openlink virtuoso-opensource
cpe:2.3:a:openlinksw:virtuoso:*:*:*:*:*:*:*
- 7.2.11
A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11. The issue arises in the dfe_body_copy component, where attackers can cause a service crash by executing specially crafted SQL statements. This vulnerability can be reproduced using the OpenLink Virtuoso Docker image.
Exploitation of this vulnerability leads to a denial-of-service condition, causing the Virtuoso server to crash.
The vulnerability can be reproduced by first creating a SQL file containing the proof-of-concept SQL injection payload. After removing any existing Docker container named 'virtdb_test', OpenLink Virtuoso can be started in a new container with the DBA password set to 'dba'. Once the server is running, the SQL file can be executed using the isql command-line interface, which interfaces with the Virtuoso database.
Users can upgrade to the latest version of OpenLink Virtuoso to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.