SECURITY: Denial of Service Attack via specially crafted network packets
Details
| Detail name | Value |
|---|---|
| Changelog Number | 10948 |
| Type | Bug |
| Status | Resolved |
| Affected Versions | Exasol 6.1.0, Exasol 6.2.0, Exasol 7.0.0 |
| Fix Versions | Exasol 7.1.0, Exasol 7.0.4, Exasol 6.1.14, Exasol 6.2.12 |
| Resolution Date | 2020-11-26 |
Issue
We discovered a high severity denial of service vulnerability that can be exploited by an attacker with network access to the cluster by sending a specific network packet to one of the nodes.
This will cause a communication component in the Exasol cluster to fail, rendering the database inaccessible. It can also lead to exhaustion of local harddrive space on the attacked node.
Remediation
Users should upgrade to Exasol version 6.1.14, 6.2.12 or 7.0.4