Re: BUG #10184: OpenSSL Vulnerability - Mailing list pgsql-bugs

From Stephen Frost
Subject Re: BUG #10184: OpenSSL Vulnerability
Date
Msg-id 20140430165125.GI2556@tamriel.snowman.net
Whole thread Raw
In response to BUG #10184: OpenSSL Vulnerability  (adam.taylor@frontiermedex.com)
List pgsql-bugs
Adam,

* adam.taylor@frontiermedex.com (adam.taylor@frontiermedex.com) wrote:
> PostgreSQL version: 9.0.0

You should really upgrade to the latest if you're actually on 9.0.0.

> We were alerted of a new vulnerability found in OpenSSL (versions 1.0.1 a=
nd
> 1.0.2beta) that could enable remote, unauthorized access to your systems.=
 I
> have included the specifics below.=20

The vulnerability was in OpenSSL.  If you are using SSL with PostgreSQL
then you will want to verify that you have installed the latest version
of OpenSSL and that you have restarted the PostgreSQL server after
installing it.

If you are using PostgreSQL binaries from a distributor then you should
verify that you are using the latest versions and that they have been
updated.  The major Linux distributions (RedHat, CentOS, Debian, Ubuntu,
etc) have provided updates for their supported releases.  The Windows
installer distributed by EDB has also been updated; you'll want to
download and install the latest minor version for the PG major version
which you're running.  You should also review the release notes for all
versions between the one you are on and what you are upgrading to.

    Thanks,

        Stephen

pgsql-bugs by date:

Previous
From: adam.taylor@frontiermedex.com
Date:
Subject: BUG #10184: OpenSSL Vulnerability
Next
From: Rainer Tammer
Date:
Subject: Re: Problem with PostgreSQL 9.2.7 and make check on AIX 7.1