-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 18 Apr 2025 16:28:00 -0400 Source: mongo-c-driver Binary: libbson-1.0-0 libbson-1.0-0-dbgsym libbson-dev libmongoc-1.0-0 libmongoc-1.0-0-dbgsym libmongoc-dev Architecture: ppc64el Version: 1.23.1-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-conova-01) Changed-By: Roberto C. Sanchez Description: libbson-1.0-0 - Library to parse and generate BSON documents - runtime files libbson-dev - Library to parse and generate BSON documents - dev files libmongoc-1.0-0 - MongoDB C client library - runtime files libmongoc-dev - MongoDB C client library - dev files Changes: mongo-c-driver (1.23.1-1+deb12u1) bookworm; urgency=medium . * Fix CVE-2023-0437: When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. * Fix CVE-2024-6381: The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. * Fix CVE-2024-6383: The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory. * Fix CVE-2025-0755: The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final BSON document which exceeds the maximum allowable size (INT32_MAX), resulting in a segmentation fault and possible application crash. Checksums-Sha1: ed1e5f65c1cc6673a924538d73d22afdc9ab6535 222608 libbson-1.0-0-dbgsym_1.23.1-1+deb12u1_ppc64el.deb ddb6f9682525fe39c89dfe6503ad00d263c4fac8 79808 libbson-1.0-0_1.23.1-1+deb12u1_ppc64el.deb 9edbebbf79bb4314e19fbbeb32e9423b9757cb8a 136560 libbson-dev_1.23.1-1+deb12u1_ppc64el.deb db80b4406be08f8218999c294da16da4e8490807 1225768 libmongoc-1.0-0-dbgsym_1.23.1-1+deb12u1_ppc64el.deb 50f2b1ed1f0bc21af27cb73f7924be661ab727a9 326856 libmongoc-1.0-0_1.23.1-1+deb12u1_ppc64el.deb edc07789a71b580e3e26fbfba38e2c40c4a767d7 413840 libmongoc-dev_1.23.1-1+deb12u1_ppc64el.deb 2e1f3b3e917657284c14e8ffd32a9fddd590c535 10171 mongo-c-driver_1.23.1-1+deb12u1_ppc64el-buildd.buildinfo Checksums-Sha256: ade409873dc6d91b8e92e6864858b4ddfab150b5f1efa23710cffa73a3fd8e84 222608 libbson-1.0-0-dbgsym_1.23.1-1+deb12u1_ppc64el.deb f4702adb728a9bb3fdfc66fe422fa64c7bfe573eb21752652fe8afe6ee9a79eb 79808 libbson-1.0-0_1.23.1-1+deb12u1_ppc64el.deb 78f23b5d17b05ab491e8f39e2cb033365e527737a9367df10276be0d81f27d28 136560 libbson-dev_1.23.1-1+deb12u1_ppc64el.deb 0f958e11d5b0b74ceed56ee5998d8f8efdc8b5e8f542d9db3abd09f16dbb4bb5 1225768 libmongoc-1.0-0-dbgsym_1.23.1-1+deb12u1_ppc64el.deb 111994be767640df860c04210a7586b0028a71a5732e139d27899f6242cd4ddd 326856 libmongoc-1.0-0_1.23.1-1+deb12u1_ppc64el.deb 2f91b1b7fa7966ba861f0124203af1fcc3cee9b465cca103bef99be3c25f7592 413840 libmongoc-dev_1.23.1-1+deb12u1_ppc64el.deb c56eb9a1e08608a0ec12347316db45cb32113885af2ece3aa786adf476869402 10171 mongo-c-driver_1.23.1-1+deb12u1_ppc64el-buildd.buildinfo Files: b1cbaed1fd1e644195b1edb3b2a14e49 222608 debug optional libbson-1.0-0-dbgsym_1.23.1-1+deb12u1_ppc64el.deb 4d615cdc426068c28e604cf574bbb22a 79808 libs optional libbson-1.0-0_1.23.1-1+deb12u1_ppc64el.deb 503acf1b4910334209e09d01ed370ee4 136560 libdevel optional libbson-dev_1.23.1-1+deb12u1_ppc64el.deb b690503da5f0eb1607ed585559329620 1225768 debug optional libmongoc-1.0-0-dbgsym_1.23.1-1+deb12u1_ppc64el.deb e4eac889b2e4197470ea020ad3a0a726 326856 libs optional libmongoc-1.0-0_1.23.1-1+deb12u1_ppc64el.deb 5d6ca767ab94276c8bfba9302d69139a 413840 libdevel optional libmongoc-dev_1.23.1-1+deb12u1_ppc64el.deb 223df5ad1e1a9828c864cdec17a8eb63 10171 libs optional mongo-c-driver_1.23.1-1+deb12u1_ppc64el-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEvNkWZvjZkiWgJGRETMSrGPLkYxUFAmgNLdQACgkQTMSrGPLk YxUHFBAAnpy4Fr1IqkkbKyn5L7R38MSUm3ML92NqLUv44hZkD41iMWazFRleZMMP qDyA9VZpdxcvZfStZ/lVlNxXthp1AWvjeswFsFKG7aXiEm8y3dk3vO7PT1Ocgwua He7J7x11Q9Vs3XYHrrmnsQHtnRpdg7Txkfl4nRs9WnOi5g4paTNxM/hc69hOgB9P QCaU09CvkEhu4SJ3Xb52WRQJFSBqcDgZQ+Nq2IHjBN4+ucGmSNFYz2GBQiP0s1pd bO6x6qvtI8ykniVud3o8N2WvLBec7TmdF0/ATFTtsisLRxsnsX/OHBjkJS2wYVz0 EZcnvRMnlxZwt0R2PBZGoxaLmtdGm+xy96qxcGZUeNxqg6GSMlbn0pNI0Ht5bVM0 HaiS0prm+uh+EHkopi/fG37WDIq0AG52BptN5uGqkAGtvlG5AJSklT3SXRLcvGRf c03H0WDlY61Jhov+UGRuxnFjV5BYRpa58Y310iNWpNW65LZBaaPRzaKztIXDfgmh KrRhYOtGZqz4UtknOsRTHA8noK2vxUdF/3gp6HP52c7ppz7P7i+wGOh5nfVKDJ+8 SKoLdnTBF0J7QRmZ5beVGs+2/GRyykBsEcL/iy5ipaj++GcWHpVdfDFzO3vMvOi0 AS3PWtJa/L1ED7WYElsT+hCDC5U8KGMpw07bPsttww4oCiQttoQ= =nIYy -----END PGP SIGNATURE-----