_bson_iter_next_internal in BSON-iter.c in libbson 1.12.0, come usato in MongoDB mongo-c-conducente e altri prodotti, ha un buffer heap over-lettura attraverso un buffer BSON predisposto. |
https://bugzilla.redhat.com/show_bug.cgi?id=1627923#c3 https://github.com/mongodb/mongo-c-driver/commit/0d9a4d98bfdf4acd2c0138d4aaeb4e2e0934bd84 https://jira.mongodb.org/browse/CDRIVER-2819 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16790 |
Vulnerabilità: CVE-2018-16790
