PT-2023-8879 · Unknown+4 · Virtuoso-Opensource+4
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
virtuoso-opensource version 7.2.11
Description
The issue is related to the box equal function in virtuoso-opensource, which can be exploited by attackers to cause a Denial of Service (DoS) after running a SELECT statement. The vulnerability is associated with the incorrect implementation of the sequence of actions performed. Exploitation of the vulnerability may allow a remote attacker to cause a denial of service.
Recommendations
For virtuoso-opensource version 7.2.11, consider disabling the box equal function as a temporary workaround until a patch is available. Restrict access to the SELECT statement to minimize the risk of exploitation.
Exploit
Correção
DoS
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Debian
Linuxmint
Red Os
Ubuntu
Virtuoso-Opensource