pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.
References
Configurations
No configuration.
History
21 Nov 2024, 09:04
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/jackc/pgproto3/commit/945c2126f6db8f3bea7eeebe307c01fe92bca007 - | |
References | () https://github.com/jackc/pgproto3/security/advisories/GHSA-7jwh-3vrq-q3m8 - | |
References | () https://github.com/jackc/pgx/commit/adbb38f298c76e283ffc7c7a3f571036fea47fd4 - | |
References | () https://github.com/jackc/pgx/commit/c543134753a0c5d22881c12404025724cb05ffd8 - | |
References | () https://github.com/jackc/pgx/commit/f94eb0e2f96782042c96801b5ac448f44f0a81df - | |
References | () https://github.com/jackc/pgx/security/advisories/GHSA-mrww-27vc-gghv - | |
Summary |
|
06 Mar 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-06 19:15
Updated : 2024-11-21 09:04
NVD link : CVE-2024-27304
Mitre link : CVE-2024-27304
CVE.ORG link : CVE-2024-27304
JSON object : View
Products Affected
No product.