Asyncpg Arbitrary Code Execution Via Access to an Uninitialized Pointer
Critical severity
GitHub Reviewed
Published
Apr 20, 2021
to the GitHub Advisory Database
•
Updated Sep 12, 2024
Description
Published by the National Vulnerability Database
Aug 12, 2020
Reviewed
Apr 14, 2021
Published to the GitHub Advisory Database
Apr 20, 2021
Last updated
Sep 12, 2024
asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, because of access to an uninitialized pointer in the array data decoder.
References