PT-2023-8877 · Openlink+4 · Openlink Virtuoso-Opensource+4

Fuboat

·

Published

2023-11-29

·

Updated

2024-07-04

·

CVE-2023-48946

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions openlink virtuoso-opensource version 7.2.11
Description The issue is related to the box mpy function in openlink virtuoso-opensource, which allows attackers to cause a Denial of Service (DoS) after running a SELECT statement. This is due to insufficient input validation, enabling a remote attacker to exploit the vulnerability and cause a service disruption.
Recommendations For openlink virtuoso-opensource version 7.2.11, consider disabling the box mpy function as a temporary workaround until a patch is available. Restrict access to the box mpy function to minimize the risk of exploitation. Avoid using the box mpy function in conjunction with SELECT statements until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-02539
CVE-2023-48946
USN-6879-1

Affected Products

Debian
Linuxmint
Red Os
Ubuntu
Openlink Virtuoso-Opensource