CVE-2023-31627

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2023-31627
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-31627.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-31627
Related
Published
2023-05-15T15:15:12Z
Modified
2024-09-18T03:24:50.686233Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An issue in the strhash component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

References

Affected packages

Debian:11 / virtuoso-opensource

Package

Name
virtuoso-opensource
Purl
pkg:deb/debian/virtuoso-opensource?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7.*

7.2.5.1+dfsg1-0.1
7.2.5.1+dfsg1-0.2
7.2.5.1+dfsg1-0.3
7.2.5.1+dfsg1-0.4
7.2.5.1+dfsg1-0.5
7.2.5.1+dfsg1-0.6
7.2.5.1+dfsg1-0.7
7.2.5.1+dfsg1-0.8
7.2.12+dfsg-0.1
7.2.12+dfsg-0.2
7.2.12+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / virtuoso-opensource

Package

Name
virtuoso-opensource
Purl
pkg:deb/debian/virtuoso-opensource?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7.*

7.2.5.1+dfsg1-0.3
7.2.5.1+dfsg1-0.4
7.2.5.1+dfsg1-0.5
7.2.5.1+dfsg1-0.6
7.2.5.1+dfsg1-0.7
7.2.5.1+dfsg1-0.8
7.2.12+dfsg-0.1
7.2.12+dfsg-0.2
7.2.12+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / virtuoso-opensource

Package

Name
virtuoso-opensource
Purl
pkg:deb/debian/virtuoso-opensource?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.2.12+dfsg-0.2

Affected versions

7.*

7.2.5.1+dfsg1-0.3
7.2.5.1+dfsg1-0.4
7.2.5.1+dfsg1-0.5
7.2.5.1+dfsg1-0.6
7.2.5.1+dfsg1-0.7
7.2.5.1+dfsg1-0.8
7.2.12+dfsg-0.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/openlink/virtuoso-opensource

Affected ranges

Type
GIT
Repo
https://github.com/openlink/virtuoso-opensource
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

v4.*

v4.5.0
v4.5.2
v4.5.3
v4.5.4
v4.5.6
v4.5.7

v5.*

v5.0.0
v5.0.1
v5.0.12
v5.0.13
v5.0.14
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9

v6.*

v6.0.0
v6.0.0-tp1
v6.1.0
v6.1.1
v6.1.2
v6.1.3
v6.1.4
v6.1.5
v6.1.6
v6.1.7
v6.1.7.1
v6.1.7.2
v6.1.8

v7.*

v7.0.0
v7.1.0
v7.2.0
v7.2.0.1
v7.2.1
v7.2.2
v7.2.2.1
v7.2.4
v7.2.4.1
v7.2.4.2
v7.2.5
v7.2.5.1
v7.2.6
v7.2.6.1
v7.2.7
v7.2.8
v7.2.9