-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 18 Apr 2025 16:28:00 -0400 Source: mongo-c-driver Binary: libbson-1.0-0 libbson-1.0-0-dbgsym libbson-dev libmongoc-1.0-0 libmongoc-1.0-0-dbgsym libmongoc-dev Architecture: mips64el Version: 1.23.1-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Roberto C. Sanchez Description: libbson-1.0-0 - Library to parse and generate BSON documents - runtime files libbson-dev - Library to parse and generate BSON documents - dev files libmongoc-1.0-0 - MongoDB C client library - runtime files libmongoc-dev - MongoDB C client library - dev files Changes: mongo-c-driver (1.23.1-1+deb12u1) bookworm; urgency=medium . * Fix CVE-2023-0437: When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. * Fix CVE-2024-6381: The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. * Fix CVE-2024-6383: The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory. * Fix CVE-2025-0755: The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final BSON document which exceeds the maximum allowable size (INT32_MAX), resulting in a segmentation fault and possible application crash. Checksums-Sha1: 79ec6cd6bc914fb5486ca4d3f8052d1281ffa1e0 223160 libbson-1.0-0-dbgsym_1.23.1-1+deb12u1_mips64el.deb e92463c21101d5ce65db47227286bf482f221d98 65244 libbson-1.0-0_1.23.1-1+deb12u1_mips64el.deb a9d3b414b22f7656cd13b5397262ad10247861c8 133472 libbson-dev_1.23.1-1+deb12u1_mips64el.deb 908df454e94d73538a892dcb64a9f50467f35dd2 1232176 libmongoc-1.0-0-dbgsym_1.23.1-1+deb12u1_mips64el.deb 1beb3d0938e7af22e65c046667a664eedb64b6f0 250600 libmongoc-1.0-0_1.23.1-1+deb12u1_mips64el.deb bca146c114c9fd648193833f352ef92870729504 399544 libmongoc-dev_1.23.1-1+deb12u1_mips64el.deb fc5c97339076f3f4fe943565bbdb6cca58a9aad3 10004 mongo-c-driver_1.23.1-1+deb12u1_mips64el-buildd.buildinfo Checksums-Sha256: f532f5f964e23501e6be0c6f992b2673266c34c882cccbd011f4d147d88f7dbb 223160 libbson-1.0-0-dbgsym_1.23.1-1+deb12u1_mips64el.deb e0b710d1c81d508e14d0a4b428bde16c79be40f95cfccd80983cfd5891795cf8 65244 libbson-1.0-0_1.23.1-1+deb12u1_mips64el.deb 8bf3b1b202ea1ec87a6b294c4bc3697a90733b4d1afa43302fcbd39d7da5ea68 133472 libbson-dev_1.23.1-1+deb12u1_mips64el.deb 0e3b2048bf06f3e6638df91d7270d07716cfd87b933b98d3770fad5568ec4d34 1232176 libmongoc-1.0-0-dbgsym_1.23.1-1+deb12u1_mips64el.deb f56cfbc81f6f29c044582e6e97146565a8e2997b8a6c74312f26f1ffe2530343 250600 libmongoc-1.0-0_1.23.1-1+deb12u1_mips64el.deb b4ec079c0b3e9e6e042b7cc8e2b562791aab42b3e3e60188dfcf22233e17b93f 399544 libmongoc-dev_1.23.1-1+deb12u1_mips64el.deb 186358fecec478a72ea43a6bad63bc6fa8cd5c55f592928735f6f75472ac8b27 10004 mongo-c-driver_1.23.1-1+deb12u1_mips64el-buildd.buildinfo Files: 2e7de21e59666b3a2594b7fd2919d3e7 223160 debug optional libbson-1.0-0-dbgsym_1.23.1-1+deb12u1_mips64el.deb 549b2262b651582bf6c92727aca34914 65244 libs optional libbson-1.0-0_1.23.1-1+deb12u1_mips64el.deb c1dffe4e3364be5cf8dec01b4c321499 133472 libdevel optional libbson-dev_1.23.1-1+deb12u1_mips64el.deb 8280b9eca549fab676b7537347e12973 1232176 debug optional libmongoc-1.0-0-dbgsym_1.23.1-1+deb12u1_mips64el.deb 7bcb3d4c211d65c0ba16d74e804793df 250600 libs optional libmongoc-1.0-0_1.23.1-1+deb12u1_mips64el.deb 8e2daa4d8a601615542ce31d967c82c8 399544 libdevel optional libmongoc-dev_1.23.1-1+deb12u1_mips64el.deb 02a9a49f01c5f82162dfa1a3a4f0510b 10004 libs optional mongo-c-driver_1.23.1-1+deb12u1_mips64el-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYLhEzFkGpb3yYRVHmlVdU6AM9BUFAmgNQ1cACgkQmlVdU6AM 9BVdGg/+LNunLew7p5ssnWcdii9N40zaFoeDjAYKQvpp5nHg9I8etp0K1aRAzlUs dLU7PTEQG6WRXXdXTMTIa8X/xNC0xw7PR7bldV+QKc5Sbe+yBSxUrbWDjWf4dl8c wUq/YxLoV+1RfQiD4jXsJl5g/Y9ff4CmqR7Q0JFZ16oPVgpP2uihbxeJkmVCYljh siOSbf2vjU3X3deBBAwRZO7PhbM04x44/e6Lp4P4p0J4vCTmP1ET0i2nU/QV5paI QiXdd2A2z0ZMxm98R+6758JqR5I2+UdO5pR1YVdSb+P9PRM6pUFCwq5swJbl47fZ CsWMiOZqeSLemc36Rqu+bWTslc9FgkpaXQNrP4TP1wrTQ0qDw6HnBln70HAFr1Dj Nmp3UjAsyX+fXF326vuYI2ECZqqlIs59q1n25s2uGg9z7dP7Jd6qafzYb+jQJ33W FGuUCTqS+CTZBcpPDSnzee58bbHKr+gbS1HKfmXDYsU6jr3CuQzxKMImPTjVpg6f PpvnbRYtffNszpMiUeqkujCblySLtc94T9dby+1Wws0VKIqfDszJeVOXqtkIUNAC 4Ue4dy5mhWeHWBQu5YtizO9UYlvGzI2lGeona0p9qi/Q03diH4f6IZK7WO48AlHA Mg68FPZ8s50zo86eV3CgZhHhwxOo6hdIHRYwRA6vMcFaY8ROm3A= =7/nF -----END PGP SIGNATURE-----