The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Jackc Pgproto3
cpe:2.3:a:jackc:pgproto3:*:*:*:*:*:go:*:*
|
2.0.0
|
<= 2.3.3
|