Bug ID 1065956
Summary VUL-0: CVE-2017-15535: mongodb: a disabled-by-defaultconfiguration setting, networkMessageCompressors (aka wire protocolcompression) if enabled could lead to denial of service
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.3
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Network
Assignee cloud-bugs@suse.de
Reporter vpereira@microfocus.com
QA Contact qa-bugs@suse.de
Found By Security Response Team
Blocker ---

CVE-2017-15535

MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default
configuration setting, networkMessageCompressors (aka wire protocol
compression), which exposes a vulnerability when enabled that could be
exploited
by a malicious attacker to deny service or modify memory.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-15535
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15535
https://jira.mongodb.org/browse/SERVER-31273


You are receiving this mail because: