The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.
CVSS Details
- CVSS 3.1 Base Score: 5.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade pygresql | Jul 30, 2024 | Oct 22, 2009 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 14, 2009 |
| Ubuntu | — | Upgrade python-pygresql | Nov 8, 2024 | Oct 22, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub