UbuntuUpdates.org

Package "mongodb"

Name: mongodb

Description:

object/document-oriented database (metapackage)

Latest version: 1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3
Release: focal (20.04)
Level: security
Repository: universe
Homepage: https://www.mongodb.org

Links


Download "mongodb"


Other versions of "mongodb" in Focal

Repository Area Version
base universe 1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5
updates universe 1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3 2021-10-04 18:06:21 UTC

  mongodb (1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3) focal-security; urgency=medium

  * SECURITY UPDATE: message decompressor to incorrectly allocate memory (LP: #1933520)
    - d/p/CVE-2019-20925-SERVER-43751-Recompute-compressor-manager-message-pa.patch:
      An unauthenticated client can trigger denial of service by
      issuing specially crafted wire protocol messages,
      which cause the message decompressor to incorrectly allocate memory
    - CVE-2019-20925

 -- Heather Lemon <email address hidden> Thu, 26 Aug 2021 14:36:35 +0000

Source diff to previous version
1933520 message decompressor to incorrectly allocate memory
CVE-2019-20925 An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to

Version: 1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.2 2021-08-26 03:06:20 UTC

  mongodb (1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.2) focal-security; urgency=medium

  [Heather Lemon]
  * SECURITY UPDATE: account session reuse leads to unauthorized access (LP: #1934518)
    - d/p/CVE-2019-2386-SERVER-38984-Validate-unique-User-ID-on-UserCache-hi.patch:
      Attach ID to users.
      After user deletion in MongoDB Server the improper invalidation of
      authorization sessions allows an authenticated user's session to
      persist and become conflated with new accounts
    - CVE-2019-2386

  [Alex Murray]
  * Refresh
    d/p/CVE-2019-2386-SERVER-38984-Validate-unique-User-ID-on-UserCache-hi.patch
    with the version from the 3.4 upstream branch that is still licensed
    under the AGPL.

 -- Alex Murray <email address hidden> Mon, 23 Aug 2021 17:01:06 +0930

1934518 improper invalidation of authorization sessions



About   -   Send Feedback to @ubuntu_updates