MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol compression), which exposes a vulnerability when enabled that could be exploited by a malicious attacker to deny service or modify memory.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "mongodb",
"binary_version": "1:3.6.3-0ubuntu1"
},
{
"binary_name": "mongodb-clients",
"binary_version": "1:3.6.3-0ubuntu1"
},
{
"binary_name": "mongodb-clients-dbgsym",
"binary_version": "1:3.6.3-0ubuntu1"
},
{
"binary_name": "mongodb-server",
"binary_version": "1:3.6.3-0ubuntu1"
},
{
"binary_name": "mongodb-server-core",
"binary_version": "1:3.6.3-0ubuntu1"
},
{
"binary_name": "mongodb-server-core-dbgsym",
"binary_version": "1:3.6.3-0ubuntu1"
}
]
}