yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2024-5629
Component Overview
Vulnerability Overview
Name
CVE-2024-5629
Source
NVD (
link
)
Debian (
link
)
Description
An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.
CWEs
CWE-125
CWE-125
Published Date
Jun 5, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://jira.mongodb.org/browse/PYTHON-4305
Issue Tracking
https://lists.debian.org/debian-lts-announce/2024/06/msg00007.html
Third Party Advisory
https://jira.mongodb.org/browse/PYTHON-4305
Issue Tracking
https://lists.debian.org/debian-lts-announce/2024/06/msg00007.html
Third Party Advisory
Analysis
#
Affected Component
Analysis
python3-pymongo
Patched
Vulnerability Ratings
#
4.7
CVSSv31
8.1
CVSSv31
NaN
other
Others affected component
#
Name
Project
Project Version
Version
Status
python3-pymongo
yocto
scarthgap
4.6.3
Not Affected
Resolved with patches
#
python3-pymongo (yocto:kirkstone)
#
Title
Author
Resolve
1
PYTHON-4305 Fix bson size check (#1564)
Shane Harvey <shnhrv@gmail.com>
CVE-2024-5629