VDB

DEBIAN-CVE-2024-27304

DEBIAN-CVE-2024-27304 PUBLISHED CVSS 9.800000190734863 CRITICAL

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

Risk Scores

CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:11golang-github-jackc-pgx4.18.3-1, 4.18.3-2, 0
Debian:12golang-github-jackc-pgconn1.14.3-1, 1.14.3-1, 1.14.0-1
Debian:14golang-github-jackc-pgx0, 0
Debian:13golang-github-jackc-pgx0, 0
Debian:14golang-github-jackc-pgconn1.14.0-1, 0, 1.14.3-1~exp0
Debian:13golang-github-jackc-pgconn1.14.3-1, 1.14.0-1, 0
Debian:12golang-github-jackc-pgx4.18.3-1, 4.18.3-2, *

Timeline

  • Mar 6, 2024 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›