mongod terminates when certain types of invalid x.509 certificates are provided for client authentication, printing a brief error message in the log:
2014-04-26T19:05:18.243-0400 [conn2] ERROR: Uncaught std::exception: basic_string::substr, terminating
Anyone able to establish a connection with the server can crash it by using an invalid or malformed certificate and x.509 authentication. Only mongod servers compiled with SSL and with x.509 authentication enabled are affected by this issue.
Disable x.509 authentication or use a version of the server without SSL support.
MongoDB production releases 2.6.0 and 2.6.1 are affected by this issue.
The fix is included in the 2.6.2 production release.
Check for malformed and invalid certificates in the x.509 authentication circuitry.