QID 997623
Date Published: 2024-03-06
QID 997623: GO (Go) Security Update for github.com/jackc/pgproto3 (GHSA-mrww-27vc-gghv)
SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-mrww-27vc-gghv for updates and patch information.
Vendor References
- GHSA-mrww-27vc-gghv -
github.com/advisories/GHSA-mrww-27vc-gghv
CVEs related to QID 997623
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mrww-27vc-gghv | github.com/jackc/pgproto3 |
|