Candidate: CVE-2016-3104 PublicDate: 2017-04-14 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3104 https://jira.mongodb.org/browse/SERVER-24378 Description: mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database. Ubuntu-Description: Notes: ratliff> The mongodb advisory recommend upgrading to latest 2.6. No 2.4 patch Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_mongodb: upstream_mongodb: needs-triage precise_mongodb: ignored (reached end-of-life) precise/esm_mongodb: DNE (precise was needs-triage) trusty_mongodb: ignored (out of standard support) trusty/esm_mongodb: needed vivid/stable-phone-overlay_mongodb: DNE vivid/ubuntu-core_mongodb: DNE xenial_mongodb: ignored (end of standard support, was needed) yakkety_mongodb: ignored (reached end-of-life) zesty_mongodb: ignored (reached end-of-life) artful_mongodb: ignored (reached end-of-life) bionic_mongodb: not-affected (1:3.6.3-0ubuntu1) cosmic_mongodb: not-affected (1:3.6.3-0ubuntu1) disco_mongodb: not-affected (1:3.6.3-0ubuntu1) eoan_mongodb: not-affected (1:3.6.3-0ubuntu1) focal_mongodb: not-affected (1:3.6.3-0ubuntu1) groovy_mongodb: DNE hirsute_mongodb: DNE impish_mongodb: DNE jammy_mongodb: DNE devel_mongodb: DNE