USN-8808-1: SQL parse vulnerabilities
Ubuntu warned that SQL parse complexity flaws can exhaust CPU via deeply nested SQL statements.
Ubuntu Security Notice USN-8808-1 reports multiple algorithmic complexity flaws in SQL parse when parsing SQL statements with deeply nested parentheses, comments, or dollar-quoted string literals. An attacker can cause the parser to consume excessive CPU, resulting in a denial of service. The notice does not name a CVE or report exploitation in the wild.
- USN-8808-1 covers algorithmic complexity flaws in SQL parse.
- Deeply nested parentheses, comments, or dollar-quoted strings can exhaust CPU.
- The issue can cause denial of service; no CVE is named.
It was discovered that SQL parse contained multiple algorithmic complexity flaws when parsing SQL statements with deeply nested parentheses, comments, or dollar-quoted string literals. An attacker could use this issue to cause SQL parse to consume excessive CPU resources, resulting in a denial of service.
This source does not provide full text. Read it at ubuntu.com.