Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 477324 (CVE-2013-4142) - <dev-db/mongodb-2.4.5: remote code execution via javascript (CVE-2013-2132)
Summary: <dev-db/mongodb-2.4.5: remote code execution via javascript (CVE-2013-2132)
Status: RESOLVED DUPLICATE of bug 472034
Alias: CVE-2013-4142
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ~1 [cleanup]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-07-18 19:00 UTC by Agostino Sarubbo
Modified: 2013-07-18 21:44 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-07-18 19:00:44 UTC
From ${URL} :

Similar to CVE-2013-1892, it was reported [1] that MongoDB suffers from remote code execution   
This flaw requires read-write access to the MongoDB database to execute arbitrary code; however it 
looks as though read-only access could be used to cause the database to crash.

It is unknown whether this flaw was introduced in 2.2.3 with the change to using the V8 Javascript 
engine, or if it also affects earlier versions.


[1] http://blog.scrt.ch/2013/06/04/mongodb-rce-by-databasespraying/


@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not.
Comment 1 Chris Reffett (RETIRED) gentoo-dev Security 2013-07-18 21:44:29 UTC
Upstream says CVE-2013-4142 is a dupe of CVE-2013-2132.

*** This bug has been marked as a duplicate of bug 472034 ***