PT-2024-2043 · Pgx+2 · Pgx+2
Paul-Gerste-Sonarsource
·
Published
2024-03-04
·
Updated
2026-05-21
·
CVE-2024-27304
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
pgx versions prior to 4.18.2
pgx versions prior to 5.5.4
Description
SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control.
Recommendations
For pgx versions prior to 4.18.2, update to version 4.18.2 or later.
For pgx versions prior to 5.5.4, update to version 5.5.4 or later.
As a temporary workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.
Exploit
Fix
SQL injection
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Pgx