Описание
An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
A flaw was found in virtuoso-opensource. An attacker could send specially crafted SQL (Structured Query Language) statements to a specific component, sqlo_try_in_loop, leading to a Denial of Service (DoS). This could make the service unavailable to legitimate users.
Меры по смягчению последствий
To reduce the attack surface, restrict network access to the virtuoso-opensource service to only trusted clients using firewall rules. If the virtuoso-opensource service is not actively used, consider disabling it.
To disable the service:
sudo systemctl stop virtuoso-opensource
sudo systemctl disable virtuoso-opensource
Applying firewall rules to limit access to the service's port (e.g., 1111/tcp) from specific trusted IP addresses can also reduce exposure.
sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_IP_ADDRESS>" port port="1111" protocol="tcp" accept'
sudo firewall-cmd --reload
Disabling the service will prevent its functionality. A service restart or system reboot may be required for changes to take full effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 7 | virtuoso-opensource | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
An issue in the sqlo_try_in_loop component of openlink virtuoso-openso ...
An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
EPSS
6.5 Medium
CVSS3