue.

For the stable distribution (wheezy), this problem has been fixed in
version 2.2-4+deb7u1.

For the testing distribution (jessie), this problem has been fixed in
version 2.5.2-1.

For the unstable distribution (sid), this problem has been fixed in
version 2.5.2-1.

We recommend that you upgrade your pymongo packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: pymongo
CVE ID: CVE-2013-2132

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here