Vulnerability Description
In MongoDB libbson 1.7.0, the bson_iter_codewscope function in bson-iter.c miscalculates a bson_utf8_validate length argument, which allows remote attackers to cause a denial of service (heap-based buffer over-read in the bson_utf8_validate function in bson-utf8.c), as demonstrated by bson-to-json.c.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | Mongodb | 1.7.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/100825Third Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1489355Issue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1489356Issue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1489362Issue TrackingThird Party Advisory
- http://www.securityfocus.com/bid/100825Third Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1489355Issue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1489356Issue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1489362Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/05/msg00012.html
FAQ
What is CVE-2017-14227?
CVE-2017-14227 is a vulnerability with a CVSS score of 7.5 (HIGH). In MongoDB libbson 1.7.0, the bson_iter_codewscope function in bson-iter.c miscalculates a bson_utf8_validate length argument, which allows remote attackers to cause a denial of service (heap-based bu...
How severe is CVE-2017-14227?
CVE-2017-14227 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14227?
Check the references section above for vendor advisories and patch information. Affected products include: Mongodb Mongodb.