CVE-2016-3104

mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-24378 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1324496 Issue Tracking Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/94929 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:2.6.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:2.4.0:*:*:*:*:*:*:*

Information

Published : 2017-04-14 11:59

Updated : 2017-04-22 07:15


NVD link : CVE-2016-3104

Mitre link : CVE-2016-3104


JSON object : View

CWE
CWE-400

Uncontrolled Resource Consumption

Advertisement

dedicated server usa

Products Affected

mongodb

  • mongodb