CVE-2025-0755
MongoDB C Driver bson library may be susceptible to buffer overflow
7.5
HIGH
CVSS 3.1
EPSS 0.73%
描述
The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final BSON document which exceeds the maximum allowable size (INT32_MAX), resulting in a segmentation fault and possible application crash. This issue affected libbson versions prior to 1.27.5, MongoDB Server v8.0 versions prior to 8.0.1 and MongoDB Server v7.0 versions prior to 7.0.16
如何修補 CVE-2025-0755
要修補 CVE-2025-0755,請將受影響套件升級到下列已修補版本。
- —升級至 7.0.16 或更新版本
- —升級至 0.8.4-1+deb11u1 或更新版本
- —升級至 1.17.6-1+deb11u1 或更新版本
CVE-2025-0755 正在被利用嗎?
低 — EPSS 為 0.7%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- >= 7.0.0, < 7.0.16, >= 8.0.0, < 8.0.1
- from 0, < 0.8.4-1+deb11u1
- from 0, < 1.17.6-1+deb11u1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |