CVE-2013-2132
published 2013-08-15CVE-2013-2132: bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.63%
83.8th percentile
bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | pymongo | < pymongo 2.5.2-1 (bookworm) | pymongo 2.5.2-1 (bookworm) |
| mongodb | mongodb | <= 2.5.1 | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PyMongo vulnerability
vendor_ubuntu·2013-07-03
CVE-2013-2132 PyMongo vulnerability
Title: PyMongo vulnerability
Summary: PyMongo could be made to crash under certain conditions.
Jibbers McGee discovered that PyMongo incorrectly handled certain invalid
DBRefs. An attacker could use this issue to cause PyMongo to crash,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
pymongo: null pointer when decoding invalid DBRef
vendor_redhat·2013-05-31·CVSS 4.3
CVE-2013-2132 [MEDIUM] CWE-476 pymongo: null pointer when decoding invalid DBRef
pymongo: null pointer when decoding invalid DBRef
bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."
Statement: Red Hat Update Infrastructure 2.1.3 is now in Production 2 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Update Infrastructure Life Cycle: https://access.redhat.com/support/policy/updates/rhui.
Package: python-pymongo (Red Hat Satellite 6) - Not affected
Debian
CVE-2013-2132: pymongo - bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as u...
vendor_debian·2013·CVSS 4.3
CVE-2013-2132 [MEDIUM] CVE-2013-2132: pymongo - bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as u...
bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."
Scope: local
bookworm: resolved (fixed in 2.5.2-1)
bullseye: resolved (fixed in 2.5.2-1)
forky: resolved (fixed in 2.5.2-1)
sid: resolved (fixed in 2.5.2-1)
trixie: resolved (fixed in 2.5.2-1)
OSV
Use of NullPointerException Catch to Detect NULL Pointer Dereference in Pymongo
osv·2022-05-14
CVE-2013-2132 [MEDIUM] Use of NullPointerException Catch to Detect NULL Pointer Dereference in Pymongo
Use of NullPointerException Catch to Detect NULL Pointer Dereference in Pymongo
bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."
GHSA
Use of NullPointerException Catch to Detect NULL Pointer Dereference in Pymongo
ghsa·2022-05-14
CVE-2013-2132 [MEDIUM] CWE-395 Use of NullPointerException Catch to Detect NULL Pointer Dereference in Pymongo
Use of NullPointerException Catch to Detect NULL Pointer Dereference in Pymongo
bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."
OSV
CVE-2013-2132: bson/_cbsonmodule
osv·2013-08-15·CVSS 4.3
CVE-2013-2132 [MEDIUM] CVE-2013-2132: bson/_cbsonmodule
bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2132 pymongo: null pointer when decoding invalid DBRef [fedora-all]
bugzilla·2013-05-31·CVSS 4.3
CVE-2013-2132 [MEDIUM] CVE-2013-2132 pymongo: null pointer when decoding invalid DBRef [fedora-all]
CVE-2013-2132 pymongo: null pointer when decoding invalid DBRef [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affe
Bugzilla
CVE-2013-2132 pymongo: null pointer when decoding invalid DBRef [epel-all]
bugzilla·2013-05-31·CVSS 4.3
CVE-2013-2132 [MEDIUM] CVE-2013-2132 pymongo: null pointer when decoding invalid DBRef [epel-all]
CVE-2013-2132 pymongo: null pointer when decoding invalid DBRef [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue a
Bugzilla
CVE-2013-2132 pymongo: null pointer when decoding invalid DBRef
bugzilla·2013-05-31·CVSS 4.3
CVE-2013-2132 [MEDIUM] CVE-2013-2132 pymongo: null pointer when decoding invalid DBRef
CVE-2013-2132 pymongo: null pointer when decoding invalid DBRef
A user triggerable null pointer occurs when parsing invalid DBref records.
This was reported by Jibbers McGee.
This can be triggered in Mongo shell:
db.python532.insert({x : {"$ref" : "whatever"} });
Or in Python shell:
import pymongo
pymongo.MongoClient().test.python532.find_one()
A workaround is reportedly available:
Add "process_dbrefs=False" to all the drivers
External reference:
https://jira.mongodb.org/browse/PYTHON-532
Upstream patch:
https://github.com/mongodb/mongo-python-driver/commit/a060c15ef87e0f0e72974c7c0e57fe811bbd06a2
Discussion:
Created mongodb tracking bugs for this issue
Affects: epel-all [bug 969563]
---
Created mongodb tracking bugs for this issue
Affects: fedora-all [bug 969566]
---
This is
arXiv
Toward Validation of Textual Information Retrieval Techniques for Software Weaknesses
arxiv_fulltext·2018-09-05
Toward Validation of Textual Information Retrieval Techniques for Software Weaknesses
Toward Validation of Textual Information
Retrieval Techniques for Software Weaknesses
Jukka Ruohonen
Ville Lepp\"anen
\juanruo, ville.leppanen\@utu.fi
Department of Future Technologies, University of Turku, Finland
## Abstract
This paper presents a preliminary validation of common textual information retrieval techniques for mapping unstructured software vulnerability information to distinct software weaknesses. The validation is carried out with a dataset compiled from four software repositories tracked in the Snyk vulnerability database. According to the results, the information retrieval techniques used perform unsatisfactorily compared to regular expression searches. Although the results vary from a repository to another, the preliminary validation presented indicates that explicit
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=710597http://lists.opensuse.org/opensuse-updates/2013-06/msg00180.htmlhttp://seclists.org/oss-sec/2013/q2/447http://ubuntu.com/usn/usn-1897-1http://www.debian.org/security/2013/dsa-2705http://www.osvdb.org/93804http://www.securityfocus.com/bid/60252https://github.com/mongodb/mongo-python-driver/commit/a060c15ef87e0f0e72974c7c0e57fe811bbd06a2https://jira.mongodb.org/browse/PYTHON-532http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=710597http://lists.opensuse.org/opensuse-updates/2013-06/msg00180.htmlhttp://seclists.org/oss-sec/2013/q2/447http://ubuntu.com/usn/usn-1897-1http://www.debian.org/security/2013/dsa-2705http://www.osvdb.org/93804http://www.securityfocus.com/bid/60252https://github.com/mongodb/mongo-python-driver/commit/a060c15ef87e0f0e72974c7c0e57fe811bbd06a2https://jira.mongodb.org/browse/PYTHON-532
2013-08-15
Published