攻击算术:PostgreSQL libpq 中的整数溢出如何导致拒绝服务
swarm.ptsecurity.com | 研究 | #cloud | #memory-safety | #denial-of-service | #postgresql | #integer-overflow | #libpq
摘要
PT SWARM 在 PostgreSQL 官方客户端库 libpq 的 PQescapeInternal 函数(由 PQescapeLiteral / PQescapeIdentifier 调用)中发现整数溢出漏洞:特定输入会导致内存分配过小、写出数百 MB 数据越过缓冲区,使应用发生段错误,构成拒绝服务风险。
- 发布时间
- 收录时间
Skip to content