PgBouncer
cpe:2.3:a:pgbouncer:pgbouncer:*:*:*:*:*:*:*, +1 more
- < 1.25.2
A null pointer dereference vulnerability has been identified in PgBouncer versions prior to 1.25.2. This vulnerability can lead to a crash if a server sends an error response lacking the SQLSTATE field. The issue arises from improper handling of error responses, which can create a scenario where PgBouncer attempts to process a null value, causing a crash.
Exploitation of this vulnerability can cause PgBouncer to crash, disrupting database connection pooling and potentially leading to downtime for applications relying on the service.
Users can upgrade to PgBouncer version 1.25.2 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.