public inbox for [email protected]
help / color / mirror / Atom feedFrom: Daniel Gustafsson <[email protected]>
To: Moore, David A <[email protected]>
Cc: [email protected] <[email protected]>
Cc: LeMaster, James C <[email protected]>
Cc: Gause Jr, George <[email protected]>
Subject: Re: Hash Value for Updated POSTGRESQL?
Date: Tue, 18 Feb 2025 12:49:21 +0100
Message-ID: <[email protected]> (raw)
In-Reply-To: <PH8PR09MB9833528FB0652B092226E53C93FE2@PH8PR09MB9833.namprd09.prod.outlook.com>
References: <PH8PR09MB9833528FB0652B092226E53C93FE2@PH8PR09MB9833.namprd09.prod.outlook.com>
> On 14 Feb 2025, at 20:33, Moore, David A <[email protected]> wrote:
>
> Hello, We are a NERC regulated organization in the critical infrastructure arena. The most recent zero-day injection bug (CVE-2025-1094) has us concerned. We are attempting to update our postgresql, which has several dependencies in our organization. We are failing to find a md5 to verify authenticity and perform an integrity check on the installation file. I have researched this and finding nothing on this topic except for other orgs finding the same issues. Can you please advise us on this and any method of verification that you may provide that will satisfy our stringent compliance requirements?
First of all, you are emailing the discussion list for the postgres ODBC driver
but reading your email I'm fairly sure you mean the postgres server and not the
ODBC driver.
Regarding package signatures, the postgres project only offers source core
downloads and for those hash fingerprints are available. See for example the
17.3 version:
https://www.postgresql.org/ftp/source/v17.3/
If you download a pre-built package or installer you need to check with whom it
is you are downloading from.
--
Daniel Gustafsson
view thread (3+ messages) latest in thread
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: [email protected]
Cc: [email protected], [email protected], [email protected], [email protected]
Subject: Re: Hash Value for Updated POSTGRESQL?
In-Reply-To: <[email protected]>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox