CyberRota Analysis
AI-GeneratedpgPointcloud versions up to 1.2.5 are vulnerable to a heap out-of-bounds read issue during WKB deserialization, allowing authenticated database users to access adjacent heap memory. This vulnerability can be exploited by attackers to exfiltrate sensitive data or crash the PostgreSQL backend by supplying malicious pcpatch values. Database administrators and security teams should prioritize patching this vulnerability to mitigate potential data breaches and service disruptions.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-controlled size fields to copy heap memory into stored patches for exfiltration or crash the PostgreSQL backend.