CVE-2024-6381

CVSS V2 None CVSS V3 None
Description
The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson versions prior to 1.26.2
Overview
  • CVE ID
  • CVE-2024-6381
  • Assigner
  • mongodb
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-07-02T17:14:48.908Z
  • Last Modified Date
  • 2024-07-02T18:57:49.237Z
References
Reference URL Reference Tags
https://jira.mongodb.org/browse/CDRIVER-5622
History
Created Old Value New Value Data Type Notes
2024-07-03 13:07:55 Added to TrackCVE