Amazon Athena ODBC Driver Resource Exhaustion Vulnerability Leading to Denial-of-Service
Vulnerability
A denial-of-service vulnerability has been identified in the Amazon Athena ODBC driver, prior to version 2.1.0.0. The issue arises from the parsing components of the driver, which allocate resources without limits. This flaw could be exploited by a threat actor who delivers crafted input that triggers excessive resource consumption during the driver's parsing operations.
Impact
Exploitation of this vulnerability can lead to uncontrolled resource consumption, causing a denial-of-service condition where the application becomes unresponsive or unavailable.
Remediation
Users are advised to upgrade to the Amazon Athena ODBC driver version 2.1.0.0 or later. The updated driver is available for Windows, Linux, and macOS. For detailed download instructions, refer to the Amazon Athena ODBC 2.x release notes.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
