MonetDB
cpe:2.3:a:monetdb:monetdb:*:*:*:*:*:*:*
- v11.47.11
A denial-of-service vulnerability has been identified in MonetDB Server version 11.47.11. The issue arises in the 'bind_col_exp' component, where attackers can cause the server to crash by using specially crafted SQL statements. This vulnerability can be reproduced by creating a table and then executing a SELECT query that includes complex ordering and aggregation functions, which leads to a server crash.
Exploitation of this vulnerability causes the MonetDB server to crash, disrupting any active database sessions and requiring the server to be restarted.
The vulnerability can be reproduced by creating a table and then executing a SELECT query that orders the results based on an average of a maximum value, using window functions and NULL handling. This can be done manually or automated with a script that runs inside a Docker container with MonetDB.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.