GHSA-jqcq-xjh3-6g23

ADVISORY - github

Summary

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

Common Weakness Enumeration (CWE)

ADVISORY - github

Improper Validation of Array Index


GitHub

CREATED

UPDATED

EXPLOITABILITY SCORE

3.9

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

7.5high