The bson_strfreev function in the MongoDB C driver...
Moderate severity
Unreviewed
Published
Jul 2, 2024
to the GitHub Advisory Database
•
Updated Jul 2, 2024
Description
Published by the National Vulnerability Database
Jul 2, 2024
Published to the GitHub Advisory Database
Jul 2, 2024
Last updated
Jul 2, 2024
The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson versions prior to 1.26.2
References