Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-61024

Опубликовано: 23 июн. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

A flaw was found in virtuoso-opensource. An attacker could send specially crafted SQL (Structured Query Language) statements to a specific component, sqlo_try_in_loop, leading to a Denial of Service (DoS). This could make the service unavailable to legitimate users.

Меры по смягчению последствий

To reduce the attack surface, restrict network access to the virtuoso-opensource service to only trusted clients using firewall rules. If the virtuoso-opensource service is not actively used, consider disabling it. To disable the service: sudo systemctl stop virtuoso-opensource sudo systemctl disable virtuoso-opensource Applying firewall rules to limit access to the service's port (e.g., 1111/tcp) from specific trusted IP addresses can also reduce exposure. sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_IP_ADDRESS>" port port="1111" protocol="tcp" accept' sudo firewall-cmd --reload Disabling the service will prevent its functionality. A service restart or system reboot may be required for changes to take full effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7virtuoso-opensourceOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-606
https://bugzilla.redhat.com/show_bug.cgi?id=2491869virtuoso-opensource: virtuoso-opensource: Denial of Service via crafted SQL statements in sqlo_try_in_loop

EPSS

Процентиль: 28%
0.00351
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
nvd
около 2 месяцев назад

An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
debian
около 2 месяцев назад

An issue in the sqlo_try_in_loop component of openlink virtuoso-openso ...

CVSS3: 7.5
github
около 2 месяцев назад

An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

EPSS

Процентиль: 28%
0.00351
Низкий

6.5 Medium

CVSS3