openlink virtuoso-opensource
cpe:2.3:a:openlinksw:virtuoso:*:*:*:*:*:*:*
- 7.2.11
A denial-of-service vulnerability has been identified in the itc_sample_row_check component of OpenLink Virtuoso Open Source version 7.2.11. This issue allows attackers to cause a service disruption by executing crafted SQL statements that exploit the vulnerability.
Exploitation of this vulnerability leads to a crash of the Virtuoso database server, causing a denial-of-service condition where the server becomes unresponsive or unavailable.
The vulnerability can be reproduced by running a crafted SQL statement that mixes numeric and integer values in a way that the itc_sample_row_check component cannot handle. This can be done using the isql command-line tool to execute the malicious SQL payload, which causes the Virtuoso server to crash.
Users can update to the latest version of OpenLink Virtuoso Open Source, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.