CVE-2015-1609
published 2015-03-30CVE-2015-1609: MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.78%
84.8th percentile
MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| mongodb | mongodb | <= 2.4.12 | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | — | — |
| mongodb | mongodb | >= 0 < 1:2.4.9-1ubuntu2+esm2 | 1:2.4.9-1ubuntu2+esm2 |
| mongodb | mongodb | >= 0 < 1:2.6.10-0ubuntu1+esm2 | 1:2.6.10-0ubuntu1+esm2 |
| mongodb | mongodb | >= 0 < 1:3.6.3-0ubuntu1.4+esm1 | 1:3.6.3-0ubuntu1.4+esm1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
mongodb vulnerabilities
osv·2026-02-25·CVSS 5.0
CVE-2015-1609 [MEDIUM] mongodb vulnerabilities
mongodb vulnerabilities
Eliot Horowitz discovered that MongoDB may fail to validate some instances
of malformed BSON. A remote attacker could possibly use this issue to cause
MongoDB to crash, resulting in a denial of service. This issue only
affected Ubuntu 14.04 LTS. (CVE-2015-1609)
It was discovered that MongoDB read raw permissions from .dbshell history
files. A local attacker could possibly use this issue to obtain sensitive
information. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04
LTS. (CVE-2016-6494)
Travis Brown discovered that MongoDB may be unable to parse specially
crafted UTF-8 strings in BSON requests. A remote attacker could possibly
use this issue to cause MongoDB to crash, resulting in a denial of service.
This issue only affected Ubuntu 18.04 LTS. (CVE-201
GHSA
GHSA-vpxf-9vr8-jf96: MongoDB before 2
ghsa_unreviewed·2022-05-17
CVE-2015-1609 [MEDIUM] CWE-20 GHSA-vpxf-9vr8-jf96: MongoDB before 2
MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.
OSV
CVE-2015-1609: MongoDB before 2
osv·2015-03-30·CVSS 5.0
CVE-2015-1609 [MEDIUM] CVE-2015-1609: MongoDB before 2
MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.
Ubuntu
MongoDB vulnerabilities
vendor_ubuntu·2026-02-25·CVSS 5.0
CVE-2018-20802 [MEDIUM] MongoDB vulnerabilities
Title: MongoDB vulnerabilities
Summary: Several security issues were fixed in MongoDB.
Eliot Horowitz discovered that MongoDB may fail to validate some instances
of malformed BSON. A remote attacker could possibly use this issue to cause
MongoDB to crash, resulting in a denial of service. This issue only
affected Ubuntu 14.04 LTS. (CVE-2015-1609)
It was discovered that MongoDB read raw permissions from .dbshell history
files. A local attacker could possibly use this issue to obtain sensitive
information. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04
LTS. (CVE-2016-6494)
Travis Brown discovered that MongoDB may be unable to parse specially
crafted UTF-8 strings in BSON requests. A remote attacker could possibly
use this issue to cause MongoDB to crash, resulting in a denial
Red Hat
mongodb: DoS due to improper BSON validation
vendor_redhat·2015-02-17·CVSS 5.0
CVE-2015-1609 [MEDIUM] CWE-20 mongodb: DoS due to improper BSON validation
mongodb: DoS due to improper BSON validation
MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.
A flaw was found in the way MongoDB processed certain BSON-serialized UTF-8 strings. A remote, unauthenticated attacker could use this flaw to crash a mongod server via a specially crafted BSON message.
Package: mongodb (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Fix deferred
Package: mongodb (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Fix deferred
Package: mongodb (Red Hat OpenShift Enterprise 2) - Will not fix
Package: mongodb (Red Hat OpenStack Platform 4) - Will not fix
Package: mongodb24-mongodb (Red Hat Software Collections) - Will not fix
Package: mongodb (Red
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1609 mongodb: DoS due to improper BSON validation [epel-7]
bugzilla·2015-03-10·CVSS 5.0
CVE-2015-1609 [MEDIUM] CVE-2015-1609 mongodb: DoS due to improper BSON validation [epel-7]
CVE-2015-1609 mongodb: DoS due to improper BSON validation [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for mongodb: see blocks bug list for full
Bugzilla
CVE-2015-1609 mongodb: DoS due to improper BSON validation [fedora-all]
bugzilla·2015-03-10·CVSS 5.0
CVE-2015-1609 [MEDIUM] CVE-2015-1609 mongodb: DoS due to improper BSON validation [fedora-all]
CVE-2015-1609 mongodb: DoS due to improper BSON validation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora
Bugzilla
CVE-2015-1609 mongodb: DoS due to improper BSON validation [epel-6]
bugzilla·2015-03-10·CVSS 5.0
CVE-2015-1609 [MEDIUM] CVE-2015-1609 mongodb: DoS due to improper BSON validation [epel-6]
CVE-2015-1609 mongodb: DoS due to improper BSON validation [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-6 tracking bug for mongodb: see blocks bug list for full
Bugzilla
CVE-2015-1609 mongodb: DoS due to improper BSON validation
bugzilla·2015-03-10·CVSS 5.0
CVE-2015-1609 [MEDIUM] CVE-2015-1609 mongodb: DoS due to improper BSON validation
CVE-2015-1609 mongodb: DoS due to improper BSON validation
It was found that the mongod server did not correctly validate certain malformed BSON requests. A remote, unauthenticated attacker could use a specially crafted BSON message to crash a mongod server.
Upstream issue:
https://jira.mongodb.org/browse/SERVER-17264
Upstream patches:
2.4 -- https://github.com/mongodb/mongo/commit/3a7e85ea1f672f702660e5472566234b1d19038e
2.6 -- https://github.com/mongodb/mongo/commit/8f1c734c7f1862180f607c241fb167640889efba
3.0 -- https://github.com/mongodb/mongo/commit/5285225e71c5c0652520ef99d0ae4ca24655f72f
Discussion:
Created mongodb tracking bugs for this issue:
Affects: fedora-all [bug 1200447]
Affects: epel-6 [bug 1200448]
Affects: epel-7 [bug 1200449]
---
mongodb-2.6.8-1.fc22 has been pu
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152493.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/153690.htmlhttp://www.securitytracker.com/id/1034466http://www.splunk.com/view/SP-CAAAPC3https://jira.mongodb.org/browse/SERVER-17264https://security.gentoo.org/glsa/201611-13http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152493.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/153690.htmlhttp://www.securitytracker.com/id/1034466http://www.splunk.com/view/SP-CAAAPC3https://jira.mongodb.org/browse/SERVER-17264https://security.gentoo.org/glsa/201611-13
2015-03-30
Published