OpenLink Virtuoso Denial-of-Service Vulnerability in itc_sample_row_check Component

Vulnerability

A denial-of-service vulnerability has been identified in the itc_sample_row_check component of OpenLink Virtuoso Open Source version 7.2.11. This issue allows attackers to cause a service disruption by executing crafted SQL statements that exploit the vulnerability.

Impact

Exploitation of this vulnerability leads to a crash of the Virtuoso database server, causing a denial-of-service condition where the server becomes unresponsive or unavailable.

Reproduction

The vulnerability can be reproduced by running a crafted SQL statement that mixes numeric and integer values in a way that the itc_sample_row_check component cannot handle. This can be done using the isql command-line tool to execute the malicious SQL payload, which causes the Virtuoso server to crash.

Remediation

Users can update to the latest version of OpenLink Virtuoso Open Source, where this vulnerability has been fixed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
6.1
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.