Re: Heartbleed Impact

From: Dev Kumkar <devdas(dot)kumkar(at)gmail(dot)com>
To: John R Pierce <pierce(at)hogranch(dot)com>
Cc: "pgsql-general(at)postgresql(dot)org" <pgsql-general(at)postgresql(dot)org>
Subject: Re: Heartbleed Impact
Date: 2014-04-16 20:16:12
Message-ID: CALSLE1PdseUJa6YKdA_n3+A5fNi5BuC-xtfdjQ0CyY=g=haCnw@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

On Thu, Apr 17, 2014 at 1:31 AM, John R Pierce <pierce(at)hogranch(dot)com> wrote:

> do you enable SSL and expose it to an insecure network ? if not, no
> exposure to the heartbleed bug.
>

No, SSL is not enabled in my case but also wanted to make sure there is no
binary available which can later result into any potential issue.

> AFAIK, the binary name is postgres.exe, from what I've read they are
> static linking openssl. the updated versions on the site linked in another
> message are fixed per the note on that page.
> http://www.enterprisedb.com/products-services-training/pgdownload

http://www.enterprisedb.com/products-services-training/pgbindownload also
has the note added sometime back.
I was able to verify for Linux binaries looking at STRINGS of so file but
was not sure about the windows side and hence was looking for confirmation.

Regards...

In response to

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Andy Colson 2014-04-16 21:15:00 Re: hot standby data folder bigger than primary
Previous Message John R Pierce 2014-04-16 20:01:59 Re: Heartbleed Impact