CVE-2020-12135
Summary
| CVE | CVE-2020-12135 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-24 01:15:00 UTC |
| Updated | 2020-08-12 17:15:00 UTC |
| Description | bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() parameter bytesNeeded could have an integer overflow via properly constructed bson input. |
Risk And Classification
Problem Types: CWE-190
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| USN-4450-1: Whoopsie vulnerabilities | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | |
| launchpadlibrarian.net/474887364/bson-fix-overflow.patch | MISC | launchpadlibrarian.net | Patch, Third Party Advisory |
| don't mix up int and size_t (first pass to fix that) · 10gen-archive/mongo-c-driver-legacy@1a1f5e2 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Bug #1872560 “integer overflow in whoopsie 0.2.69” : Bugs : whoopsie package : Ubuntu | MISC | bugs.launchpad.net | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.