-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 18 Apr 2025 16:28:00 -0400 Source: mongo-c-driver Binary: libbson-1.0-0 libbson-1.0-0-dbgsym libbson-dev libmongoc-1.0-0 libmongoc-1.0-0-dbgsym libmongoc-dev Architecture: mipsel Version: 1.23.1-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-04) Changed-By: Roberto C. Sanchez Description: libbson-1.0-0 - Library to parse and generate BSON documents - runtime files libbson-dev - Library to parse and generate BSON documents - dev files libmongoc-1.0-0 - MongoDB C client library - runtime files libmongoc-dev - MongoDB C client library - dev files Changes: mongo-c-driver (1.23.1-1+deb12u1) bookworm; urgency=medium . * Fix CVE-2023-0437: When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. * Fix CVE-2024-6381: The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. * Fix CVE-2024-6383: The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory. * Fix CVE-2025-0755: The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final BSON document which exceeds the maximum allowable size (INT32_MAX), resulting in a segmentation fault and possible application crash. Checksums-Sha1: 7bffcf82074d00170eb3492fc34c26a43894e375 225424 libbson-1.0-0-dbgsym_1.23.1-1+deb12u1_mipsel.deb 9a5c73b402cd461ef595e0b19e666399b8858b0d 71748 libbson-1.0-0_1.23.1-1+deb12u1_mipsel.deb b349a14618ba1b8037c0f021b59452084a57590e 136936 libbson-dev_1.23.1-1+deb12u1_mipsel.deb 17ee69fe41a6ca3d14a9f18a946a5015bec56a0a 1220616 libmongoc-1.0-0-dbgsym_1.23.1-1+deb12u1_mipsel.deb d60dc55152ab5b36a7b0c8f361fb09b4eaa15a0a 261860 libmongoc-1.0-0_1.23.1-1+deb12u1_mipsel.deb a589ea4d5e2ea63f9850a7e009a585f1ff3e8ec5 406460 libmongoc-dev_1.23.1-1+deb12u1_mipsel.deb f8b75c177212badcff33ed386c456789fd2ebd2e 9957 mongo-c-driver_1.23.1-1+deb12u1_mipsel-buildd.buildinfo Checksums-Sha256: 4a97c1bd90ba770216dfb3d8d7c371406524d61f97bc91e606646c549f4468d2 225424 libbson-1.0-0-dbgsym_1.23.1-1+deb12u1_mipsel.deb b5c4a5fd1a7c09ba77c675ac646da1cc3731afaf7c6a5e67b5c3c65ca9620686 71748 libbson-1.0-0_1.23.1-1+deb12u1_mipsel.deb 441adc82d744b515fa23954d7ef746ec2e5e64bb3e686aa27f0fdee73d25df4a 136936 libbson-dev_1.23.1-1+deb12u1_mipsel.deb ddf1fc56f58e91a1a62d72b016ce8f0185fe5dbb3f29e9b596ad06f29d982d09 1220616 libmongoc-1.0-0-dbgsym_1.23.1-1+deb12u1_mipsel.deb 01ce9024e78cbbcd524ba66d9728820ff0951b0c0e3ab175de2292d57d01c146 261860 libmongoc-1.0-0_1.23.1-1+deb12u1_mipsel.deb a87834e2a01c7599b361093b1553478dc84153cfe6216a719e62385e6795a44c 406460 libmongoc-dev_1.23.1-1+deb12u1_mipsel.deb 9fb3e71ed7f017465e1ffbbbcaef085544d6550678c84b07a774fe879f063b20 9957 mongo-c-driver_1.23.1-1+deb12u1_mipsel-buildd.buildinfo Files: 0b0d3140289a17bcfcabc91f68e3bc5c 225424 debug optional libbson-1.0-0-dbgsym_1.23.1-1+deb12u1_mipsel.deb 3460e98efae585136f4eedfc86e47737 71748 libs optional libbson-1.0-0_1.23.1-1+deb12u1_mipsel.deb b13e34333e764161580112b2aef13e70 136936 libdevel optional libbson-dev_1.23.1-1+deb12u1_mipsel.deb d2c2fe38c81052a6a103dda62aeb0ec2 1220616 debug optional libmongoc-1.0-0-dbgsym_1.23.1-1+deb12u1_mipsel.deb 2b0752ac695c134d39071ba1f2fbd9e1 261860 libs optional libmongoc-1.0-0_1.23.1-1+deb12u1_mipsel.deb 59b8c5e4fda09625a93def39d67ebfaa 406460 libdevel optional libmongoc-dev_1.23.1-1+deb12u1_mipsel.deb 70b8bc54da7c99e0a0c121e536bb55c8 9957 libs optional mongo-c-driver_1.23.1-1+deb12u1_mipsel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERbXMbY9VMQqnSaVEV4aVsMglzVcFAmgNLxIACgkQV4aVsMgl zVc9+A/8CU8bpWLaO49LoFYIN08opR3+Km3LuY4DVhAG5abHsmcDgS3yPGbYv/Vg Vm7Bdu893/y+6KWAGvUiHKIS08N0A9rJ0Y1XDv3KnpL6MlYgGeZqo5yuI5J91AeY 0sXEwhFDNP5DHEwIYuliJPcMr/QoCjtR+A0qetNwaOGH53MsrgDWcec50iW3Qm2t bYpOMlM8QOzdOcZCs33AYvCGv6Tyl4eIAVT5Tf3HvtLqkFnQxBqltXagWLYMgCU1 MYJVTS5wBcPY3lWIqmSRM3M50bphkx7oelKZPS2jwP9EWV2D1tbIONJRjnPb4bHQ 3viwfIA4m7pTGVbtEOdpiywdEum3C6kMteyOJG4tXspSU7D9lbGC3a4wk76V3X78 y2t2GIFf9ND0ZO2YouZbH9qX42vidoLB1vaFEeTkZLsPuCNVS8hQPxp//MxXqrn5 DkxwgcDDWgZ0V4xPCqeYe3sYaheZ3vF0Xt9iPAyaLIuOdENz8O0lp3tTCyNF2jnr pAY5EDUtDEkwEKEWYQTC1YuTEomRxzN3hNxYv+uISI9VyOKnLKzNvV4t0RS7jCHW 3luExIclK0jWTkCdOAWwCrjvjv+5UFcnjGUXwyhUiv44fTLYDoDnUz2XnSJeYbKj OeZutDlIOXTpwsLJlcLzCAmoWj7yDagIdTwORDPshlRDnOn1Lj8= =WLoc -----END PGP SIGNATURE-----