PT-2023-14504 · Unknown+5 · Active Record+5

Jeremy Evans

·

Publicado

2023-01-18

·

Atualizado

2025-11-25

·

CVE-2022-44566

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions ActiveRecord versions prior to 6.1.7.1 ActiveRecord versions prior to 7.0.4.1
Description A denial of service issue is present in ActiveRecord's PostgreSQL adapter. When a value outside the range for a 64bit signed integer is provided to the PostgreSQL connection adapter, it will treat the target column type as numeric. Comparing integer values against numeric values can result in a slow sequential scan, potentially leading to a denial of service. The issue is related to insufficient input validation in the PostgreSQL adapter.
Recommendations For versions prior to 6.1.7.1, update to version 6.1.7.1 or apply the patch 6-1-Added-integer-width-check-to-PostgreSQL-Quoting.patch. For versions prior to 7.0.4.1, update to version 7.0.4.1 or apply the patch 7-0-Added-integer-width-check-to-PostgreSQL-Quoting.patch. As a temporary workaround, ensure that user-supplied input provided to ActiveRecord clauses does not contain integers wider than a signed 64bit representation or floats.

Exploit

Correção

DoS

RCE

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_16880
ALT-PU-2023-1336
ALT-PU-2023-4268
ALT-PU-2024-7814
BDU:2025-01400
CVE-2022-44566
DLA-4383-1
GHSA-579W-22J4-4749
OESA-2023-1132
OESA-2023-1133
OPENSUSE-SU-2024:12766-1
OPENSUSE-SU-2024:14069-1
OPENSUSE-SU-2025:15112-1
RHSA-2023:6818
RLSA-2023:6818
SUSE-SU-2023:0492-1
SUSE-SU-2023:0518-1
SUSE-SU-2023:0587-1
SUSE-SU-2023_0492-1

Produtos afetados

Alt Linux
Active Record
Debian
Red Os
Rocky Linux
Suse