Re: Regarding cve-2024-0985

From: Ron Johnson <ronljohnsonjr(at)gmail(dot)com>
To: Pgsql-admin <pgsql-admin(at)lists(dot)postgresql(dot)org>
Subject: Re: Regarding cve-2024-0985
Date: 2024-02-15 20:13:54
Message-ID: CANzqJaBBe4Svm2yOjGEn9BDShZuymUtB98JQS-gh9Y-Rn0MPYw@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-admin

1) What OS? "yum list installed | grep postgresql" or "dpkg -l | grep
postgresql" should show you what's installed.
2) PG 12.3 is *really old*.
3) Applying the latest 12 release (.18) is pretty trivial, *IF* you have
reasonable Linux sysadmin skills.

On Thu, Feb 15, 2024 at 9:46 AM Rakesh Nashine <nashine(dot)rakesh(at)gmail(dot)com>
wrote:

> Hi Ron,
> Actually i wasn't aware about it, as someone has done the postgresql
> installation long back . Now since we need to get out of this ve-2024-0985,
> I am looking for some assistance to roll this out in existing environment.
> Currently we are on *Postgres (PostgreSQL) 12.3. *
>
> Thanks
>
>
> On Thu, Feb 15, 2024 at 7:58 PM Ron Johnson <ronljohnsonjr(at)gmail(dot)com>
> wrote:
>
>> On Thu, Feb 15, 2024 at 5:23 AM Rakesh Nashine <nashine(dot)rakesh(at)gmail(dot)com>
>> wrote:
>>
>>> Hello All,
>>> Good afternoon !
>>> I would like to apply the latest patch as remediation of cve-2024-0985:
>>> Can anyone please help me with the steps to apply these patches ? or may
>>> be any documents.
>>>
>>
>> https://www.postgresql.org/support/security/CVE-2024-0985/
>>
>> From what source did you install Postgresql?
>>
>>
>
> --
> Thanks & Regards
> Rakesh Nashine
>

In response to

Browse pgsql-admin by date

  From Date Subject
Next Message Krishnaswamy 2024-02-16 07:57:24 Re: Postgres upgrade from 9.6.9 to postgresql 16 version
Previous Message David G. Johnston 2024-02-15 15:14:47 Re: Regarding cve-2024-0985