pgproto3 SQL Injection via Protocol Message Size Overflow
GHSA-7jwh-3vrq-q3m8 · CVE-2024-27304 · GHSA-mrww-27vc-gghv · GO-2024-2606
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control.
Patches
The problem is resolved in v2.3.3
Workarounds
Reject user input large enough to cause a single query or bind message to exceed 4 GB in size.
References
- WEB https://github.com/jackc/pgproto3/security/advisories/GHSA-7jwh-3vrq-q3m8
- WEB https://github.com/jackc/pgx/security/advisories/GHSA-mrww-27vc-gghv
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-27304
- WEB https://github.com/jackc/pgproto3/commit/945c2126f6db8f3bea7eeebe307c01fe92bca007
- WEB https://github.com/jackc/pgx/commit/adbb38f298c76e283ffc7c7a3f571036fea47fd4
- WEB https://github.com/jackc/pgx/commit/c543134753a0c5d22881c12404025724cb05ffd8
- WEB https://github.com/jackc/pgx/commit/f94eb0e2f96782042c96801b5ac448f44f0a81df
- PACKAGE https://github.com/jackc/pgproto3
Ready to move
Start Securing
Free, no credit card | First findings in minutes