Bugzilla – Bug 1226013
VUL-0: CVE-2024-5629: python-pymongo: out-of-bounds read in the BSON module
Last modified: 2024-06-05 17:38:47 UTC
An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-5629 https://www.cve.org/CVERecord?id=CVE-2024-5629 https://jira.mongodb.org/browse/PYTHON-4305
No codestreams are affected by this vulnerability, as it was already fixed due to bug #1222492. CVE-2024-21506 was REJECTED and marked as a duplicate of the CVE from this bug. I will, therefore, be closing this as RESOLVED/FIXED.
*** Bug 1222492 has been marked as a duplicate of this bug. ***