QID 982733
QID 982733: Python (pip) Security Update for asyncpg (GHSA-2xpj-f5g2-8p7m)
asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, because of access to an uninitialized pointer in the array data decoder.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2xpj-f5g2-8p7m for updates pertaining to this vulnerability.
Vendor References
- GHSA-2xpj-f5g2-8p7m -
github.com/advisories/GHSA-2xpj-f5g2-8p7m
CVEs related to QID 982733
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2xpj-f5g2-8p7m | asyncpg |
|