Vulnerability in MongoDb version 3.4 up to 3.4.9

Bug #1750824 reported by Nils Weiher
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
mongodb (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Hello,

please see the following vulnerablitiy:

https://www.cvedetails.com/cve/CVE-2017-15535/

And the corresponding ticket confirming the vulnerability and the fix:
https://jira.mongodb.org/browse/SERVER-31273

The upcoming Ubuntu 18.04 release will include only MongoDb Version 3.4.7

Is it possible to upgrade the package for bionic to the current latest version 3.6.3.

This version also includes the bind to localhost by default, as is the case for the packages in the official Ubuntu repositories.

https://docs.mongodb.com/manual/release-notes/3.6-compatibility/

Please consider this upgrade, as it contains many more bugfixes.

CVE References

description: updated
Revision history for this message
Robie Basak (racb) wrote :

> Is it possible to upgrade the package for bionic to the current latest version 3.6.3.

In theory yes, but this requires volunteers and we currently have none and we're well after feature freeze now.

Unfortunately in my testing 3.4.14 fails to build with the current packaging so bumping to 3.4.14 isn't quite so straightforward either, and also needs volunteers to provide a patch. Alternatively I'd be happy to upload a patch that fixes just this particular problem, but again we need someone to prepare and test that.

information type: Public → Public Security
Robie Basak (racb)
Changed in mongodb (Ubuntu):
status: New → Triaged
Revision history for this message
Nils Weiher (nils.weiher) wrote :

Hello Robie Basak,

I tried to squeeze this in before the feature freeze, but it was only only several days.

> In theory yes, but this requires volunteers and we currently have none and we're well after feature freeze now.

Is there any chance that the mongodb package for bionic will be updated to a 3.6 version after release?

I would like to volunteer to do this, because in my work setting we try to rely on the Packages from official Ubuntu repositories.

The problem is I dont have the necessary experience with packaging for Ubuntu, but if you can point me to some ressources on how I would approach this this would be very nice. Maybe in the future I would be able to help.

Greetings from Heidelberg, Germany.

Nils Weiher

Revision history for this message
Gianfranco Costamagna (costamagnagianfranco) wrote :

I uploaded 3.4.14 in bionic, and 3.6 will follow in the next few days (before the release).

Changed in mongodb (Ubuntu):
status: Triaged → Fix Released
Revision history for this message
Gianfranco Costamagna (costamagnagianfranco) wrote :

(I honestly don't care about fixing this CVE for artful, that will go EOL in 3 months).

Revision history for this message
Gianfranco Costamagna (costamagnagianfranco) wrote :

of course, if somebody points out a patch, I'll be happy to do some paperwork and ask security team to upload it (if the patch is just few lines and is not "update to the latest version in artful too) :)

Revision history for this message
Nils Weiher (nils.weiher) wrote :

Thanks a lot costamagnagianfranco!

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.