asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, because of access to an uninitialized pointer in the array data decoder.
| Software | From | Fixed in |
|---|---|---|
| magic / asyncpg | - | 0.21.0 |
| debian / debian_linux | 9.0 | 9.0.x |
asyncpg
|
- | 0.21.0 |