MonetDB Server Damerau-Levenshtein Component Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the Damerau-Levenshtein component of MonetDB Server version 11.49.1. This issue allows attackers to cause the server to crash by using specially crafted SQL statements. The vulnerability can be reproduced in a Docker container running Ubuntu 20.04.

Impact

Exploitation of this vulnerability leads to a crash of the MonetDB server process, causing a denial-of-service condition where the database server is no longer available to handle requests.

Reproduction

The vulnerability can be reproduced by creating a table and inserting various values, including NULLs and large numbers. After populating the table, a SQL query can be executed that uses the Damerau-Levenshtein function with specific parameters. This query causes the server to crash, as the process handling the database operations is terminated.

Remediation

This vulnerability has been fixed in the Dec2023 release of MonetDB Server.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
9.1
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.