Lucene search

K
githubGitHub Advisory DatabaseGHSA-J32J-2HXV-RQF7
HistoryJun 18, 2022 - 12:00 a.m.

pg-native and libpq vulnerable to uncontrolled resource consumption

2022-06-1800:00:20
CWE-400
CWE-704
GitHub Advisory Database
github.com
16
pg-native
libpq
dos
vulnerability
resource consumption
npm's libpq

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

31.9%

pg-native before 3.0.1 and libpq before 1.8.10 are vulnerable to Denial of Service (DoS) when the addons attempt to cast the second argument to an array and fail. This happens for every non-array argument passed. Note: pg-native is a mere binding to npm’s libpq library, which in turn has the addons and bindings to the actual C libpq library. This means that problems found in pg-native may transitively impact npm’s libpq.

Affected configurations

Vulners
Node
pg-native_projectpg-nativeRange3.0.0node.js
OR
libpq_projectlibpqRange1.8.9node.js
VendorProductVersionCPE
pg-native_projectpg-native*cpe:2.3:a:pg-native_project:pg-native:*:*:*:*:*:node.js:*:*
libpq_projectlibpq*cpe:2.3:a:libpq_project:libpq:*:*:*:*:*:node.js:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

31.9%

Related for GHSA-J32J-2HXV-RQF7