Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1tq5pK-00Gt79-Eu for pgsql-performance@arkaria.postgresql.org; Thu, 06 Mar 2025 07:39:30 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1tq5pI-001jf0-Km for pgsql-performance@arkaria.postgresql.org; Thu, 06 Mar 2025 07:39:28 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1tq5pI-001jer-62 for pgsql-performance@lists.postgresql.org; Thu, 06 Mar 2025 07:39:28 +0000 Received: from mx0a-001c1302.pphosted.com ([205.220.168.87]) by magus.postgresql.org with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1tq5pD-001FwN-0L for pgsql-performance@lists.postgresql.org; Thu, 06 Mar 2025 07:39:26 +0000 Received: from pps.filterd (m0279004.ppops.net [127.0.0.1]) by mx0b-001c1302.pphosted.com (8.18.1.2/8.18.1.2) with ESMTP id 5265FUkZ012271 for ; Thu, 6 Mar 2025 07:39:21 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bmc.com; h=cc :content-transfer-encoding:content-type:date:from:message-id :mime-version:subject:to; s=dkim202204; bh=0DzeV7booLpbeBX87SsTm 9DImCOiJmXRm17jAJ4OrEo=; b=Yd/WM7yIJ6H+E89Z0x5gT3uBJ3/J72PzmZy+b Zk384axyokWCKrvOBoU5pIHyVlvvyFXCNYyTkhf2bwmXONH4G97AwGfApys/uQfy oBViGXxnf8Yf2wqWQSNhMPjlbupvECjhDKo3Jhbs4Suyl8A8HlSDD9Dq2fUyL2F3 DUELFHDwaEy0Ekrk+EffJlZ6adCUX/pgOjocueGSJSWi8LpD9X9NLlKJf9n7KQ80 dUtCPVpoiDygJ+XqcCj0pgG8UWfzCJRrrusQyRn57/XBMEWHois5yf176PLkvHbC gF+r7y90MZCTWtIQIZNseUOvUo7S12f0z0QPN91Awh+ZZeGpw== Received: from bl0pr05cu006.outbound.protection.outlook.com (mail-BL0PR05CU006.outbound1701.protection.outlook.com [40.93.2.8]) by mx0b-001c1302.pphosted.com (PPS) with ESMTPS id 453tn6v9m2-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Thu, 06 Mar 2025 07:39:20 +0000 (GMT) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=FdXP02kAaqbUj9z5g/mUeFWB7JC6Tu4iOj1UjssYF1/AcpO0T7ngRTROrdo42IzW6FFeYhJSIpdj6XFYn22NCsadwVGXXwc/RDSh5+BC7VtV7UQCdQGUwJWIgMvOk/vlUO0sKVO/AkBoPT10KISybOYxKU397gt+dbSQI05exQsXynoycGqijsNPxYxZ4JGdk5F5/ylzK8626WKTsP9hyEX75kexal68nPr31RGPaVNrZVlvfn0ayA5KgOU2bQy/I5kAmqjHFTDbjs7FnNdNZ1pcBjIxnYAq7g3N8e9938tmj+CYGh0zjESg0mfI3Yk4pWQroF6F4e+g91l6Ws8Y5g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=0DzeV7booLpbeBX87SsTm9DImCOiJmXRm17jAJ4OrEo=; b=ZLSl/5QHvnqQVnbpoFJgn1AYnpG4ChZyPPwm7rJlDvsR6WIiQnw9S+9vehF0SN/eNYcUYsKmDH3+7syyMKQgOWjlD1HMlzH8WZgZrYBmR6wpGH3sK3RvNx7yv6HORmjo7jZ1SbEwYDq4fXyf89A2RYJTSAEeb9v27Zsy3KmaCTLY7IMtRuOXj5fkq7EJkyQhtTtIot7zbKJ+5+V0iQP9879mhhBMeyHEbltfYRW2EHRMvZfONA+hS4ytkPLVUSabtO61rNclCZmJM/sKWo9wCXEuUvrwV/DY5gHW0GcoasGGTvVVevkbS2M/rKi9fzPrjFnTYn6lHoze9jMiL1flnA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=bmc.com; dmarc=pass action=none header.from=bmc.com; dkim=pass header.d=bmc.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bmcsoftware.onmicrosoft.com; s=selector2-bmcsoftware-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=0DzeV7booLpbeBX87SsTm9DImCOiJmXRm17jAJ4OrEo=; b=RuF5/PgAKFmZ+wYphEdTO9iBrYfOQPAoeD0SYKxEY819q6aH8BDs34qEC6u5k/UdPFkcmxcyVTR0NitViY6fhNy1mSCWdQT3ZFFCAPUO/7xnIlSykzQRUOlTrntJg8+0lV3ZzCj1ln9beL00+pbUCTemOADks/bG52hPe4hKw7A= Received: from SA1PR02MB9698.namprd02.prod.outlook.com (2603:10b6:806:385::11) by BL3PR02MB8052.namprd02.prod.outlook.com (2603:10b6:208:35b::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8511.16; Thu, 6 Mar 2025 07:39:18 +0000 Received: from SA1PR02MB9698.namprd02.prod.outlook.com ([fe80::4ced:9ced:d904:1b01]) by SA1PR02MB9698.namprd02.prod.outlook.com ([fe80::4ced:9ced:d904:1b01%6]) with mapi id 15.20.8511.015; Thu, 6 Mar 2025 07:39:18 +0000 From: "Abraham, Danny" To: "pgsql-performance@lists.postgresql.org" CC: "Abraham, Danny" Subject: Asking for OK for a nasty trick to resolve PG CVE-2025-1094 i Thread-Topic: Asking for OK for a nasty trick to resolve PG CVE-2025-1094 i Thread-Index: AduOaq+oBG+0sgRgSkednXepiY1Y/A== Date: Thu, 6 Mar 2025 07:39:17 +0000 Message-ID: Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-ms-publictraffictype: Email x-ms-traffictypediagnostic: SA1PR02MB9698:EE_|BL3PR02MB8052:EE_ x-ms-office365-filtering-correlation-id: b47f212a-decc-42b0-4ecb-08dd5c820080 x-ms-exchange-senderadcheck: 1 x-ms-exchange-antispam-relay: 0 x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|376014|366016|38070700018; x-microsoft-antispam-message-info: =?us-ascii?Q?S/qJlCKoNIdbwEheWmuLx0zWIn3xKiA2RnYpsQwadN5XT1ZrzkmquQgCTqfH?= =?us-ascii?Q?qUIo2QDLQVrPG6KBN0k6AizgBWTZ3pi7ZG7nXuYeyrOE6ezpOGcKY/MCByOU?= =?us-ascii?Q?Lnz4Z4K9bo8k1VacnE4VWa4yKZQwrmvSTmkdS3ehuZgZ/Ao1hCkKkp6QwidQ?= =?us-ascii?Q?ebo5IntBcoR5W8HlHxpcf+48ANjFTL9CAviBNr1k+lVBP2XNKAhzoww6httG?= =?us-ascii?Q?e0RGHN09qn3yBAExn0PoJGPt7l7ABwCfhTrTeQMsDA5e4zpZ6mc91OK+zxCz?= =?us-ascii?Q?wg8mCwEhGMwy0xU3XwTZD7e0OLBti/sqxrKPvAzs+RtDDvxushzLf8GtiXoc?= =?us-ascii?Q?TesZ/m+fqGjULzdpeozEaFtbh1xg7K/E+QRVRn6dGkxraN8Ikj9cH3J3b+Sk?= =?us-ascii?Q?poXuHkiUPCjfzQ99mUBaoTpB7tIaJ5b2v3QWcUkVWj8yPbdT43Vp8RyZ1ALD?= =?us-ascii?Q?dt9N/ilCcxhheZKNcmNkicqOsz0j4M8oSGUuuy3LXWX/wDIuHYLMiY0DkZa2?= =?us-ascii?Q?jX0zIsC9lJwcCfBshw+7Sqch+OLcssHLdOL3c2y2+3+cbWfVy2NEcq1ipspu?= =?us-ascii?Q?39XoUnqpX5q0k77e1rU2AB+ZWReIOdKtbdz8JHIkOqU76mizouSrIGlYD1g9?= =?us-ascii?Q?BvqiKLnD0PqNjc3YFyVOvFK4X2D321qv2nU5SzrixpKowKbByaw9vkfmvn40?= =?us-ascii?Q?ejVEz7QCY2Q46zJrp9UIiY9WGR+1RaYnj92E639OfdQijd8VtLukfK3vJQdw?= =?us-ascii?Q?BGCVTJHYbnDHuHdG8PXMu/n6YPFa3pcU/Pa5im+0OtxFhEvxL/Bnte3liOLl?= =?us-ascii?Q?Urw8WSHIOJuuM3c35O/YLkskI/MS0rQKiZ+wngbm9aEufOW5ci0LwxCZTM84?= =?us-ascii?Q?t8KIwjP3CscHv/eu1jQsSPR/joq3NVnW822URzcCODE1QmFe6AUJKrfgd5Ea?= =?us-ascii?Q?fsxR/pAM+oBy4K+nLKR7Vs2dtSzlzIGu7vbkp6/lH4cYa8JlMFOUv4FPLypE?= =?us-ascii?Q?neLRoa5cYO1Tq8HYo5N/xOdcCazI7MkjIOeHsmyvyw73lTQaKxast++wArK5?= =?us-ascii?Q?LSmJo9s1rTPjMAREp+WIqS7s97OmcJj70tlR2lkJhZoQu40EEWLmcfh6GLeL?= =?us-ascii?Q?jXsIxID2lPHRm/Nb+2+jE8QeDRRiJXess3kIPs6bCMUeD5ESzT/JXBVf24YW?= =?us-ascii?Q?tzJPMDLwUJkL6+hzaoUCVriB/0eWpjdrSEvrEZmP8pEjTqCFYh4VIe9BxXwy?= =?us-ascii?Q?YlQNTF5TvTd6eWuWyX9i5v8kg+aVD7Jg9doQxPBQzl7OTsg2jYTaC8biKJvm?= =?us-ascii?Q?ZTETyHGovgbfBSRTzjTlIXenx0T/NfcBKGxcisgvXjypFpJMaECQw4pvI3FV?= =?us-ascii?Q?O21hKPXCssIkUOA9N+Kn0KidshLL8W6b2WZqnH0cCm+SWg0KVFCNbXJJb63/?= =?us-ascii?Q?uLCxHSxS92SDrM7J0zZ2CY1soe8XQkDy?= x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:SA1PR02MB9698.namprd02.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(376014)(366016)(38070700018);DIR:OUT;SFP:1101; x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?us-ascii?Q?GUBebIDbtPPWqLpFV5iqY8oBi2X/27ejcBmD/MdonpTTZrU4z1MMzsjFuCWL?= =?us-ascii?Q?1x0A06z9UcFjryuS3oc2vu0QxvlD8MtrXtOWAcwnb4oKFgG6wlavVZoOf6Up?= =?us-ascii?Q?RWbumVfyJIlkhettTV795PMz3j/IkmW+kXz8bp4cXd0zAneQqRec2qckbJMu?= =?us-ascii?Q?XzSG4StN3kce6TfmENJycyNFRoTnxDGJ042bNy6zZLm9oH1VTRJhkiHg6h8b?= =?us-ascii?Q?nS4JiNcCRaXJ3tuH0V/x4KjO3exXiCZ9CKFymj1J05x8Zlg83bj9mqufwbmy?= =?us-ascii?Q?1kz7mdN8OlNeCu/YtUCKh+A0lRzRrMAI4iSoFlr4YHG41XrlNgIK2dfbrS0V?= =?us-ascii?Q?qXl05ZM8wWaj405QBVi0aeIhmTNWgYnRU1Vmx1fYSKm0ZUw/iBalQ/ark1Vv?= =?us-ascii?Q?Y0l/iJezKfaQnMMXjd/L0WSchYUJWjksEbTsGJYkE6y/aR3mB7KcE4Gwc/XE?= =?us-ascii?Q?ludv7v8EqAALZnLn1aFLOcSJ7G595Cbm+3DMxjY2X8W42w2JRdWBHVBuAlUy?= =?us-ascii?Q?0IwSfPaSgMWBebPmhNakA4tq+rSPNb58FPp4lefFjoAFPPP5sQsFgGp+kML7?= =?us-ascii?Q?y+JQ6St9yJWKPnQEHQ/TOjXmxk5vrtzEjkhjD5B6EfdhICAnNcBKxlcGJF6n?= =?us-ascii?Q?9fiHFHIjqQQJ8lMCcmQUU5pczbu7gx07D6daeEEb6KvAeciIE1hph7siqUff?= =?us-ascii?Q?7GU5Q7fSpOgahLOMlluICRCUauA9nOZ0wUBkDI8GEejBD5cnuoINBDCd3A5Q?= =?us-ascii?Q?77KiGtPOOS4VAcSHzVaLH5Q8g4JhqQFbl4X5mNC7KulAU1J4iG0eJV/2Mbns?= =?us-ascii?Q?gqZ1H/z85HJQWw7wROXW+MNvH2ymfgxFx5NSd4vE16YW3vipiGDX2gsZlf3S?= =?us-ascii?Q?Q4MRt7esozNds8BxpRvcbwo5xTcnDfIUpZp5i6emtehJWAdnE7VmRQ4Txu+E?= =?us-ascii?Q?veB8ijcFpl52ZIFpJOElsLyNQl9K6zGhgo802a4zgQKd7/Ud+cDrR5VIo/hc?= =?us-ascii?Q?t1G9K283zrGoZq7rGTELBCkeVeQvcauV82UCAUK1GtzPsmwdQoYesURadXuR?= =?us-ascii?Q?vgjXz0CzuH1v2l4l7VsopNT81x+3faC5+nSi7w3iwaxKipF4XBjX3wqWsYUP?= =?us-ascii?Q?nvZA4w9pWp99GrSaGsujLxDE+ETINWe3Kic0xhywYN0a9JfF4k1gM42r34iy?= =?us-ascii?Q?5OpJlO0nPPzG3DyPss0+W3usePyZYNbKxkDPqw49C5w8JdY/GbnXoOnyDCuF?= =?us-ascii?Q?AHJcsQbXskmLfkIO1xBLmxVUTkVbp8OuId+pATg40MsucCO+creyvYIOX0Us?= =?us-ascii?Q?EWJi+dkRBAn7kwc6nCv3aUxy8dTe6hhg0PDEsnlAslgiOQ6RsBmNjjbjNCNo?= =?us-ascii?Q?4jX1+rqfznQlj5DRGHUGKJrtWp6x1eOncB5KEdeBEDdXS9kmecQzBExqf9yt?= =?us-ascii?Q?xhm4stMSc9vXe8A/+k9x3tAvuhRWQAJdBYVXuga60MgokVRaS5gtuG3MBQpE?= =?us-ascii?Q?VmiMzzVET/wOJFLXHQPBFViHKHYMmxa291VHtZCVSGRd8amVyK4v9iNZevqb?= =?us-ascii?Q?wiQcNyosEws8xtDUkpc=3D?= Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-OriginatorOrg: bmc.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: SA1PR02MB9698.namprd02.prod.outlook.com X-MS-Exchange-CrossTenant-Network-Message-Id: b47f212a-decc-42b0-4ecb-08dd5c820080 X-MS-Exchange-CrossTenant-originalarrivaltime: 06 Mar 2025 07:39:18.0035 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 92b796c5-5839-40a6-8dd9-c1fad320c69b X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: 9Vuku684Sg4ZG4LF3/MhZ20eWIbO9hrsqDBCBsRdSdBTlSgneEV53/eOntaJ8SeeH/5uUBnZFT0p0nyv+EiQJA== X-MS-Exchange-Transport-CrossTenantHeadersStamped: BL3PR02MB8052 X-Authority-Analysis: v=2.4 cv=HtmMG1TS c=1 sm=1 tr=0 ts=67c95128 cx=c_pps a=Kq952KYlFoMAqHE57MuLQQ==:117 a=lCpzRmAYbLLaTzLvsPZ7Mbvzbb8=:19 a=wKuvFiaSGQ0qltdbU6+NXLB8nM8=:19 a=Ol13hO9ccFRV9qXi2t6ftBPywas=:19 a=Kqp1oTVpMCRLoH_f:21 a=xqWC_Br6kY4A:10 a=kj9zAlcOel0A:10 a=Vs1iUdzkB0EA:10 a=uF0kXBFlZFoA:10 a=d3EI0Ksnvr7dlnRzR_cA:9 a=CjuIK1q_8ugA:10 a=iFS0Xi_KNk6JYoBecTCZ:22 X-Proofpoint-GUID: oCDbc3ykxeoQvN5--pKr6pwzB_pvXMhm X-Proofpoint-ORIG-GUID: oCDbc3ykxeoQvN5--pKr6pwzB_pvXMhm X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1093,Hydra:6.0.680,FMLib:17.12.68.34 definitions=2025-03-06_03,2025-03-06_01,2024-11-22_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 suspectscore=0 bulkscore=0 spamscore=0 impostorscore=0 clxscore=1011 malwarescore=0 phishscore=0 adultscore=0 mlxlogscore=385 lowpriorityscore=0 mlxscore=0 classifier=spam authscore=0 authtc=n/a authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.19.0-2502100000 definitions=main-2503060056 List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk Hi, I have many customers using PG 15.3 happily, and I cannot just snap upgrade= them all to 15.12. I have tested a nasty trick of replacing PSQL,LIBPQ and several other DLL's= so that I have a PG client 15.12 within the folders of Server 15.3. All working just fine. I plan to ship it as a patch - but would like to hear you opinion on this "= merge". (Of course, the next version will use PG 17.4, so this is just an SOS actio= n). Thanks Danny=20 BMC Software Directory of C:\Users\dbauser\Desktop\15.12 02/20/2025 11:48 AM 4,696,576 libcrypto-3-x64.dll 02/20/2025 11:48 AM 1,850,401 libiconv-2.dll 02/20/2025 11:48 AM 475,769 libintl-9.dll 02/20/2025 11:48 AM 323,584 libpq.dll 02/20/2025 11:48 AM 779,776 libssl-3-x64.dll 02/20/2025 11:48 AM 52,736 libwinpthread-1.dll 02/20/2025 11:48 AM 604,160 psql.exe =3D=3D C:\Program Files\BMC Software\Control-M Server\pgsql\bin>postgres -V postgres (PostgreSQL) 15.3 C:\Program Files\BMC Software\Control-M Server\pgsql\bin>psql -V psql (PostgreSQL) 15.12