Login
Newsletter
Werbung

Sicherheit: Denial of Service in MongoDB
Aktuelle Meldungen Distributionen
Name: Denial of Service in MongoDB
ID: USN-5101-1
Distribution: Ubuntu
Plattformen: Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
Datum: Mo, 4. Oktober 2021, 22:14
Referenzen: https://launchpad.net/ubuntu/+source/mongodb/1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20925
Applikationen: mongoDB

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============8723776844981887209==
Content-Type: multipart/signed; micalg=pgp-sha256;
protocol="application/pgp-signature";
boundary="R927uEq1xtbbKMWzg7anJr0P28iMKcwNW"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--R927uEq1xtbbKMWzg7anJr0P28iMKcwNW
Content-Type: multipart/mixed;
boundary="16ICHypYBtUwYizGJ98YLDqmLMOsA44UQ";
protected-headers="v1"
From: Marc Deslauriers <marc.deslauriers@canonical.com>
Reply-To: Ubuntu Security <security@ubuntu.com>
To: "ubuntu-security-announce@lists.ubuntu.com"
<ubuntu-security-announce@lists.ubuntu.com>
Message-ID: <a5ab85b8-2064-6195-127f-e5a457107a43@canonical.com>
Subject: [USN-5101-1] MongoDB vulnerability

--16ICHypYBtUwYizGJ98YLDqmLMOsA44UQ
Content-Type: text/plain; charset=utf-8
Content-Language: en-C
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-5101-1
October 04, 2021

mongodb vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

MongoDB could be made to crash if it received specially crafted network
traffic.

Software Description:
- mongodb: object/document-oriented database

Details:

It was discovered that MongoDB incorrectly handled certain wire protocol
messages. A remote attacker could possibly use this issue to cause MongoDB
to crash, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
mongodb 1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3
mongodb-clients 1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3
mongodb-server 1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3
mongodb-server-core 1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3

Ubuntu 18.04 LTS:
mongodb 1:3.6.3-0ubuntu1.4
mongodb-clients 1:3.6.3-0ubuntu1.4
mongodb-server 1:3.6.3-0ubuntu1.4
mongodb-server-core 1:3.6.3-0ubuntu1.4

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5101-1
CVE-2019-20925

Package Information:

https://launchpad.net/ubuntu/+source/mongodb/1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3
https://launchpad.net/ubuntu/+source/mongodb/1:3.6.3-0ubuntu1.4


--16ICHypYBtUwYizGJ98YLDqmLMOsA44UQ--

--R927uEq1xtbbKMWzg7anJr0P28iMKcwNW
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmFbQhgACgkQZWnYVadE
vpPcRQ/+PkP8LapVg9fImr1r4Bw/RRJqbdVKfaxaAVS6d2ewrWRCRk+oFhS1ipLr
xd3bnK8mI6hwaEZjqYY62k15H7y5HRmtHRF3cFe11JiIbPyyJW0Lv06ieHA3Vd9o
OHe8VZnFxNzLTsUjk9qMMe7lxXhjtU9w7phPXDL8L6kaH5Dx8cLvRrmjBGc/Z1Cl
sejoYAWKhTVVHeEIHC8chExjAryy9Bxg//+mdEaNYqe0k151+SdU6ArcfAS4em1x
V8fPRWbx+wkVO+yGaM+xKsMC221ivQf/xWHUtwCD1wts1HOJ/uX2ilvHRyvjBsMp
dmEb4X8hQclnOeMl9czY5VFD8vu/koFBfVexTSdU1C2pQWX7YiFBEKcRXBrMY183
S6LmDvuJPhF0kj+jkSkrqMpM9zLZ9KaTw951VwevJ/acg4lW+vVoz1pb6CRjS45T
N6suHgSoLpLAnvFSr/wbWdgp3zdojeAJzFIgsDb5Xxi6euoQ6FKyRCj93OJk/D2Y
/LVX4iGmpDGWG0naIo99T/CwvEK3u0aZDxLSxk+0rHTEYPVNueJPVHYNMAMeLn4r
1KnqMOiYHyOl8to8xP6reMIIsTeaosRzBjPWruQPSf7S37aiyPyZTGL8YGV+8QaA
CUiH7YTbZ7euxq0tzWn6bIoqMI8lZV9z5O8MMPxv4G75k4bmfGA=
=a88a
-----END PGP SIGNATURE-----

--R927uEq1xtbbKMWzg7anJr0P28iMKcwNW--


--===============8723776844981887209==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============8723776844981887209==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung