Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 13.10: 2023-5 Important: PyMongo Threat Response

ubuntu
Calendar Grey July 3, 2013
Scroller Ubuntu
Ensure your Ubuntu system is patched to address the PyMongo vulnerability noted in USN-1897-1, impacting several iterations.
PyMongo could be made to crash under certain conditions.

Summary

PyMongo could be made to crash under certain conditions.

Software Description:

- pymongo: Python interface to the MongoDB document-oriented database

Details:

Jibbers McGee discovered that PyMongo incorrectly handled certain invalid

DBRefs. An attacker could use this issue to cause PyMongo to crash,

resulting in a denial of service.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  python-bson                     2.2-4ubuntu0.1
  python-bson-ext                 2.2-4ubuntu0.1

Ubuntu 12.10:
  python-bson                     2.2-2ubuntu0.1
  python-bson-ext                 2.2-2ubuntu0.1

Ubuntu 12.04 LTS:
  python-bson                     2.1-1ubuntu0.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1897-1

CVE-2013-2132

Severity
important
Lowest
Low
Medium
High
Critical

July 03, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.