Back

HIGH

libbson: Heap based buffer over read in the bson_utf8_validate function

Published Sep 9, 2017

Description

In MongoDB libbson 1.7.0, the bson_iter_codewscope function in bson-iter.c miscalculates a bson_utf8_validate length argument, which allows remote attackers to cause a denial of service (heap-based buffer over-read in the bson_utf8_validate function in bson-utf8.c), as demonstrated by bson-to-json.c.

Affected products

Remediation

No remediation recorded yet.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 9, 2017
Updated Nov 3, 2025
Reserved Sep 9, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 7, 2017