An exploitable denial-of-service vulnerability exists in the fabric-worker component of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause the server process to dereference a null pointer. An attacker can simply connect to a TCP port in order to trigger this vulnerability.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/96376 | vdb entry third party advisory broken link |
http://www.talosintelligence.com/reports/TALOS-2016-0263/ | patch exploit vdb entry third party advisory technical description |