Impact
A stack-based buffer overflow in Pgpool-II can be triggered by an unauthenticated user, causing the process to terminate unexpectedly. The flaw stems from insufficient bounds checking on user-supplied data, aligning with CWE‑121. The primary consequence is denial of service, as the failed process must be restarted to restore normal database proxy functionality. There is no indication in the current data that arbitrary code execution or data exfiltration is possible, but a terminated process could lead to broader system instability if not handled promptly.
Affected Systems
All versions of Pgpool-II distributed by the Pgpool Global Development Group are vulnerable, as no specific version range is provided in the advisory. Organizations relying on Pgpool-II for PostgreSQL connection pooling should review installed versions and plan an upgrade accordingly.
Risk and Exploitability
The vulnerability has a CVSS score of 8.7, indicating a high severity level. EPSS data is not available, and the issue is not referenced in the CISA KEV catalog. Based on the description, the likely attack vector is remote network access to the Pgpool-II service, where an unauthenticated client can send crafted input to trigger the overflow. The absence of exploit probability data means that while the vulnerability is severe, the likelihood of active exploitation is uncertain, yet the potential impact warrants proactive mitigation.
OpenCVE Enrichment