Denial of service via malformed network packet
Published Nov 24, 2020
7.5
HIGHCVSS 3.1
EPSS 1.68%
Description
An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects MongoDB Server v4.2 versions prior to 4.2.1; MongoDB Server v4.0 versions prior to 4.0.13; MongoDB Server v3.6 versions prior to 3.6.15 and MongoDB Server v3.4 versions prior to 3.4.24.
Affected products
-
- Version 3.4StatusaffectedConstraints<3.4.24
- Version 3.6StatusaffectedConstraints<3.6.15
- Version 4.0StatusaffectedConstraints<4.0.13
- Version 4.2StatusaffectedConstraints<4.2.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| MongoDB Inc. | MongoDB Server | unaffected |
|
No data.
Red Hat Advanced Cluster Management for Kubernetes 2
mongodb
Not affected
Red Hat OpenStack Platform 10 (Newton)
mongodb
Out of support scope
Red Hat Software Collections
rh-mongodb36-mongodb
Will not fix
Red Hat Update Infrastructure 3 for Cloud Providers
mongodb
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | mongodb | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | mongodb | Out of support scope | n/a |
| Red Hat Software Collections | rh-mongodb36-mongodb | Will not fix | n/a |
| Red Hat Update Infrastructure 3 for Cloud Providers | mongodb | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://access.redhat.com/security/cve/CVE-2019-20925 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1901527 Issue Tracking
- https://jira.mongodb.org/browse/SERVER-43751 x_refsource_MISCIssue TrackingPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-20925
- https://www.cve.org/CVERecord?id=CVE-2019-20925
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-20925 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1901527 | Issue Tracking | |
| https://jira.mongodb.org/browse/SERVER-43751 | x_refsource_MISCIssue TrackingPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-20925 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-20925 |
Change history (0)
No recorded changes yet.