SECURITY: Denial of Service Attack via specially crafted network packets

Details

Detail name Value
Changelog Number 10948
Type Bug
Status Resolved
Affected Versions Exasol 6.1.0, Exasol 6.2.0, Exasol 7.0.0
Fix Versions Exasol 7.1.0, Exasol 7.0.4, Exasol 6.1.14, Exasol 6.2.12
Resolution Date 2020-11-26

Issue

We discovered a high severity denial of service vulnerability that can be exploited by an attacker with network access to the cluster by sending a specific network packet to one of the nodes.

This will cause a communication component in the Exasol cluster to fail, rendering the database inaccessible. It can also lead to exhaustion of local harddrive space on the attacked node.

Remediation

Users should upgrade to Exasol version 6.1.14, 6.2.12 or 7.0.4