Back

MEDIUM

Process termination via PID file manipulation

Published Aug 30, 2019

Description

Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the PID file to insert arbitrary PIDs to be killed when the root user stops the MongoDB process via SysV init. This issue affects MongoDB Server v4.0 versions prior to 4.0.11; MongoDB Server v3.6 versions prior to 3.6.14; MongoDB Server v3.4 versions prior to 3.4.22.

Affected products

Remediation

Red Hat statement

This issue affects the mongodb packages as shipped in the Red Hat Enterprise Linux version 6 release of Red Hat Software Collections. For the Red Hat Enterprise Linux version 7 release of Red Hat Software Collections, refer to systemd CVE-2018-16888. Red Hat Satellite 6 is using MongoDB, but is not considered vulnerable because it is using the systemd service file. Please refer to CVE-2018-16888.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mongodb
Published Aug 30, 2019
Updated Aug 4, 2024
Reserved Dec 10, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 30, 2019