{"id":"GHSA-x33v-f3gp-gw2c","summary":"Use of NullPointerException Catch to Detect NULL Pointer Dereference in Pymongo","details":"bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an \"invalid DBRef.\"","aliases":["CVE-2013-2132","PYSEC-2013-30"],"modified":"2024-10-16T02:48:07.426983Z","published":"2022-05-14T02:10:10Z","database_specific":{"github_reviewed_at":"2022-07-08T19:07:51Z","nvd_published_at":"2013-08-15T17:55:00Z","cwe_ids":["CWE-395"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-2132"},{"type":"WEB","url":"https://github.com/mongodb/mongo-python-driver/commit/a060c15ef87e0f0e72974c7c0e57fe811bbd06a2"},{"type":"WEB","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=710597"},{"type":"PACKAGE","url":"https://github.com/mongodb/mongo-python-driver"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pymongo/PYSEC-2013-30.yaml"},{"type":"WEB","url":"https://jira.mongodb.org/browse/PYTHON-532"},{"type":"WEB","url":"https://lists.opensuse.org/opensuse-updates/2013-06/msg00180.html"},{"type":"WEB","url":"https://seclists.org/oss-sec/2013/q2/447"},{"type":"WEB","url":"https://ubuntu.com/usn/usn-1897-1"},{"type":"WEB","url":"https://www.debian.org/security/2013/dsa-2705"}],"affected":[{"package":{"name":"pymongo","ecosystem":"PyPI","purl":"pkg:pypi/pymongo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.2"}]}],"versions":["0.1.1pre","0.1.2pre","0.10","0.10.1","0.10.2","0.10.3","0.11","0.11.1","0.11.2","0.11.3","0.12","0.13","0.14","0.14.1","0.14.2","0.15","0.15.1","0.15.2","0.16","0.1pre","0.2pre","0.3.1pre","0.3pre","0.4pre","0.5.1pre","0.5.2pre","0.5.3pre","0.5pre","0.6","0.7","0.7.1","0.7.2","0.8","0.8.1","0.9","0.9.1","0.9.2","0.9.3","0.9.4","0.9.5","0.9.6","0.9.7","1.0","1.1","1.1.1","1.1.2","1.10","1.10.1","1.11","1.2","1.2.1","1.3","1.4","1.5","1.5.1","1.5.2","1.6","1.7","1.8","1.8.1","1.9","2.0","2.0.1","2.1","2.1.1","2.2","2.2.1","2.3","2.4","2.4.1","2.4.2","2.5","2.5.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x33v-f3gp-gw2c/GHSA-x33v-f3gp-gw2c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}