Impact
An out-of-bounds write vulnerability in Pgpool-II allows an authenticated attacker to trigger abnormal process termination, resulting in a denial of service. The out-of-bounds write can overwrite memory outside the intended buffer, compromising program stability. This weakness is classified as CWE-787.
Affected Systems
The affected vendor is Pgpool Global Development Group, product Pgpool-II. Version information was not disclosed; therefore any potential release before the update that addresses this issue could be vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. As the flaw requires authentication, the attacker must possess valid credentials for Pgpool-II, limiting the threat to users who can be compromised or exploited for credential gain. The impact is local process termination, which disrupts service availability but does not expose data. Due to the lack of exploitation data, the likelihood of exploitation remains uncertain, though the moderate severity suggests it is less urgent than higher‑score vulnerabilities.
OpenCVE Enrichment