NA

CVE-2024-27304

Published: 06/03/2024 Updated: 06/03/2024

Vulnerability Summary

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

Vulnerability Trend

Vendor Advisories

Debian Bug report logs - #1065687 golang-github-jackc-pgx: CVE-2024-27304 Package: src:golang-github-jackc-pgx; Maintainer for src:golang-github-jackc-pgx is Debian Go Packaging Team <team+pkg-go@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 8 Mar 2024 21:42:04 UTC Severity: i ...
Description<!---->This CVE is under investigation by Red Hat Product Security ...