← Back

CVE-2024-10977

nvd nist
Published: Nov 14, 2024Modified: Jun 17, 2026

JSON object

Loading...
3.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.2 / Impact: 1.4
Source: NVD

Description

Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper user of psql mistakes for valid query results. This is probably not a concern for clients where the user interface unambiguously indicates the boundary between one error message and other text. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.

Affected (10)

1 product
Postgresql
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Postgresql
From 12.0 to 12.21
From 13.0 to 13.17
From 14.0 to 14.14
From 15.0 to 15.9
From 16.0 to 16.5
Version 17.0
Version 17.0 beta1
Version 17.0 beta2
Version 17.0 beta3
Version 17.0 rc1

References (2)

Source: f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.