The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory. This issue affects libbson versions prior to 1.27.1
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4160-1 | libbson-xs-perl security update |
Debian DLA |
DLA-4175-1 | mongo-c-driver security update |
EUVD |
EUVD-2024-47490 | The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory. This issue affects libbson versions prior to 1.27.1 |
Ubuntu USN |
USN-7613-1 | mongo-c-driver vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 04 Oct 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2025-11-03T19:34:31.467Z
Reserved: 2024-06-27T08:43:40.268Z
Link: CVE-2024-6383
Updated: 2024-10-04T15:02:53.248Z
Status : Awaiting Analysis
Published: 2024-07-03T22:15:03.240
Modified: 2025-11-03T20:17:03.463
Link: CVE-2024-6383
No data.
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN