CVE-2024-6381

July 2, 2024, 6:15 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

libbson

  • before 1.26.2

Source

cna@mongodb.com

Tags

CVE-2024-6381 details

Published : July 2, 2024, 6:15 p.m.
Last Modified : July 2, 2024, 6:15 p.m.

Description

The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson versions prior to 1.26.2

CVSS Score

1 2 3 4.0 5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-680 Integer Overflow to Buffer Overflow The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.

CVSS Data

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

Base Score

4.0

Exploitability Score

2.5

Impact Score

1.4

Base Severity

MEDIUM

References

URL Source
https://jira.mongodb.org/browse/CDRIVER-5622 cna@mongodb.com
This website uses the NVD API, but is not approved or certified by it.