DirectorySecurity advisories
Sign in

Security advisories

GHSA-7jwh-3vrq-q3m8

Published

Last updated

https://github.com/advisories/GHSA-7jwh-3vrq-q3m8

Description

pgproto3 SQL Injection via Protocol Message Size Overflow. ### Impact

SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control.

Patches

The problem is resolved in v2.3.3

Workarounds

Reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

References

Affected packages

Advisories are based on vulnerability information provided by Grype from Anchore.

Products

Chainguard Images

© 2024 Chainguard, Inc.