Bug#717173: mongodb: databaseSpraying remote code execution

2013-07-18 Thread Salvatore Bonaccorso
Control: retitle -1 mongodb: CVE-2013-4142: databaseSpraying remote code execution Hi On Wed, Jul 17, 2013 at 04:37:30PM +0300, Henri Salo wrote: Package: mongodb Version: 1:2.4.3-1 Severity: important Tags: security Information:

Bug#717173: mongodb: databaseSpraying remote code execution

2013-07-18 Thread Antonin Kral
Hi Salvatore, thank you for report. I've actually prepared new package, but currently fighting with compilation as the V8 in debian is too old and using the package is currently failing :((( Antonin * Salvatore Bonaccorso car...@debian.org [2013-07-18 08:59] wrote: Control: retitle -1

Bug#717173: mongodb: databaseSpraying remote code execution

2013-07-17 Thread Henri Salo
Package: mongodb Version: 1:2.4.3-1 Severity: important Tags: security Information: http://blog.scrt.ch/2013/06/04/mongodb-rce-by-databasespraying/ CVE request: http://openwall.com/lists/oss-security/2013/07/17/2 Please verify if Debian packages are affected and patch if needed. Please contact