Impact
An out-of-bounds write condition exists in Pgpool-II that may lead to abnormal process termination or arbitrary code execution by an authenticated user. The vulnerability stems from insufficient bounds checking during data handling, which can corrupt memory and allow attackers to execute arbitrary instructions. This flaw can compromise confidentiality, integrity and availability of the database cluster if exploited.
Affected Systems
Pgpool Global Development Group’s Pgpool-II product is affected. The specific product version range responsible for the flaw was not disclosed in the advisory. Administrators should verify the installed version and compare it against the vendor’s documentation for affected releases. The vulnerability requires authentication within the Pgpool-II service to be triggered.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. No EPSS score was provided, so the current prevalence of exploitation is uncertain. The flaw is not present in the CISA KEV catalog, yet the high impact and requirement for authenticated access suggest that privileged users could exploit it if proper controls are not in place. Attackers would need legitimate credentials to initiate the vulnerable operation, making internal threat actors or compromised accounts primary vectors.
OpenCVE Enrichment