Junglewise Threat Intelligence

CVE-2013-2132: PYSEC-2013-30 - bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause

CVE-2013-2132 · Severity: medium · CVSS 4 · Published 2013-08-15

Technologies: pymongo (PyPI). Vendors: PyPI.

Executive brief

bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."

Affected products

  • PyPI pymongo

Related threats