Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1tEKzF-006nPO-1E for pgsql-general@arkaria.postgresql.org; Fri, 22 Nov 2024 04:09:41 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1tEKzD-004auP-Bl for pgsql-general@arkaria.postgresql.org; Fri, 22 Nov 2024 04:09:39 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1tEKzD-004auH-0u for pgsql-general@lists.postgresql.org; Fri, 22 Nov 2024 04:09:39 +0000 Received: from mail-oa1-x34.google.com ([2001:4860:4864:20::34]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.94.2) (envelope-from ) id 1tEKz6-0039wr-HQ for pgsql-general@lists.postgresql.org; Fri, 22 Nov 2024 04:09:37 +0000 Received: by mail-oa1-x34.google.com with SMTP id 586e51a60fabf-297078d8eaeso990829fac.1 for ; Thu, 21 Nov 2024 20:09:32 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1732248572; x=1732853372; darn=lists.postgresql.org; h=cc:to:subject:message-id:date:from:references:in-reply-to :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=6jxp9BYCEL1O3ketrjU49ABDJVmSV76gHLgD7JMZaTo=; b=jRJi/fEBrYIEwmsaoXQ3PheM3sowr36bq7XmRWn2LeOWqcJjeD2bshel/g9AEkAkGy msobajbXnzMUJ1NbiP1u4FlY12cUgzun8BN+1gjl814AlnhQMNSt7DJ5ZdN/UFZN7nNW /vg/V3/AtetgywtThuTgIWDhWVV2pgbYm1fONwy51cvrUnujPA5HyuXmDpAvZ2LQmhNR DOT229SCuVJQEL0C/kv6Q6k1SWI7yInnCyijhBwDvHHfG4mGctL3GBSqUkbh+YdHzLJe +ymyL6Ek6Qkv3KV20skQKwBSPucotogl0QZ/qgf9ZX7TzLhg6z3Wwrax5Mn5n6xO6CDh rcuA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1732248572; x=1732853372; h=cc:to:subject:message-id:date:from:references:in-reply-to :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=6jxp9BYCEL1O3ketrjU49ABDJVmSV76gHLgD7JMZaTo=; b=Vr95u7VOlOoEouJsC1lxvCU7QLSxxW72ph3reBtd2UMFrX7YN+Z0onL+V5eOMwCLdw SVaKj7znBkQPSl7Zx/tphpTLrYRPRkPE5dLAqopIhAo0Mt8XpU7cTF/7gGf/3E4wBobf q2SCCgZSsAs0ZIIFuTZ5hBsvDRerayRtUa5R0EkHX+KKLFazmi/OL+4ReUHtUSyWR/Oy lvAQirmRqiJDYojSx0pGTvMg3DCkIWiFe46zbqYPw5+49hbUpc5RETmZKpJW4ejcBsOZ GRny/8htcDpNYQpiqfBI5xqQp33lvZn5xzIAwVDgAGSkNcBmE12221bHm6dBLzLVV0Lp EaVg== X-Forwarded-Encrypted: i=1; AJvYcCVSzB47d1dMtueBS/cQF4k1eQH37qp7Hfqdi6naVsZxBbvYhTinPxTKtdxdNbIDz4sv82MpUTMPl+N/MPUN@lists.postgresql.org X-Gm-Message-State: AOJu0Yx3/FZyEwnl04M5HsZMbI/ht4dyGFOpk3BEzKj/SpH23C/vDJuT QOKvv08dULR52Hhcs3xvfyNtrcV5+JeKIRYDg3qLwWp89w363gl8N7lONv+MEKBQL1jNo5hNIAQ KCqE3DBdHp5DCtC8DkzaqlQRdZi8= X-Gm-Gg: ASbGncv3npEYdpyAcmgklM5iiJ9DcMkdF32KEWt5IqD7w1KifX39yfZgalOdSCZiopC SBIrFnHICu1+eBvZi4QbUdVVC2ZzDoCk= X-Google-Smtp-Source: AGHT+IFxWhJWII9VDHZHGaGe/8elquc7abTd5FDyY/LvebTSsbXOe7t/xyHvFBAZ0Iw0sa2im/jEPVbfjDg8T+4HgAs= X-Received: by 2002:a05:6870:f14b:b0:295:f00e:d4e5 with SMTP id 586e51a60fabf-29720f627c9mr1346752fac.36.1732248571853; Thu, 21 Nov 2024 20:09:31 -0800 (PST) MIME-Version: 1.0 Received: by 2002:a8a:5fc:0:b0:56c:c9af:3ee6 with HTTP; Thu, 21 Nov 2024 20:09:31 -0800 (PST) In-Reply-To: References: <7b5846ac-c16e-48d3-b548-99a772a528c5@aklaver.com> From: "David G. Johnston" Date: Thu, 21 Nov 2024 21:09:31 -0700 Message-ID: Subject: CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10 To: Subhash Udata Cc: Adrian Klaver , =?UTF-8?B?6rmA7KO87Jew?= , "pgsql-general@lists.postgresql.org" Content-Type: multipart/alternative; boundary="000000000000c9c5950627788c21" List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk --000000000000c9c5950627788c21 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Thursday, November 21, 2024, Subhash Udata wrote: > > > Thank you for your response regarding the affected versions of PostgreSQL= . > I have a follow-up question for clarification: > > The PostgreSQL documentation mentions that the versions with a fix for > CVE-2024-10979 are *17.1, 16.5, 15.9, 14.14, 13.17, and 12.21*. However, > your reply states that any version greater than 13+ should suffice. > > Could you please confirm if upgrading to one of the specific versions > listed above is mandatory, or is it acceptable to upgrade to any version > higher than 13 > It was literally just reported and fixed. If you are on a supported release of PostgreSQL you have the fix. If you are not, you don=E2=80=99t. At this point only major versions 13+ are supported. Upgrading to an unsupported minor release is never recommended. The fact you are on version 11 means you should not expect an answer to the question whether this newly discovered CVE affects you - that would be expecting support for a long-unsupported version. Which of the 5 currently supported releases you should upgrade to is a decision you need to make given your circumstances. David J. --000000000000c9c5950627788c21 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Thursday, November 21, 2024, Subhash Udata <subhashudata@gmail.com> wrote:


Thank you for your resp= onse regarding the affected versions of PostgreSQL. I have a follow-up ques= tion for clarification:

The PostgreSQL documentation mentions that th= e versions with a fix for CVE-2024-10979 are 17.1, 16.5, 15.9, 14.1= 4, 13.17, and 12.21. However, your reply states that any version g= reater than 13+ should suffice.

Could you please confirm if upgrading= to one of the specific versions listed above is mandatory, or is it accept= able to upgrade to any version higher than 13

It was literally just reported and fixed.=C2=A0 If you are on = a supported release of PostgreSQL you have the fix.=C2=A0 If you are not, y= ou don=E2=80=99t.

At this point only major version= s 13+ are supported.

Upgrading to an unsupported m= inor release is never recommended.

The fact you ar= e on version 11 means you should not expect an answer to the question wheth= er this newly discovered CVE affects you - that would be expecting support = for a long-unsupported version.

Which of the 5 cur= rently supported releases you should upgrade to is a decision you need to m= ake given your circumstances.

David J.
= =C2=A0
--000000000000c9c5950627788c21--