Description
In MongoDB libbson 1.7.0, the bson_iter_codewscope function in bson-iter.c miscalculates a bson_utf8_validate length argument, which allows remote attackers to cause a denial of service (heap-based buffer over-read in the bson_utf8_validate function in bson-utf8.c), as demonstrated by bson-to-json.c.
Remediation
References
Related Vulnerabilities
WordPress Plugin Download Manager PHAR Deserialization (3.2.49)
WordPress Plugin MailChimp Forms by MailMunch Unspecified Vulnerability (2.0.6.3)
WordPress Plugin Custom Content Type Manager Backdoor (0.9.8.8)
WordPress Plugin User Role by BestWebSoft Cross-Site Scripting (1.4.1)
Oracle Database Server CVE-2024-21251 Vulnerability (CVE-2024-21251)