Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pr6x-gg24-6wfp

Опубликовано: 13 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

EPSS

Процентиль: 12%
0.0004
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 5.9
ubuntu
7 дней назад

[Avoid integer overflow in allocation-size calculations within libpq]

CVSS3: 5.9
nvd
6 дней назад

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

CVSS3: 5.9
msrc
5 дней назад

PostgreSQL libpq undersizes allocations, via integer wraparound

CVSS3: 5.9
debian
6 дней назад

Integer wraparound in multiple PostgreSQL libpq client library functio ...

CVSS3: 5.9
fstec
7 дней назад

Уязвимость библиотеки libpq системы управления базами данных PostgreSQL, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 12%
0.0004
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-190