Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1tELSW-006pv5-Ex for pgsql-general@arkaria.postgresql.org; Fri, 22 Nov 2024 04:39:56 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1tELSU-004vHU-JV for pgsql-general@arkaria.postgresql.org; Fri, 22 Nov 2024 04:39:54 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1tELSU-004vFh-6b for pgsql-general@lists.postgresql.org; Fri, 22 Nov 2024 04:39:54 +0000 Received: from mail-ot1-x32a.google.com ([2607:f8b0:4864:20::32a]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.94.2) (envelope-from ) id 1tELSR-003DVo-2n for pgsql-general@lists.postgresql.org; Fri, 22 Nov 2024 04:39:53 +0000 Received: by mail-ot1-x32a.google.com with SMTP id 46e09a7af769-71811c7eb8dso932138a34.0 for ; Thu, 21 Nov 2024 20:39:50 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1732250389; x=1732855189; darn=lists.postgresql.org; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :from:to:cc:subject:date:message-id:reply-to; bh=Kr5Lfq6/EXsyBBj0I++/Er++MWO86d1VYy6TIudF6tE=; b=IYDQOSO45SBTKTVeMPvThvefoKqO/QU/ZGEJre1N/1V12hsqQlil0Oobj0/OnVIVLH 1qib7hRU35Bvpt58kWdtBgRL3HkT+SZ3aysstzwSWc4HI4k5lMeaCNNKFFPTjmEFSMC5 Q0SHGeMGgNcNHyRkwZU9sSPU9qYgWKchLjgfgJ5zh4t4NetSHzXvijH7O3jkv2+7QzXJ Iow70+bnPpx4Q3IRUIgTlJqhvNdNpgI6B6PpNEFkkbGY7wHj8MpoRibNnpfnoRHnJ5+i 64moKJHmBTRSC4idMc9Rq4Eh+rhrxDNlSdjGLUHiZhNfsrtK3pzr2YmyafQ1avjr/TMW bzRw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1732250389; x=1732855189; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=Kr5Lfq6/EXsyBBj0I++/Er++MWO86d1VYy6TIudF6tE=; b=GMbSLM7wmgmyAAzsuS5F6gUSLAW+qhmyBoahMuqHsAMYaKdtuVYn5vc2O7E8YlO5Eg rT8Dj9fM6PRE7bJw9CGbLVlEJv7gDe+4cFN9pzHWRb7ZX2jb3m8rn/2CYygGhU8kAWEq 3LbBiP5uCQzRDurYJl7/DMDb+pWUqSR2jEixRv1CphqIezr/9FszQy0N3H476p3VZk0k bgcTlI4qbkIdiQl8SctBULL7V8vZLBXaQubsaw+VVEaZIChjokF4y6Aw5THM8xvQzsrZ 4f2hmHtpfFT1ezVjpe8rDPrtmx4/coae4lKVrEvs6Ut6WQF2GbSV2EtFG7DtmH/5TOWg +J+w== X-Gm-Message-State: AOJu0Yzgfqr+aUgI05G/EFgQ1HGgPfqnn38Ywbp8Pfg/GEEX4qytICs+ 4P7m3+Oc0XY+E9KBSXm0PbYlSnobTEDGs3msUkj0GGMvHg+S+XnM1thK6/XbYB3cSe25Lz52ihX 6A7qIxa4Du1NUiaQqBEHNcMMmY98APwHS X-Gm-Gg: ASbGncs9qkFs9lHybdhy/qwXchGhN7WEybB4cIjSAPRWBiST3leAJkIILwRsWY+bS5G 26Cklda89VM+m+uz57bRqLo4Wwi12h2NNoOELhuPOKFHQYbtnZt7U2lFFJQbwl4X2hQ== X-Google-Smtp-Source: AGHT+IFowzERaMuBFDgCxryUzBRUxpHx5q35EwsSbGlvkWymHYtZwIuqm405geZK1aTe/aoyccoQoQ1psvRSzbusDpw= X-Received: by 2002:a05:6830:84c:b0:718:1793:ecd8 with SMTP id 46e09a7af769-71c04df45d3mr1608914a34.30.1732250389070; Thu, 21 Nov 2024 20:39:49 -0800 (PST) MIME-Version: 1.0 References: <7b5846ac-c16e-48d3-b548-99a772a528c5@aklaver.com> In-Reply-To: From: Ron Johnson Date: Thu, 21 Nov 2024 23:39:38 -0500 Message-ID: Subject: Re: CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10 To: "pgsql-general@lists.postgresql.org" Content-Type: multipart/alternative; boundary="0000000000001a5081062778f965" List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk --0000000000001a5081062778f965 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable 15.0 is missing TWO YEARS of bug fixes. https://www.postgresql.org/docs/release/ And It's your database, not ours. Plus, we aren't the Version Police that knock your head with a billy club if you don't upgrade. Patching takes 10 minutes, and any good DBA will keep his or her systems as patched as his organization will allow. On Thu, Nov 21, 2024 at 11:31=E2=80=AFPM Subhash Udata wrote: > Thank you for your detailed response. I would like to clarify my situatio= n > further to ensure I take the appropriate steps. > > Currently, my environment is running *PostgreSQL 15.0*. I understand that > version *15.9* contains the fix for CVE-2024-10979, as mentioned in the > release notes. > > Given that I am not using the *PL/Perl* extension in my environment, I > wanted to ask: > > - Is it still mandatory to upgrade specifically to version *15.9*, or > would remaining on version *15.0* suffice in this case? > > I appreciate your guidance on whether this upgrade is necessary, > considering the specifics of my setup. > > Thank you for your time and support. > > On Fri, 22 Nov 2024 at 09:39, David G. Johnston < > david.g.johnston@gmail.com> wrote: > >> On Thursday, November 21, 2024, Subhash Udata >> wrote: >>> >>> >>> Thank you for your response regarding the affected versions of >>> PostgreSQL. I have a follow-up question for clarification: >>> >>> The PostgreSQL documentation mentions that the versions with a fix for >>> CVE-2024-10979 are *17.1, 16.5, 15.9, 14.14, 13.17, and 12.21*. >>> However, your reply states that any version greater than 13+ should suf= fice. >>> >>> Could you please confirm if upgrading to one of the specific versions >>> listed above is mandatory, or is it acceptable to upgrade to any versio= n >>> higher than 13 >>> >> >> It was literally just reported and fixed. If you are on a supported >> release of PostgreSQL you have the fix. If you are not, you don=E2=80= =99t. >> >> At this point only major versions 13+ are supported. >> >> Upgrading to an unsupported minor release is never recommended. >> >> The fact you are on version 11 means you should not expect an answer to >> the question whether this newly discovered CVE affects you - that would = be >> expecting support for a long-unsupported version. >> >> Which of the 5 currently supported releases you should upgrade to is a >> decision you need to make given your circumstances. >> >> David J. >> >> > --=20 Death to , and butter sauce. Don't boil me, I'm still alive. lobster! --0000000000001a5081062778f965 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
15.0 is missing TWO YEARS of bug fixes.=C2=A0 https://www.postgresql.o= rg/docs/release/

And It's your datab= ase, not ours.=C2=A0 Plus, we aren't the Version Police that knock your= =C2=A0head with a billy club if you don't upgrade.

=
Patching takes 10 minutes, and any good DBA will keep his or her syste= ms as patched as his organization will allow.

On Thu, Nov 21, 2024 at 11:31=E2=80=AFPM Subhash Udata <subhashudata@gmail.com> wrote:

Thank you for your detailed response. I would like= to clarify my situation further to ensure I take the appropriate steps.

Currently, my environment is running PostgreSQL 15.0. = I understand that version 15.9 contains the fix for CVE-20= 24-10979, as mentioned in the release notes.

Given that I am not usin= g the PL/Perl extension in my environment, I wanted to ask= :

  • Is it still mandatory to upgrade specifically to version 15.9, or would remaining on version 15.0 suffi= ce in this case?

I appreciate your guidance on whether this upg= rade is necessary, considering the specifics of my setup.

Thank you f= or your time and support.


On Fri, 22 Nov 2024 at 09:39, David G. Johnst= on <davi= d.g.johnston@gmail.com> wrote:
On Thursday, November 21, 2024, Subhash Udata <subhashudata@gmail= .com> wrote:


Thank you for your response regarding the affected versio= ns of PostgreSQL. I have a follow-up question for clarification:

The = PostgreSQL documentation mentions that the versions with a fix for CVE-2024= -10979 are 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21. Howe= ver, your reply states that any version greater than 13+ should suffice.

Could you please confirm if upgrading to one of the specific versions l= isted above is mandatory, or is it acceptable to upgrade to any version hig= her than 13


It was literally just= reported and fixed.=C2=A0 If you are on a supported release of PostgreSQL = you have the fix.=C2=A0 If you are not, you don=E2=80=99t.

At this point only major versions 13+ are supported.
Upgrading to an unsupported minor release is never recommended.=

The fact you are on version 11 means you should n= ot expect an answer to the question whether this newly discovered CVE affec= ts you - that would be expecting support for a long-unsupported version.

Which of the 5 currently supported releases you shou= ld upgrade to is a decision you need to make given your circumstances.

David J.
=C2=A0


--
Death to <Redacted>, and butter sauce.Don't boil me, I'm still alive.
<Redacted> lobs= ter!
--0000000000001a5081062778f965--