PgBouncer
cpe:2.3:a:pgbouncer:pgbouncer:*:*:*:*:*:*:*, +1 more
- < 1.25.2
A vulnerability exists in PgBouncer versions prior to 1.25.2, where an integer overflow in the network packet parsing code can bypass a boundary check, potentially leading to a crash. This issue allows an unauthenticated remote attacker to cause a denial-of-service by sending a malformed SCRAM authentication packet.
Exploitation of this vulnerability causes PgBouncer to crash, disrupting service.
Users can upgrade to PgBouncer version 1.25.2 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.