Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Attack arithmetic: how an integer overflow in PostgreSQL libpq leads to denial of service

Summary

An integer overflow in PostgreSQL libpq's PQescapeInternal() makes it allocate too little and write hundreds of MB past the buffer, segfaulting applications — a denial-of-service vulnerability.
Published
Collected

original ↗

Related coverage

back