Re: OpenSSL v1.1.1n in postgres

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: OpenSSL v1.1.1n in postgres
Дата
Msg-id 146123.1648327136@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: OpenSSL v1.1.1n in postgres  (Daniel Gustafsson <daniel@yesql.se>)
Ответы Re: OpenSSL v1.1.1n in postgres  ("David G. Johnston" <david.g.johnston@gmail.com>)
Список pgsql-bugs
Daniel Gustafsson <daniel@yesql.se> writes:
>> On 26 Mar 2022, at 18:32, Vibhu Chauhan (iDEAS-ER&D) <vibhu.chauhan@wipro.com> wrote:
>> In one security scan we found that OpenSSL v1.1.1k is vulnerable which is sub-component of postgres 13.3.  From
belowlink we came to know that affected OpenSSL version 1.1.1k is fixed in 1.1.1n version. We wanted to know which
postgresversion having this fix version of OpenSSL? And is there any steps to mitigate the risk of version 1.1.1k? 

> PostgreSQL doesn't come statically linked to any OpenSSL version, you need to
> ask your system administrators and/or PostgreSQL service provider about this.

The question is possibly about the EDB Windows installer, but
it would still be better directed to EDB's support people.

            regards, tom lane



В списке pgsql-bugs по дате отправления:

Предыдущее
От: Daniel Gustafsson
Дата:
Сообщение: Re: OpenSSL v1.1.1n in postgres
Следующее
От: "David G. Johnston"
Дата:
Сообщение: Re: OpenSSL v1.1.1n in postgres