Description
asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, because of access to an uninitialized pointer in the array data decoder.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2363-1 | asyncpg security update |
EUVD |
EUVD-2020-0048 | asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, because of access to an uninitialized pointer in the array data decoder. |
Github GHSA |
GHSA-2xpj-f5g2-8p7m | Asyncpg Arbitrary Code Execution Via Access to an Uninitialized Pointer |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T13:53:17.448Z
Reserved: 2020-08-09T00:00:00.000Z
Link: CVE-2020-17446
No data.
Status : Modified
Published: 2020-08-12T16:15:11.963
Modified: 2024-11-21T05:08:07.977
Link: CVE-2020-17446
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA