mongodb/mongodb-extension is vulnerable to Out-of-Bounds Read
69
Medium Risk
MongoDB's PHP driver builds a dotted field path string for exception messages about corrupt BSON from an array of field path elements. When the nesting depth is a multiple of that array's allocation step, the loop reads one element past the end of the allocation and copies adjacent heap memory into the error message. Decoding a corrupt or malformed BSON document at one of these depths triggers the out-of-bounds read and exposes uninitialized heap contents to the caller. The fix bounds the loop by both the array's allocated size and its logical size.
You are affected if you are using a version that falls within the vulnerable range, and you decode corrupt or externally supplied BSON data that includes deeply nested field structures.
mongodb/mongodb-extension is vulnerable to Out-of-Bounds Read in versions 1.15.0 - 1.21.7, 2.0.0 - 2.1.8 and 2.2.0 - 2.5.0.
Upgrade the mongodb/mongodb-extension and/or the mongodb library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.