Asking for OK for a nasty trick to resolve PG CVE-2025-1094 i

From: "Abraham, Danny" <danny_abraham(at)bmc(dot)com>
To: "pgsql-performance(at)lists(dot)postgresql(dot)org" <pgsql-performance(at)lists(dot)postgresql(dot)org>
Cc: "Abraham, Danny" <danny_abraham(at)bmc(dot)com>
Subject: Asking for OK for a nasty trick to resolve PG CVE-2025-1094 i
Date: 2025-03-06 07:39:17
Message-ID: SA1PR02MB969837F0BEDE8CD64AE703958ECA2@SA1PR02MB9698.namprd02.prod.outlook.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general pgsql-performance

Hi,

I have many customers using PG 15.3 happily, and I cannot just snap upgrade them all to 15.12.

I have tested a nasty trick of replacing PSQL,LIBPQ and several other DLL's so that I have a PG client 15.12 within the folders of Server 15.3.

All working just fine.

I plan to ship it as a patch - but would like to hear you opinion on this "merge".

(Of course, the next version will use PG 17.4, so this is just an SOS action).

Thanks

Danny
BMC Software

Directory of C:\Users\dbauser\Desktop\15.12

02/20/2025 11:48 AM 4,696,576 libcrypto-3-x64.dll
02/20/2025 11:48 AM 1,850,401 libiconv-2.dll
02/20/2025 11:48 AM 475,769 libintl-9.dll
02/20/2025 11:48 AM 323,584 libpq.dll
02/20/2025 11:48 AM 779,776 libssl-3-x64.dll
02/20/2025 11:48 AM 52,736 libwinpthread-1.dll
02/20/2025 11:48 AM 604,160 psql.exe

==
C:\Program Files\BMC Software\Control-M Server\pgsql\bin>postgres -V
postgres (PostgreSQL) 15.3

C:\Program Files\BMC Software\Control-M Server\pgsql\bin>psql -V
psql (PostgreSQL) 15.12

Responses

Browse pgsql-general by date

  From Date Subject
Next Message me nefcanto 2025-03-06 07:44:25 Re: Quesion about querying distributed databases
Previous Message Ron Johnson 2025-03-06 06:22:38 Re: Quesion about querying distributed databases

Browse pgsql-performance by date

  From Date Subject
Next Message Laurenz Albe 2025-03-06 08:11:41 Re: Asking for OK for a nasty trick to resolve PG CVE-2025-1094 i
Previous Message Alexey Borschev 2025-03-03 08:47:07 Slow performance of collate "en_US.utf8"