Executive brief
Aerospike Database Server, a high-performance NoSQL database used for large-scale web applications, contains a critical security flaw in its data querying component. An unauthenticated attacker can exploit this by sending a specially crafted network packet to the database server. Successful exploitation could allow the attacker to take complete control of the server, potentially leading to data theft, service disruption, or unauthorized access to the underlying infrastructure.
Technical details
A stack-based buffer overflow vulnerability exists in Aerospike Database Server 3.10.0.3 within the secondary index matching logic. The flaw is located in the `as_sindex__simatch_by_iname` function, which is reachable during the processing of multi-record query transactions. When the server receives a packet with the `PROTO_TYPE_AS_MSG` protocol type and the `AS_MSG_FIELD_BIT_INDEX_RANGE` field set, it triggers the query setup path. An attacker can trigger the overflow by providing a specially crafted index name or related field in the query packet. This vulnerability is exploitable over the network without authentication, allowing for remote code execution (RCE) with the privileges of the database process.
Affected products
- Aerospike Aerospike Database Server 3.10.0.3
Timeline
- 2016-11-20: disclosed: Vulnerability reported to vendor by Cisco Talos
- 2017-01-09: advisory: Public advisory released by Cisco Talos
- 2017-01-26: advisory: NVD publication date