Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1tELWg-006qF4-BH for pgsql-general@arkaria.postgresql.org; Fri, 22 Nov 2024 04:44:14 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1tELWe-004zPK-Ou for pgsql-general@arkaria.postgresql.org; Fri, 22 Nov 2024 04:44:12 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1tELWe-004zPC-EO for pgsql-general@lists.postgresql.org; Fri, 22 Nov 2024 04:44:12 +0000 Received: from fhigh-a2-smtp.messagingengine.com ([103.168.172.153]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1tELWb-003ABK-Bb for pgsql-general@lists.postgresql.org; Fri, 22 Nov 2024 04:44:10 +0000 Received: from phl-compute-02.internal (phl-compute-02.phl.internal [10.202.2.42]) by mailfhigh.phl.internal (Postfix) with ESMTP id BE83211400F7; Thu, 21 Nov 2024 23:44:08 -0500 (EST) Received: from phl-mailfrontend-01 ([10.202.2.162]) by phl-compute-02.internal (MEProxy); Thu, 21 Nov 2024 23:44:08 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=aklaver.com; h= cc:cc:content-transfer-encoding:content-type:content-type:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to; s=fm3; t=1732250648; x=1732337048; bh=cUqYeWaZP3MfLK1d94KISOya+0bd3TeyTJww33wt2vo=; b= bahIv49AthsUMLH7TnJ4U21TZN2ScXcM3AllAQW680U8SDQzxavUuQHqt/U7hETC +sr+BWgabY+tifI5ogkC/1ONJSu7j17bkvdlGuYfxudi6up4OgPnGsc/QCJ0tpNK JlNKrFf+r8c/TzNSrTVWRXq5+OYU2TfNqK53y4Bmo7eHSUCnnRvvPx+4XrQMsnET YmuUmbyvCMn7ma0jPG/4eqUnQCZeCl/CufU3fZnX8eKO/Vpf7C3eChInV5R2t+jn 5UcW1tR/C6fAXc8ewnxqsoKSs/76mJOuuVx2SyfsLGm6pBIxYYMv3i7O1gE9qQNz UvpT55dgWgohdqgl/e7wqQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:content-type:date:date:feedback-id:feedback-id :from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm1; t=1732250648; x= 1732337048; bh=cUqYeWaZP3MfLK1d94KISOya+0bd3TeyTJww33wt2vo=; b=i SBUhUTRdPiySexCmOMCfsGC4IHb0PnCsZBS5qRYciDQb/0MRr0+HH4HrBBL64GCu fKtIMlKL1ELlBBtoYVowuLgN4A/qnMXq/lAwncRCIs28pDC+PAhyTLC5CgfXf59a DBzJXu1JEF+3mucuum+NNa4INAPwYME/XzqgsxZNtzAPF518PvN0tlXDrZj96yGY k+AvWuyXap/wqw2bu8hwLZTuuwmbHlSmqassKdaqkW45CuOo09U9Vs05vH/YX1Mk KyYly3IC+c8Vl/H2t4W0yUPbKaQ2EabxWd1FLYOwjSelDFfaPOrjifFRepVnVjS/ WNJZUuXN74a3NjCKWlbAA== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefuddrfeejgdejgecutefuodetggdotefrodftvf curfhrohhfihhlvgemucfhrghsthforghilhdpggftfghnshhusghstghrihgsvgdpuffr tefokffrpgfnqfghnecuuegrihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnth hsucdlqddutddtmdenucfjughrpefkffggfgfuvfevfhfhjggtgfesthekredttddvjeen ucfhrhhomheptegurhhirghnucfmlhgrvhgvrhcuoegrughrihgrnhdrkhhlrghvvghrse grkhhlrghvvghrrdgtohhmqeenucggtffrrghtthgvrhhnpeefgeefieeutdfggfetgefg heekjeehteeileeigfetieekjedvieeviefgheevtdenucevlhhushhtvghrufhiiigvpe dtnecurfgrrhgrmhepmhgrihhlfhhrohhmpegrughrihgrnhdrkhhlrghvvghrsegrkhhl rghvvghrrdgtohhmpdhnsggprhgtphhtthhopeegpdhmohguvgepshhmthhpohhuthdprh gtphhtthhopehsuhgshhgrshhhuhgurghtrgesghhmrghilhdrtghomhdprhgtphhtthho pegurghvihgurdhgrdhjohhhnhhsthhonhesghhmrghilhdrtghomhdprhgtphhtthhope hmhihshihlphhhsehgmhgrihhlrdgtohhmpdhrtghpthhtohepphhgshhqlhdqghgvnhgv rhgrlheslhhishhtshdrphhoshhtghhrvghsqhhlrdhorhhg X-ME-Proxy: Feedback-ID: i76984098:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Thu, 21 Nov 2024 23:44:07 -0500 (EST) Message-ID: Date: Thu, 21 Nov 2024 20:44:07 -0800 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10 To: Subhash Udata , "David G. Johnston" Cc: =?UTF-8?B?6rmA7KO87Jew?= , "pgsql-general@lists.postgresql.org" References: <7b5846ac-c16e-48d3-b548-99a772a528c5@aklaver.com> Content-Language: en-US From: Adrian Klaver In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk On 11/21/24 20:31, Subhash Udata wrote: > Thank you for your detailed response. I would like to clarify my > situation further to ensure I take the appropriate steps. > > Currently, my environment is running *PostgreSQL 15.0*. I understand > that version *15.9* contains the fix for CVE-2024-10979, as mentioned in > the release notes. Whoa, I thought the topic of discussion from your first post and the email subject was: "I am currently using PostgreSQL 11.10 and would like to know if the CVE-2024-10979 vulnerability affects this version." > > Given that I am not using the *PL/Perl* extension in my environment, I > wanted to ask: > > * Is it still mandatory to upgrade specifically to version *15.9*, or > would remaining on version *15.0* suffice in this case? > > I appreciate your guidance on whether this upgrade is necessary, > considering the specifics of my setup. The upgrades fixed more then this issue, so yes you should upgrade for all the reasons listed in the release notes for 15.1 to 15.10. > > Thank you for your time and support. > > > On Fri, 22 Nov 2024 at 09:39, David G. Johnston > > wrote: > > On Thursday, November 21, 2024, Subhash Udata > > wrote: > > > Thank you for your response regarding the affected versions of > PostgreSQL. I have a follow-up question for clarification: > > The PostgreSQL documentation mentions that the versions with a > fix for CVE-2024-10979 are *17.1, 16.5, 15.9, 14.14, 13.17, and > 12.21*. However, your reply states that any version greater than > 13+ should suffice. > > Could you please confirm if upgrading to one of the specific > versions listed above is mandatory, or is it acceptable to > upgrade to any version higher than 13 > > > It was literally just reported and fixed.  If you are on a supported > release of PostgreSQL you have the fix.  If you are not, you don’t. > > At this point only major versions 13+ are supported. > > Upgrading to an unsupported minor release is never recommended. > > The fact you are on version 11 means you should not expect an answer > to the question whether this newly discovered CVE affects you - that > would be expecting support for a long-unsupported version. > > Which of the 5 currently supported releases you should upgrade to is > a decision you need to make given your circumstances. > > David J. > -- Adrian Klaver adrian.klaver@aklaver.com