← Retour aux CVEs
CVE-2013-1892
N/ADescription
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute arbitrary code via a crafted memory address in the first argument.
Details CVE
Score CVSS v3.1N/A
Publie10/1/2013
Derniere modification4/29/2026
Sourcenvd
Observations honeypot0
Produits affectes
mongodb:mongodbredhat:enterprise_mrg
Faiblesses (CWE)
CWE-20
References
http://blog.scrt.ch/2013/03/24/mongodb-0-day-ssji-to-rce/(secalert@redhat.com)
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101630.html(secalert@redhat.com)
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101679.html(secalert@redhat.com)
http://rhn.redhat.com/errata/RHSA-2013-1170.html(secalert@redhat.com)
http://www.exploit-db.com/exploits/24935(secalert@redhat.com)
http://www.exploit-db.com/exploits/24947(secalert@redhat.com)
http://www.mongodb.org/about/alerts/(secalert@redhat.com)
http://www.openwall.com/lists/oss-security/2013/03/25/9(secalert@redhat.com)
https://jira.mongodb.org/browse/SERVER-9124(secalert@redhat.com)
http://blog.scrt.ch/2013/03/24/mongodb-0-day-ssji-to-rce/(af854a3a-2127-422b-91ae-364da2661108)
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101630.html(af854a3a-2127-422b-91ae-364da2661108)
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101679.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2013-1170.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.exploit-db.com/exploits/24935(af854a3a-2127-422b-91ae-364da2661108)
http://www.exploit-db.com/exploits/24947(af854a3a-2127-422b-91ae-364da2661108)
http://www.mongodb.org/about/alerts/(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2013/03/25/9(af854a3a-2127-422b-91ae-364da2661108)
https://jira.mongodb.org/browse/SERVER-9124(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.