openlink virtuoso-opensource
cpe:2.3:a:openlinksw:virtuoso:*:*:*:*:*:*:*
- 7.2.11
A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11. The issue arises in the sqlg_place_dpipes component, where attackers can cause a service disruption by sending crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image.
Exploitation of this vulnerability leads to a denial-of-service condition, causing the Virtuoso server to crash.
The vulnerability can be reproduced by first creating a SQL file containing a crafted SQL statement designed to exploit the sqlg_place_dpipes component. After removing any existing Docker container named 'virtdb_test', start a new Virtuoso container with the DBA password set to 'dba'. Once the server is running, verify that a simple query executes successfully. Finally, execute the crafted SQL statement through the Virtuoso command-line interface, which will cause the server to crash.
Users can update to OpenLink Virtuoso version 7.2.12, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.