Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1tELKf-006pIv-Ho for pgsql-general@arkaria.postgresql.org; Fri, 22 Nov 2024 04:31:49 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1tELKd-004jP6-8e for pgsql-general@arkaria.postgresql.org; Fri, 22 Nov 2024 04:31:47 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1tELKc-004jOy-PS for pgsql-general@lists.postgresql.org; Fri, 22 Nov 2024 04:31:46 +0000 Received: from mail-pg1-x529.google.com ([2607:f8b0:4864:20::529]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.94.2) (envelope-from ) id 1tELKa-003A5V-4o for pgsql-general@lists.postgresql.org; Fri, 22 Nov 2024 04:31:45 +0000 Received: by mail-pg1-x529.google.com with SMTP id 41be03b00d2f7-7ae3d7222d4so1332074a12.3 for ; Thu, 21 Nov 2024 20:31:44 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1732249903; x=1732854703; darn=lists.postgresql.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=4IXqooPsWYTYqmCGJbk2eXu3M/YBPLapdZZRzOb+tuw=; b=DAJaXfPAD4/Cu2SW0mksxhTCN3NHLmCkiXaw8sg7lJYPg1deB9RxFa+Cb9eggNv+mB esQWuiRMOnGvezHp/zpgVHKZtIZiDrDmJGwPmOx68hU9AiztI8w/uNcOVP3RiiBW64NL 9AHueYRjHku0t3ZcU5e6MNpTsjvbxQrEzoM6b/TGAUTZJzMD/F657UnwdIypUgshcshe 1ws6kM71mhVXc2+y5jGMuQZT+/DO1lHthLvxFolVvliGwHfiuDu3nzPY1axYqrmHUMzr +U3oAOc4ca+HgFhmiy48+TZdUY4rQFvST3zE/q6Di86aW658G7eVFlMUSG22BjwNnDug X3Pw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1732249903; x=1732854703; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=4IXqooPsWYTYqmCGJbk2eXu3M/YBPLapdZZRzOb+tuw=; b=oGNmDAySQ2LIkOJEUVnrr+S12PuGaN0+r2EuZ4c1MSBkx4/0GUI+Co//BULCmiuY4A loMG8TphrEGgm4SgaUl8Lcozg1hsWklFVJ7RVD8WjmP+E1CdKYHqSHq1OkYt51F49Gh1 Qxwtfr+NMv+n16SI/nUyXRTCaiFvOgy1+LQdmgCoWAZhY4LgnAcBhYESW4r65D20ZHnT SdpWnO9OZXENFxEzm32xOxyLPyc/8wYKGjNeuDgPXtsLCMe+f5nUObLWYMm3Hhw3MSiU 7cB+/y0fHe/je6HymHa0qCbqYM24j+lZeiD8J5pZ844Wq+LqwXh3Nc5ehaXHId0DmakH hnIg== X-Forwarded-Encrypted: i=1; AJvYcCX25UFlnUrtFmk0dyQwbmGAP+EIlK6UcVT81/OLdCT2uzekeV8h8y1royXicHDgTjhT5y+rJSJYCpTab0GW@lists.postgresql.org X-Gm-Message-State: AOJu0Yx1GxcL9/w+qeLMe1ftG2P+a6OgbpTlfGLwOe76VfJGdIqJR29o o9JizvlzPxK1Kx3sBqRekfMZKa1GzkzgC2skbTfalPy8vRKEdV1Iv88mupXfV0l3KIewBat5Oih Laa6cvyvMctRcnBaFFa92WP/Pu3BZTVRG6nk= X-Gm-Gg: ASbGnctZDbIwRISvZ0YE61RNWMUfqN1cpWZP50Dj2j52oLZVtIuPH2uag2VQsU/ib1/ GnmC5vkPvqs3ZUUId24llvJhxfdRsZA== X-Google-Smtp-Source: AGHT+IEts0i5eMVnCKKPmcgD7DAO/u70WJpgHMZ/vRG3w5+ItwHs9VzXP12Bdr+hVTCsMqMZfWhagS64hNNMipFPCcY= X-Received: by 2002:a05:6a20:2d23:b0:1db:e038:7e01 with SMTP id adf61e73a8af0-1e09e44e33fmr2095779637.11.1732249902800; Thu, 21 Nov 2024 20:31:42 -0800 (PST) MIME-Version: 1.0 References: <7b5846ac-c16e-48d3-b548-99a772a528c5@aklaver.com> In-Reply-To: From: Subhash Udata Date: Fri, 22 Nov 2024 10:01:31 +0530 Message-ID: Subject: Re: CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10 To: "David G. Johnston" Cc: Adrian Klaver , =?UTF-8?B?6rmA7KO87Jew?= , "pgsql-general@lists.postgresql.org" Content-Type: multipart/alternative; boundary="0000000000001e68c4062778dcb6" List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk --0000000000001e68c4062778dcb6 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Thank you for your detailed response. I would like to clarify my situation further to ensure I take the appropriate steps. Currently, my environment is running *PostgreSQL 15.0*. I understand that version *15.9* contains the fix for CVE-2024-10979, as mentioned in the release notes. Given that I am not using the *PL/Perl* extension in my environment, I wanted to ask: - Is it still mandatory to upgrade specifically to version *15.9*, or would remaining on version *15.0* suffice in this case? I appreciate your guidance on whether this upgrade is necessary, considering the specifics of my setup. Thank you for your time and support. On Fri, 22 Nov 2024 at 09:39, David G. Johnston wrote: > On Thursday, November 21, 2024, Subhash Udata > wrote: >> >> >> Thank you for your response regarding the affected versions of >> PostgreSQL. I have a follow-up question for clarification: >> >> The PostgreSQL documentation mentions that the versions with a fix for >> CVE-2024-10979 are *17.1, 16.5, 15.9, 14.14, 13.17, and 12.21*. However, >> your reply states that any version greater than 13+ should suffice. >> >> Could you please confirm if upgrading to one of the specific versions >> listed above is mandatory, or is it acceptable to upgrade to any version >> higher than 13 >> > > It was literally just reported and fixed. If you are on a supported > release of PostgreSQL you have the fix. If you are not, you don=E2=80=99= t. > > At this point only major versions 13+ are supported. > > Upgrading to an unsupported minor release is never recommended. > > The fact you are on version 11 means you should not expect an answer to > the question whether this newly discovered CVE affects you - that would b= e > expecting support for a long-unsupported version. > > Which of the 5 currently supported releases you should upgrade to is a > decision you need to make given your circumstances. > > David J. > > --0000000000001e68c4062778dcb6 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable

Thank you for your detailed response. I would like to c= larify my situation further to ensure I take the appropriate steps.

C= urrently, my environment is running PostgreSQL 15.0. I und= erstand that version 15.9 contains the fix for CVE-2024-10= 979, as mentioned in the release notes.

Given that I am not using the= PL/Perl extension in my environment, I wanted to ask:

=
  • Is it still mandatory to upgrade specifically to version 15= .9, or would remaining on version 15.0 suffice in= this case?

I appreciate your guidance on whether this upgrade = is necessary, considering the specifics of my setup.

Thank you for yo= ur time and support.


On Fri, 22 Nov 2024 at 09:39, David G. Johnston <= ;david.g.johnston@gmail.com> wrote:
On= Thursday, November 21, 2024, Subhash Udata <subhashudata@gmail.com> wrote:


Thank = you for your response regarding the affected versions of PostgreSQL. I have= a follow-up question for clarification:

The PostgreSQL documentation= mentions that the versions with a fix for CVE-2024-10979 are 17.1,= 16.5, 15.9, 14.14, 13.17, and 12.21. However, your reply states t= hat any version greater than 13+ should suffice.

Could you please con= firm if upgrading to one of the specific versions listed above is mandatory= , or is it acceptable to upgrade to any version higher than 13


It was literally just reported and fixed.=C2= =A0 If you are on a supported release of PostgreSQL you have the fix.=C2=A0= If you are not, you don=E2=80=99t.

At this point = only major versions 13+ are supported.

Upgrading t= o an unsupported minor release is never recommended.

The fact you are on version 11 means you should not expect an answer to = the question whether this newly discovered CVE affects you - that would be = expecting support for a long-unsupported version.

= Which of the 5 currently supported releases you should upgrade to is a deci= sion you need to make given your circumstances.

Da= vid J.
=C2=A0
--0000000000001e68c4062778dcb6--