9.8
CVSSv3

CVE-2020-17446

Published: 12/08/2020 Updated: 27/01/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

asyncpg prior to 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, because of access to an uninitialized pointer in the array data decoder.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

magic asyncpg

debian debian linux 9.0