PT-2020-14995 · Postgresql · Asyncpg

Risicle

·

Published

2020-08-12

·

Updated

2024-07-12

·

CVE-2020-17446

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions asyncpg versions prior to 0.21.0
Description The issue allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code on a database client via a crafted server response. This is due to access to an uninitialized pointer in the array data decoder.
Recommendations For versions prior to 0.21.0, update to version 0.21.0 or later to resolve the issue.

Fix

Access of Uninitialized Pointer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-17446
DLA-2363-1
GHSA-2XPJ-F5G2-8P7M
OPENSUSE-SU-2024:11215-1
OPENSUSE-SU-2024:14132-1
PYSEC-2020-24

Affected Products

Asyncpg