MonetDB
cpe:2.3:a:monetdb:monetdb:*:*:*:*:*:*:*
- v11.47.11
A denial-of-service vulnerability has been identified in MonetDB Server version 11.47.11. The issue arises in the trimchars component, where crafted SQL statements can cause the server to crash. This vulnerability is related to the handling of NULL values by the newurl function, which can lead to fatal errors in the trimchars function, causing the server to become unresponsive.
Exploitation of this vulnerability leads to a crash of the MonetDB server, causing a denial-of-service condition where the server is no longer available to handle requests.
The vulnerability can be reproduced by executing a SQL statement that uses the TRIM function with the newurl function as an argument. The newurl function should be called with NULL values, which will cause the trimchars function to crash the server. This can be done manually or automated with a script that runs the SQL command through the MonetDB client.
A fix for this vulnerability has been implemented in the MonetDB Dec2023-SP1 release. Users are advised to update to this version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.