Attack arithmetic: how an integer overflow in PostgreSQL libpq leads to denial of service
swarm.ptsecurity.com | research | #cloud | #memory-safety | #denial-of-service | #postgresql | #integer-overflow | #libpq
Summary
An integer overflow in PostgreSQL libpq's PQescapeInternal() makes it allocate too little and write hundreds of MB past the buffer, segfaulting applications — a denial-of-service vulnerability.
- Published
- Collected
Skip to content