CVE-2024-57661
Published: 14 January 2025
Description
An issue in the sqlo_df component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
Security Summary
CVE-2024-57661 is a vulnerability in the sqlo_df component of OpenLink Virtuoso Open-Source version 7.2.11. The issue enables attackers to trigger a Denial of Service (DoS) condition through crafted SQL statements. It carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) and is linked to CWE-404.
Remote attackers require no privileges or user interaction and can exploit the vulnerability over the network with low attack complexity. Successful exploitation causes high-impact disruption to availability, resulting in a DoS on the affected Virtuoso instance.
Mitigation details are available in the referenced GitHub issue at https://github.com/openlink/virtuoso-opensource/issues/1220.
Details
- CWE(s)