GHSA-j32j-2hxv-rqf7

    Dashboard / Vulnerabilities / GHSA-j32j-2hxv-rqf7

    GHSA-j32j-2hxv-rqf7

    Published: 18 Jun 2022Last Modified: 8 Nov 2023

    Summary: pg-native and libpq vulnerable to uncontrolled resource consumption

    Details: pg-native before 3.0.1 and libpq before 1.8.10 are vulnerable to Denial of Service (DoS) when the addons attempt to cast the second argument to an array and fail. This happens for every non-array argument passed. **Note:** pg-native is a mere binding to npm's libpq library, which in turn has the addons and bindings to the actual C libpq library. This means that problems found in pg-native may transitively impact npm's libpq.

    Affected packages

    Package

    Name: libpq

    Purl: pkg:npm/libpq

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.8.10

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-j32j-2hxv-rqf7 | CVE-DB