Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-61023

Опубликовано: 23 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

A flaw was found in virtuoso-opensource. An attacker could exploit a vulnerability in the st_compare component by sending specially crafted SQL statements. This could lead to a Denial of Service (DoS), making the service unavailable to legitimate users.

Отчет

Although virtuoso-opensource is shipped with RHEL 7 Extended Lifecycle Support (ELS), the vulnerable code is completely absent from the package. Therefore, Red Hat products are not impacted by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7virtuoso-opensourceNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=2491803virtuoso-opensource: Virtuoso-opensource: Denial of Service in st_compare component via crafted SQL statements

EPSS

Процентиль: 39%
0.00476
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
nvd
около 2 месяцев назад

An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
debian
около 2 месяцев назад

An issue in the st_compare component of openlink virtuoso-opensource v ...

CVSS3: 7.5
github
около 2 месяцев назад

An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

EPSS

Процентиль: 39%
0.00476
Низкий

7.5 High

CVSS3