UBUNTU-CVE-2021-3935
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3935
Summary:
Details: When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.
References: https://ubuntu.com/security/CVE-2021-3935, https://www.pgbouncer.org/2021/11/pgbouncer-1-16-1, https://github.com/pgbouncer/pgbouncer/releases/tag/pgbouncer_1_16_1, https://github.com/pgbouncer/pgbouncer/commit/e4453c9151a2f5af0a9cb049b302a3f9f9654453, https://bugzilla.redhat.com/show_bug.cgi?id=2021251, http://www.pgbouncer.org/changelog.html#pgbouncer-116x, https://www.cve.org/CVERecord?id=CVE-2021-3935
Affected packages
Package
Name: pgbouncer
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
