PT-2013-3553 · Mongodb · Mongo-Python-Driver+1

·

CVE-2013-2132

·

Published

2013-07-06

·

Updated

2026-08-09

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions mongo-python-driver versions prior to 2.5.2
Description The issue allows context-dependent attackers to cause a denial of service, resulting in a NULL pointer dereference and crash. This is related to the decoding of an "invalid DBRef" in the bson/ cbsonmodule.c file.
Recommendations For versions prior to 2.5.2, update to version 2.5.2 or later to resolve the issue. As a temporary workaround, consider restricting the decoding of DBRef objects to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2132
DSA-2705-1
GHSA-X33V-F3GP-GW2C
MGASA-2013-0201
OPENSUSE-SU-2024:10226-1
OPENSUSE-SU-2024:11256-1
OPENSUSE-SU-2024:13931-1
OPENSUSE-SU-2026:11478-1
PYSEC-2013-30
RHSA-2013:1170

Affected Products

Mongodb
Mongo-Python-Driver