PT-2023-8877 · Openlink+4 · Openlink Virtuoso-Opensource+4
Fuboat
·
Published
2023-11-29
·
Updated
2024-07-04
·
CVE-2023-48946
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
openlink virtuoso-opensource version 7.2.11
Description
The issue is related to the
box mpy function in openlink virtuoso-opensource, which allows attackers to cause a Denial of Service (DoS) after running a SELECT statement. This is due to insufficient input validation, enabling a remote attacker to exploit the vulnerability and cause a service disruption.Recommendations
For openlink virtuoso-opensource version 7.2.11, consider disabling the
box mpy function as a temporary workaround until a patch is available. Restrict access to the box mpy function to minimize the risk of exploitation. Avoid using the box mpy function in conjunction with SELECT statements until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Red Os
Ubuntu
Openlink Virtuoso-Opensource