Potential Windows ODBC 10.03.0000 Security Vulnerability - Mailing list pgsql-odbc

From Nathan Harrell
Subject Potential Windows ODBC 10.03.0000 Security Vulnerability
Date
Msg-id BL0PR05MB5345FE04F83B24AA5BB8193D8A7F0@BL0PR05MB5345.namprd05.prod.outlook.com
Whole thread Raw
List pgsql-odbc

Hello all,

 

In August of 2018, CVE-2018-10915 was found with a CVSS v3 base score of 8.5 against the PostgreSQL libpq library.  This affects all PostgreSQL 10 versions of libpq up to version 10.4 and the issue is fixed as of version 10.5.  As far as I can tell, the Windows MSI provided by the PostgreSQL ODBC community for ODBC 10.03.0000 is shipping with libpq version 10.4, which would mean it is shipping with these security vulnerabilities.

 

Are there any plans to upgrade the Windows MSI libpq libraries to PostgreSQL 10.5 or 10.6 so that we can avoid this security issue?  The link below is to the security exception on PostgreSQL’s website:

 

https://www.postgresql.org/about/news/1878/

 

Thanks,

Nathan

pgsql-odbc by date:

Previous
From: Pierre Couderc
Date:
Subject: Re: problem with _ character
Next
From: Grant Shirreffs
Date:
Subject: Escaped characters in LIKE