mongodb.mongo-c-driver is vulnerable to Double Free
82
High Risk
libmongoc checks certificate revocation over OpenSSL by building an OCSP request for each responder URL listed in a peer certificate. When a certificate advertises multiple OCSP responder URLs, mongoc-openssl.c frees the same request objects more than once along the request-handling path, producing a double free. A TLS peer presenting such a certificate triggers the crash during the handshake, terminating the client process. The fix makes the OCSP cleanup unconditional and single-shot so each object is released exactly once.
You are affected if you are using a version that falls within the vulnerable range and your application uses TLS with OCSP revocation checking enabled (OCSP stapling disabled) against a server whose certificate advertises multiple OCSP responder URLs.
mongodb.mongo-c-driver is vulnerable to Double Free in versions 1.17.0 - 1.30.8 and 2.0.0 - 2.5.1.
Upgrade the mongodb.mongo-c-driver library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.