public inbox for [email protected]help / color / mirror / Atom feed
Hash Value for Updated POSTGRESQL? 3+ messages / 2 participants [nested] [flat]
* Hash Value for Updated POSTGRESQL? @ 2025-02-14 19:33 Moore, David A <[email protected]> 0 siblings, 1 reply; 3+ messages in thread From: Moore, David A @ 2025-02-14 19:33 UTC (permalink / raw) To: pgsql-odbc; +Cc: LeMaster, James C <[email protected]>; Gause Jr, George <[email protected]> Hello, We are a NERC regulated organization in the critical infrastructure arena. The most recent zero-day injection bug (CVE-2025-1094) has us concerned. We are attempting to update our postgresql, which has several dependencies in our organization. We are failing to find a md5 to verify authenticity and perform an integrity check on the installation file. I have researched this and finding nothing on this topic except for other orgs finding the same issues. Can you please advise us on this and any method of verification that you may provide that will satisfy our stringent compliance requirements? David A Moore Senior Network Security Engineer Gainesville Regional Utilities OT System Control [GRULogo] This message and any attachments may contain confidential material and information and are intended only for the use of the intended recipient(s). If you are not the person to whom this message is addressed, be aware that any use, reproduction, or distribution of this message is strictly prohibited. If you received this in error, please contact the sender and immediately delete this email and any attachments. Attachments: [image/jpeg] image001.jpg (4.6K, 3-image001.jpg) download | view image ^ permalink raw reply [nested|flat] 3+ messages in thread
* Re: Hash Value for Updated POSTGRESQL? @ 2025-02-18 11:49 Daniel Gustafsson <[email protected]> parent: Moore, David A <[email protected]> 0 siblings, 1 reply; 3+ messages in thread From: Daniel Gustafsson @ 2025-02-18 11:49 UTC (permalink / raw) To: Moore, David A <[email protected]>; +Cc: pgsql-odbc; LeMaster, James C <[email protected]>; Gause Jr, George <[email protected]> > On 14 Feb 2025, at 20:33, Moore, David A <[email protected]> wrote: > > Hello, We are a NERC regulated organization in the critical infrastructure arena. The most recent zero-day injection bug (CVE-2025-1094) has us concerned. We are attempting to update our postgresql, which has several dependencies in our organization. We are failing to find a md5 to verify authenticity and perform an integrity check on the installation file. I have researched this and finding nothing on this topic except for other orgs finding the same issues. Can you please advise us on this and any method of verification that you may provide that will satisfy our stringent compliance requirements? First of all, you are emailing the discussion list for the postgres ODBC driver but reading your email I'm fairly sure you mean the postgres server and not the ODBC driver. Regarding package signatures, the postgres project only offers source core downloads and for those hash fingerprints are available. See for example the 17.3 version: https://www.postgresql.org/ftp/source/v17.3/ If you download a pre-built package or installer you need to check with whom it is you are downloading from. -- Daniel Gustafsson ^ permalink raw reply [nested|flat] 3+ messages in thread
* Re: [EXTERNAL] Re: Hash Value for Updated POSTGRESQL? @ 2025-02-18 13:07 Moore, David A <[email protected]> parent: Daniel Gustafsson <[email protected]> 0 siblings, 0 replies; 3+ messages in thread From: Moore, David A @ 2025-02-18 13:07 UTC (permalink / raw) To: Daniel Gustafsson <[email protected]>; +Cc: pgsql-odbc Sorry about that David A Moore Senior Network Security Engineer Gainesville Regional Utilities OT System Control This message and any attachments may contain confidential material and information and are intended only for the use of the intended recipient(s). If you are not the person to whom this message is addressed, be aware that any use, reproduction, or distribution of this message is strictly prohibited. If you received this in error, please contact the sender and immediately delete this email and any attachments. From: Daniel Gustafsson <[email protected]> Date: Tuesday, February 18, 2025 at 6:49 AM To: Moore, David A <[email protected]> Cc: [email protected] <[email protected]>, LeMaster, James C <[email protected]>, Gause Jr, George <[email protected]> Subject: [EXTERNAL] Re: Hash Value for Updated POSTGRESQL? > On 14 Feb 2025, at 20:33, Moore, David A <[email protected]> wrote: > > Hello, We are a NERC regulated organization in the critical infrastructure arena. The most recent zero-day injection bug (CVE-2025-1094) has us concerned. We are attempting to update our postgresql, which has several dependencies in our organization. We are failing to find a md5 to verify authenticity and perform an integrity check on the installation file. I have researched this and finding nothing on this topic except for other orgs finding the same issues. Can you please advise us on this and any method of verification that you may provide that will satisfy our stringent compliance requirements? First of all, you are emailing the discussion list for the postgres ODBC driver but reading your email I'm fairly sure you mean the postgres server and not the ODBC driver. Regarding package signatures, the postgres project only offers source core downloads and for those hash fingerprints are available. See for example the 17.3 version: https://www.postgresql.org/ftp/source/v17.3/ If you download a pre-built package or installer you need to check with whom it is you are downloading from. -- Daniel Gustafsson ^ permalink raw reply [nested|flat] 3+ messages in thread
end of thread, other threads:[~2025-02-18 13:07 UTC | newest] Thread overview: 3+ messages (download: mbox mbox.gz follow: Atom feed) -- links below jump to the message on this page -- 2025-02-14 19:33 Hash Value for Updated POSTGRESQL? Moore, David A <[email protected]> 2025-02-18 11:49 ` Daniel Gustafsson <[email protected]> 2025-02-18 13:07 ` Moore, David A <[email protected]>
This inbox is served by agora; see mirroring instructions for how to clone and mirror all data and code used for this inbox