MonetDB Server Denial-of-Service Vulnerability in atom_get_int Component

Vulnerability

A denial-of-service vulnerability has been identified in MonetDB Server version 11.47.11. The issue arises in the atom_get_int component, where attackers can cause the server to crash by sending specially crafted SQL statements. This vulnerability can be reproduced by executing a SQL query that orders the results by a debug variable, which triggers a backtrace indicating the crash sequence.

Impact

Exploitation of this vulnerability leads to a crash of the MonetDB server, causing a denial-of-service condition where the server is no longer available to handle requests.

Reproduction

The vulnerability can be reproduced by running a Docker container with the MonetDB image version Jun2023-SP2. After starting the container and setting up the database admin password, a test SQL file containing a crafted SQL statement is executed using the MonetDB client. This SQL statement, when processed by the server, causes it to crash, as confirmed by checking the server process status after the execution.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
9.1
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.