CVE-2016-3104

mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database.
References
Link Resource
http://www.securityfocus.com/bid/94929 Third Party Advisory VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1324496 Issue Tracking Third Party Advisory VDB Entry
https://jira.mongodb.org/browse/SERVER-24378 Vendor Advisory
http://www.securityfocus.com/bid/94929 Third Party Advisory VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1324496 Issue Tracking Third Party Advisory VDB Entry
https://jira.mongodb.org/browse/SERVER-24378 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:2.6.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:49

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/94929 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/94929 - Third Party Advisory, VDB Entry
References () https://bugzilla.redhat.com/show_bug.cgi?id=1324496 - Issue Tracking, Third Party Advisory, VDB Entry () https://bugzilla.redhat.com/show_bug.cgi?id=1324496 - Issue Tracking, Third Party Advisory, VDB Entry
References () https://jira.mongodb.org/browse/SERVER-24378 - Vendor Advisory () https://jira.mongodb.org/browse/SERVER-24378 - Vendor Advisory

Information

Published : 2017-04-14 18:59

Updated : 2024-11-21 02:49


NVD link : CVE-2016-3104

Mitre link : CVE-2016-3104

CVE.ORG link : CVE-2016-3104


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-400

Uncontrolled Resource Consumption