CVE-2024-57615
Published: 14 January 2025
Description
An issue in the BATcalcbetween_intern component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
Security Summary
CVE-2024-57615 is a vulnerability affecting the BATcalcbetween_intern component in MonetDB Server version 11.47.11. The issue enables attackers to trigger a Denial of Service (DoS) condition by sending crafted SQL statements. It is associated with CWE-89 and carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), indicating high severity primarily due to its impact on availability.
The vulnerability can be exploited by unauthenticated attackers (PR:N) over the network (AV:N) with low attack complexity (AC:L) and no requirement for user interaction (UI:N). Exploitation leads to a high-impact disruption of service (A:H) on the affected MonetDB Server instance, such as crashes or unresponsiveness, without compromising confidentiality (C:N) or integrity (I:N).
Mitigation details and further information are available in the referenced GitHub issue at https://github.com/MonetDB/MonetDB/issues/7413.
Details
- CWE(s)