Re: OpenSSL v1.1.1n in postgres

Поиск
Список
Период
Сортировка
От David G. Johnston
Тема Re: OpenSSL v1.1.1n in postgres
Дата
Msg-id CAKFQuwY-KYfG7bWSq1P2rD7yPQ1+uLQdRfdb+QEW8L4XgCCW9Q@mail.gmail.com
обсуждение исходный текст
Ответ на Re: OpenSSL v1.1.1n in postgres  (Tom Lane <tgl@sss.pgh.pa.us>)
Ответы Re: OpenSSL v1.1.1n in postgres  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-bugs
On Sat, Mar 26, 2022 at 1:39 PM Tom Lane <tgl@sss.pgh.pa.us> wrote:
Daniel Gustafsson <daniel@yesql.se> writes:
>> On 26 Mar 2022, at 18:32, Vibhu Chauhan (iDEAS-ER&D) <vibhu.chauhan@wipro.com> wrote:
>> In one security scan we found that OpenSSL v1.1.1k is vulnerable which is sub-component of postgres 13.3.  From below link we came to know that affected OpenSSL version 1.1.1k is fixed in 1.1.1n version. We wanted to know which postgres version having this fix version of OpenSSL? And is there any steps to mitigate the risk of version 1.1.1k?

> PostgreSQL doesn't come statically linked to any OpenSSL version, you need to
> ask your system administrators and/or PostgreSQL service provider about this.

The question is possibly about the EDB Windows installer, but
it would still be better directed to EDB's support people.


Seems likely.  Given that the CVE is from March and our 13.6 update came out in February the odds are any bundled releases are not yet updatable.

I do find it sad that this question about when a CVE has been patched is being asked where the active version is 10 months old and missing 3 PostgreSQL CVE fixes, including an SSL related one in 13.5

David J.

В списке pgsql-bugs по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: OpenSSL v1.1.1n in postgres
Следующее
От: Tom Lane
Дата:
Сообщение: Re: OpenSSL v1.1.1n in postgres