Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1q9RDR-0006eb-K0 for pgsql-odbc@arkaria.postgresql.org; Wed, 14 Jun 2023 14:11:18 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.92) (envelope-from ) id 1q9RDQ-0001zH-Fb for pgsql-odbc@arkaria.postgresql.org; Wed, 14 Jun 2023 14:11:16 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1q9NIn-0004Ws-PS for pgsql-odbc@lists.postgresql.org; Wed, 14 Jun 2023 10:00:34 +0000 Received: from mail-bn7nam10on20720.outbound.protection.outlook.com ([2a01:111:f400:7e8a::720] helo=NAM10-BN7-obe.outbound.protection.outlook.com) by makus.postgresql.org with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1q9NIf-0028YM-MW for pgsql-odbc@postgresql.org; Wed, 14 Jun 2023 10:00:31 +0000 ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=lHoNPHvTi0nTjfL3TtSn+YAxpCkbCv9oszpXF8IWwRheRN7C7OtqPKW2SgNym15x3Hw5Cj058ZBgywytq9qyLbemD+sdm6x4bGW6qC1Ibsht9S/DozXulX3g1HgEn/pneiRMyddlCyJ9OIuaSxzvI2GrrB7BBV0aDTxa/YWrkWnKq22CD6K+afGxQAXe1Go2Jr4sHMX9J2hGAttP9HKS82MMCFZHUwH+Qi4mFOXRqlPdGr+mEOAQ6GVFkeOndT1FB2iU/qehlRqFh5PleXOwCa+zLYsAkZNPIGdd4N1qgizZJrcG/czLMGBeax2VviIA9AQHAELP5tkbh3tDnZQarg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=7skAqrhPPveUt3bs6Tot3TAISceHVZ0iKS4ZWx1KmRI=; b=CsfVIcgbrqdaoe3gbPxxfsTIlBTKV/5WcZC0yEGw0f6QWZmA4SAp7xa7R6V1/a5mXQcFSsqXGqUnHcEKGsE2XY3LsVJv5LprHzDHizTI/2u76rclAnxSH4Or/9V+kxAQfWm7fVC40zWTtsMIZIUreoKiigUDl2GSxSOSorD4ScHdIGNZjqs+S4UBPLWLYzV4g9/weeNT3SmwcdG8iYcnPIvAAHiXtPt53Tx1jj49hWMBMbiB+mESfHtcpFcWEliVTMauN6GcTfK8lZyxF5ZiXQkV/hlA4YpIAEbp/M6bguq45PRQcgTMgkfMUsvHXQDBrF61xnsnci4P9MKCN5VNvg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=solarwinds.com; dmarc=pass action=none header.from=solarwinds.com; dkim=pass header.d=solarwinds.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=solarwinds.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=7skAqrhPPveUt3bs6Tot3TAISceHVZ0iKS4ZWx1KmRI=; b=LMjX8ZjKJ9Gw1iWGepECA535EUMd1W1XUlLLf1YIkWYv8/0XR4+L6pscFxbQHrHe7iudak55dRGiOHn0QI5fj/Gj3Fw5aGAiUwSTBhLTktw+3SNhfZqZHXPBVHOq93uJwZxtHtp8Rpf4ahXEz1Lp9cEdvc7XrUdW0X8jqXsme9Q= Received: from PH0PR11MB5128.namprd11.prod.outlook.com (2603:10b6:510:39::17) by IA1PR11MB7294.namprd11.prod.outlook.com (2603:10b6:208:429::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6455.46; Wed, 14 Jun 2023 10:00:21 +0000 Received: from PH0PR11MB5128.namprd11.prod.outlook.com ([fe80::676d:1c5e:eb53:a855]) by PH0PR11MB5128.namprd11.prod.outlook.com ([fe80::676d:1c5e:eb53:a855%5]) with mapi id 15.20.6477.037; Wed, 14 Jun 2023 10:00:20 +0000 From: Miloslav Zadrazil To: "pgsql-odbc@postgresql.org" Subject: psqlODBC drivers 13.2 flagged to be vulnerable for openssl 1.1.1l vulnerabilities Thread-Topic: psqlODBC drivers 13.2 flagged to be vulnerable for openssl 1.1.1l vulnerabilities Thread-Index: AdmeptvLUNC1qEbAS2GejCUuO2k1KA== Date: Wed, 14 Jun 2023 10:00:20 +0000 Message-ID: Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=solarwinds.com; x-ms-publictraffictype: Email x-ms-traffictypediagnostic: PH0PR11MB5128:EE_|IA1PR11MB7294:EE_ x-ms-office365-filtering-correlation-id: 037b6fc5-01b6-40a6-852a-08db6cbe2a02 x-ms-exchange-senderadcheck: 1 x-ms-exchange-antispam-relay: 0 x-microsoft-antispam: BCL:0; x-microsoft-antispam-message-info: VYFwhMWk8dw2oIaFYVV+W0vcL8GSUQ4mUSQTfMYcxlS+fqYZtUdABlJOjYnN24XsPcaHs3aLgHHkNlCS3D82d2dkcv5vIpbJ2UHjTXgCCwtLjiHcEYcqJ7QK9khSAuPLjpDLQ6WanJ8T9emQ2ql1pWYnDA9aiZO7kEmeviQQbJiq4D/UTtNUMhOGQIuMFOHOLsrqB334c6X1fOewXQbtRexZm/38MpnURQLbLyvCVVlamSgBdZfTfpVx58cBvreIVjupaiTAv8BQ2l2bdzl/s2QDKpnQHjV3SqkJNAr9eijc6dkGu8YGF4q4B+L4igVXzJakXea6ANNWc249aVz+ZfGN6rG6n2cscj3sPlnR2MDKc/S9rOGl9Ato5WKE6hdjAU4lTb8lfd0rBr36ATu9T/Jf5EnjAMw76Rp7k6FO/epQFKoPB6Nv5wHJOxQCIVV+C46Sreaz0JtgF2FdCnxc5ZinauWa2zIkfzwwJD+qEfJmAgVZErjws0GKSUpatd6GnNiierlYwzCDkzvz0wRPAQ5FMo2xu/z34fKMWvrArkNdCdp80t9n+6VVHAANkJQKwqU7Egcg9RSfhbrxm9jvZx+K/t70P+PiR2T/kMG4GDOjVvkSDeabKW6pURUt3FS/ x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PH0PR11MB5128.namprd11.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230028)(4636009)(39860400002)(136003)(346002)(366004)(396003)(376002)(451199021)(71200400001)(7696005)(478600001)(33656002)(26005)(6506007)(186003)(9686003)(83380400001)(38070700005)(38100700002)(86362001)(122000001)(55016003)(76116006)(6916009)(66556008)(66446008)(66476007)(66946007)(316002)(64756008)(9326002)(8936002)(8676002)(52536014)(5660300002)(4744005)(2906002)(41300700001);DIR:OUT;SFP:1102; x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?us-ascii?Q?GwFw9I7poBIvgtP6tKFpcxYNS0cIrG7OoTtqSJkhhfQfQSEC8Odescx88Cnk?= =?us-ascii?Q?HNNw/5+rCNZn5ZI8f5jxwtyldg2NwdwDAoZVi0mla26OYVB2PFGs1N8Qbvx0?= =?us-ascii?Q?RNVAZg3h+6K4Rb5uoR+2lrDAeOmMoqL0gpA2fOcgWk0KgwnzxuSPhUIff0Zk?= =?us-ascii?Q?OVE6mwx/Z5Y0Nd1ubpzb3nFQXZB9A+ZKDJKstKG1nZOHSQze8L9XOO89TCiD?= =?us-ascii?Q?dfGPDaKpuS0HMegsx0jpqpDSohorLuWcLxJvGa9aHCH3b5qrGgN1+vqReVGH?= =?us-ascii?Q?maN9IPiOP93gRO3edj04gRbUAa8ib1V2cOjCZN/iNu9yRtzf1xxfKXO0fo/f?= =?us-ascii?Q?Or+j1PMRMcWvTH3LmBRdYNCeHdHL3+TPEj73TWTKldjslukqgoj5+d4CYP2h?= =?us-ascii?Q?jBI5Y3q/tsiudTwMKWh4Z3yblRGNWygRhVgEagJKiYGw1cIMinEPwrr2f2T4?= =?us-ascii?Q?BcDL7jlqYYLm53aMHkKodOP2e4CkxmZPkTVMvjnIo8XVoBqSRmSHktWqY8GU?= =?us-ascii?Q?EUuS60+ogoq5w18V5GqATxPgIm3Aisy7pdKsiA4PXNlP+APO2ztlqwuudNGy?= =?us-ascii?Q?SWiUz4dSyNpzve+WxYGKOkWalFTR45hOkfm8B5PnGMKY8OTkO+T0gw/Ol2Xa?= =?us-ascii?Q?st62Qb8r1hrPhb8W4gYRdgzipe5YqfqugC2PwiTosOOV6h//wQmBCIE8MLNL?= =?us-ascii?Q?C2AfUf7xJYir6MQQIXaT3zOu9ofHmqbZ4vMqKAg6RxFQ6bRnka8iXDnQDJD+?= =?us-ascii?Q?K1KnO1LVrroP6PKzKoSMCCNzlnKxbs3JSBl+ophJ5C9peGADajSakJthv0l4?= =?us-ascii?Q?LLyx8hXnQUxEx62MM2KtOFO07tr4gTRHLqsKAksrlOb4XbVnk+kuT5dL8P0j?= =?us-ascii?Q?ALup4O8xmC5+lNzQkwDvfSc+wTZIaI4LZiLv0JcFxyTbCJJqTLWWEFWbroFo?= =?us-ascii?Q?tvNp/J6ZEp295gfF++E1yliuApkHiARtXdfudsPaQtjFlppfEmaWLRKph7oF?= =?us-ascii?Q?qfiJaZ3xPjk7g/809NqmBK0dn6o+uPTAYB7EAFWacBgQKgl6yHvrz22uTEkI?= =?us-ascii?Q?nRU1QMMonpZscYoLVWxRz97VhxAt5mf8eFcS9fCOyYV4bhcII/vtouKXTJ8O?= =?us-ascii?Q?tL/22KIFb8E6HVVBeoaqKKW7X7cA7KWAUJOpP1yurT4IVNYuKZ28KrNpie7n?= =?us-ascii?Q?NtKkI5QrFKGWqKRG6929YosZHGQnhQgcs0FLucvCr9AZEqYRikr1Ie1nsQyC?= =?us-ascii?Q?yEWDEE+zokO/5iTgOhx9gM4G3xJVNieky2EB6n3tX+cFFI3LH6LOg0aSvvnN?= =?us-ascii?Q?FbvCDfVCkAedXtVNNt0yFiTsoEMQT5N5v0D4FL0PvkN2AMEa7hwH66sqzpwc?= =?us-ascii?Q?6/riUpnKig1JLtQgPi9nq8c/zwDmFVLH+7zTy03dGj4C6oOO0NXUXmHXC32r?= =?us-ascii?Q?nUamyk4TsB6Waoa3IEW+V7y+TmLL5WVkJkxutTzh0g/oPFYkrpRyMQCRyOay?= =?us-ascii?Q?yjcRktni7YggFdovOUuyDCwHmSlc0boEknLLlo/g/dr+nA4EEP2iyZOyKooQ?= =?us-ascii?Q?3+p2Ts265d6k2OXyFiimWF1KcVzLrhKASfHWsoJaA/5L+WImizrdprR1PYTl?= =?us-ascii?Q?wg=3D=3D?= Content-Type: multipart/alternative; boundary="_000_PH0PR11MB512834ECFC2C76179FF5F68A835AAPH0PR11MB5128namp_" MIME-Version: 1.0 X-OriginatorOrg: solarwinds.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: PH0PR11MB5128.namprd11.prod.outlook.com X-MS-Exchange-CrossTenant-Network-Message-Id: 037b6fc5-01b6-40a6-852a-08db6cbe2a02 X-MS-Exchange-CrossTenant-originalarrivaltime: 14 Jun 2023 10:00:20.6856 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 83f3a6e1-0470-4e13-984f-16a25372914c X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: NgYgLJrxf3t/n6dU5SV+GznsR4G4D+CWs8hTTw8lH4+F9wm2LZlY1xk+h/kkM9oUDZ/Kbdf3ZD+oY0kY/DvgBNzpjMawCixEhgd2SVJxGRs4vZplQFzY6mrw6y8JnYF+ X-MS-Exchange-Transport-CrossTenantHeadersStamped: IA1PR11MB7294 List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk --_000_PH0PR11MB512834ECFC2C76179FF5F68A835AAPH0PR11MB5128namp_ Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Hello, We use your ODBC drivers in our product. During security scans we have rece= ived warning related to content of psqlODBC 13.2 driver package. It is flagged to contains OpenSSL 1.1.1lversion vulnerable for CVE-2021-416= 0, CVE-2022-0778, CVE-2022-2097, CVE-2022-4304, CVE-2022-4450, CVE-2023-021= 5, CVE-2023-0286 exposures. We must deliver vulnerability analysis to our customers. Can you, please, c= onfirm that ODBC drivers in version 13.2 are not affected by those exposure= s ? Are there any plans to release additional ODBC driver's version considering= the fact that openssl 1.x versions are going to be EOF on September 11, 20= 23 ? Many thanks Best Regards Miloslav Zadrazil --_000_PH0PR11MB512834ECFC2C76179FF5F68A835AAPH0PR11MB5128namp_ Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable

Hello,

 

We use your ODBC drivers in our product. During secu= rity scans we have received warning related to content of psqlODBC 13.2 dri= ver package.

It is flagged to contains OpenSSL 1.1.1lversion vuln= erable for CVE-2021-4160, CVE-2022-0778, CVE-2022-2097, CVE-2022-4304, CVE-= 2022-4450, CVE-2023-0215, CVE-2023-0286 exposures.

 

We must deliver vulnerability analysis to our custom= ers. Can you, please, confirm that ODBC drivers in version 13.2 are not aff= ected by those exposures ?

 

Are there any plans to release additional ODBC drive= r’s version considering the fact that openssl 1.x versions are going = to be EOF on September 11, 2023 ?  

 

Many thanks

 

Best Regards

 

Miloslav Zadrazil

--_000_PH0PR11MB512834ECFC2C76179FF5F68A835AAPH0PR11MB5128namp_--