PT-2023-8877 · Openlink+4 · Openlink Virtuoso-Opensource+4

·

CVE-2023-48946

·

Publicado

2023-11-29

·

Atualizado

2024-07-04

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions openlink virtuoso-opensource version 7.2.11
Description The issue is related to the box mpy function in openlink virtuoso-opensource, which allows attackers to cause a Denial of Service (DoS) after running a SELECT statement. This is due to insufficient input validation, enabling a remote attacker to exploit the vulnerability and cause a service disruption.
Recommendations For openlink virtuoso-opensource version 7.2.11, consider disabling the box mpy function as a temporary workaround until a patch is available. Restrict access to the box mpy function to minimize the risk of exploitation. Avoid using the box mpy function in conjunction with SELECT statements until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-02539
CVE-2023-48946
USN-6879-1

Produtos afetados

Debian
Linuxmint
Red Os
Ubuntu
Openlink Virtuoso-Opensource