PT-2023-4102 · Unknown+1 · Monetdb Server+1

Fuboat

·

Published

2015-01-23

·

Updated

2024-12-02

·

CVE-2023-36368

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MonetDB Server versions 11.45.17 through 11.46.0
Description The issue in the cs bind ubat component allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. It is related to incorrect clearance or release of resources, which can be exploited by a remote attacker to cause a service disruption.
Recommendations For MonetDB Server versions 11.45.17 and 11.46.0, consider restricting access to the cs bind ubat component until a patch is available. As a temporary workaround, avoid using crafted SQL statements that may trigger the Denial of Service (DoS) condition in the affected versions.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Improper Resource Release

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1074
BDU:2023-04410
CVE-2023-36368

Affected Products

Alt Linux
Monetdb Server