pgPointcloud 1.2.5 及之前版本存在一个堆缓冲区越界读取漏洞,该漏洞出现在对维数补丁 WKB(Well-Known Binary)进行反序列化的过程中。具有认证权限的数据库用户可以通过此漏洞读取相邻的堆内存。攻击者可以通过构造恶意 pcpatch 值,并利用其控制的尺寸字段,将堆内存内容复制到存储的补丁中,从而进行数据外泄或导致 PostgreSQL 后端崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pgpointcloud | pointcloud | 0 ~ 1.2.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet