Description
The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory. This issue affects libbson versions prior to 1.27.1
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4160-1 | libbson-xs-perl security update |
Debian DLA |
DLA-4175-1 | mongo-c-driver security update |
EUVD |
EUVD-2024-47490 | The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory. This issue affects libbson versions prior to 1.27.1 |
Ubuntu USN |
USN-7613-1 | mongo-c-driver vulnerabilities |
References
History
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 04 Oct 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2025-11-03T19:34:31.467Z
Reserved: 2024-06-27T08:43:40.268Z
Link: CVE-2024-6383
Updated: 2024-10-04T15:02:53.248Z
Status : Deferred
Published: 2024-07-03T22:15:03.240
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-6383
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN