Bug 1208428

Summary: CVE-2015-2327 CVE-2015-2328 mongodb: multiple flaws in bundled version of PCRE
Product: [Other] Security Response Reporter: Martin Prpič <mprpic>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: abaron, admiller, aortega, apevec, ayoung, bkearney, bleanhar, bretm, cbillett, ccoleman, chrisw, cpelland, cperry, dallan, dmcphers, fpercoco, gkotton, jdetiber, jdornak, jialiu, jkeck, johan.o.hedin, jokerman, jorton, jpacner, katello-bugs, kseifried, lhh, lmeyer, lpeer, markmc, mmaslano, mmccomas, mmccune, mskalick, nathaniel, ohadlevy, rbryant, sclewis, strobert, tdawson, tjay, tomckay, yeylon
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: mongodb 2.6.9, mongodb 3.0.1 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-04-02 08:57:21 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Martin Prpič 2015-04-02 08:56:22 UTC
MongoDB bundles PCRE version 8.30 that, among other issues, is vulnerable to CVE-2014-8964. A remote, authenticated  attacker could use a specially crafted regular expression to crash a mongod server.

Upstream issue (with links to patches):

https://jira.mongodb.org/browse/SERVER-17252

Statement:

This issue did not affect the versions of MongoDB as shipped in any Red Hat product as they use the PCRE system library, not the bundled copy shipped with MongoDB. The CVE-2014-8964 PCRE flaw does not affect Red Hat Enterprise Linux 5 and 6, and has been fixed in Red Hat Enterprise Linux 7 via RHSA-2015:0330.

Comment 1 Adam Mariš 2015-12-01 10:05:43 UTC
Vulnerabilities were in PCRE. Moving CVEs to the corresponding PCRE bugs.