Red Hat Bugzilla – Bug 1516183
CVE-2017-15535 mongodb: Invalid wire protocol compression
Last modified: 2018-02-12 04:21:50 EST
MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol compression), which exposes a vulnerability when enabled that could be exploited by a malicious attacker to deny service or modify memory. Upstream issue: https://jira.mongodb.org/browse/SERVER-31273 Upstream patch [3.4.x]: https://github.com/mongodb/mongo/commit/5ad69b851801edadbfde8fdf271f4ba7c21170b5
Created mongodb tracking bugs for this issue: Affects: fedora-all [bug 1516185]