pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-controlled size fields to copy heap memory into stored patches for exfiltration or crash the PostgreSQL backend.
Score CVSS v3.1
8.1
/ 10.0
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Informations
- Publié
- 25 sept. 2026
- Mis à jour
- 25 sept. 2026
- Statut
- Received
- Source
- disclosure@vulncheck.com
Faiblesses (CWE)
CWE-125
Références (5)
CVEs similaires
Autres vulnérabilités de type CWE-125
Loading…
Surveillez vos produits
Recevez une alerte automatique à chaque nouvelle CVE affectant vos équipements.