Security
Headlines
HeadlinesLatestCVEs

Headline

Ubuntu Security Notice USN-6904-1

Ubuntu Security Notice 6904-1 - It was discovered that PyMongo incorrectly handled certain BSON. An attacker could possibly use this issue to read sensitive information or cause a crash.

Packet Storm
#vulnerability#ubuntu#mongo

==========================================================================
Ubuntu Security Notice USN-6904-1
July 22, 2024

pymongo vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 24.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 LTS
  • Ubuntu 16.04 LTS

Summary:

PyMongo could be made to crash or expose sensitive information if it
received a crafted BSON.

Software Description:

  • pymongo: Python interface to the MongoDB document-oriented database

Details:

It was discovered that PyMongo incorrectly handled certain BSON.
An attacker could possibly use this issue to read sensitive information
or cause a crash.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
python3-bson 3.11.0-1ubuntu0.24.04.1
python3-bson-ext 3.11.0-1ubuntu0.24.04.1

Ubuntu 22.04 LTS
python3-bson 3.11.0-1ubuntu0.22.04.1
python3-bson-ext 3.11.0-1ubuntu0.22.04.1

Ubuntu 20.04 LTS
python3-bson 3.10.1-0ubuntu2.1
python3-bson-ext 3.10.1-0ubuntu2.1

Ubuntu 18.04 LTS
python-bson 3.6.1+dfsg1-1ubuntu0.1~esm1
Available with Ubuntu Pro
python-bson-ext 3.6.1+dfsg1-1ubuntu0.1~esm1
Available with Ubuntu Pro
python3-bson 3.6.1+dfsg1-1ubuntu0.1~esm1
Available with Ubuntu Pro
python3-bson-ext 3.6.1+dfsg1-1ubuntu0.1~esm1
Available with Ubuntu Pro

Ubuntu 16.04 LTS
python-bson 3.2-1ubuntu0.1~esm1
Available with Ubuntu Pro
python-bson-ext 3.2-1ubuntu0.1~esm1
Available with Ubuntu Pro
python3-bson 3.2-1ubuntu0.1~esm1
Available with Ubuntu Pro
python3-bson-ext 3.2-1ubuntu0.1~esm1
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6904-1
CVE-2024-5629

Package Information:
https://launchpad.net/ubuntu/+source/pymongo/3.11.0-1ubuntu0.24.04.1
https://launchpad.net/ubuntu/+source/pymongo/3.11.0-1ubuntu0.22.04.1
https://launchpad.net/ubuntu/+source/pymongo/3.10.1-0ubuntu2.1

Related news

GHSA-m87m-mmvp-v9qm: PyMongo Out-of-bounds Read in the bson module

Versions of the package pymongo before 4.6.3 are vulnerable to Out-of-bounds Read in the bson module. Using the crafted payload the attacker could force the parser to deserialize unmanaged memory. The parser tries to interpret bytes next to buffer and throws an exception with string. If the following bytes are not printable UTF-8 the parser throws an exception with a single byte.

Packet Storm: Latest News

Zeek 6.0.8