Re: BUG #2052: Federal Agency Tech Hub Refuses to Accept Postgresql on Network because of Security Vulnerabilities - Mailing list pgsql-bugs

From Tom Lane
Subject Re: BUG #2052: Federal Agency Tech Hub Refuses to Accept Postgresql on Network because of Security Vulnerabilities
Date
Msg-id 5821.1132324363@sss.pgh.pa.us
Whole thread Raw
In response to BUG #2052: Federal Agency Tech Hub Refuses to Accept Postgresql on Network because of Security Vulnerabilities  ("Ferindo Middleton" <fmiddleton@verizon.net>)
Responses Re: BUG #2052: Federal Agency Tech Hub Refuses to Accept  (Ferindo Middleton Jr <fmiddleton@verizon.net>)
List pgsql-bugs
"Ferindo Middleton" <fmiddleton@verizon.net> writes:
> This bug report involves more than one proposed bug. I work at a federal
> government agency. The information technology division at this agency
> refuses to allow the database version 8.0.4 on their network because of
> several security vulnerabilities they noticed when testing the software
> application.

They obviously haven't "tested" anything --- they are merely reading the
CVE reports for old Postgres versions.  All known CVE problems are
resolved in 8.0.4.

(If they were actually serious about security, they wouldn't be letting
you run Windows 2000 inside their network, but I digress.)

            regards, tom lane

pgsql-bugs by date:

Previous
From: Tom Lane
Date:
Subject: Re: BUG #2049: pg_dump BACKUP error
Next
From: Stephen Frost
Date:
Subject: Re: BUG #2052: Federal Agency Tech Hub Refuses to Accept Postgresql on Network because of Security Vulnerabilities