Re: OpenSSL Vulnerabilities - Mailing list pgsql-general

From Magnus Hagander
Subject Re: OpenSSL Vulnerabilities
Date
Msg-id CABUevExQnGCfGHF3xFL=zuVNTfqBeWAsrJ1=_oU3ofOU==VRuQ@mail.gmail.com
Whole thread Raw
In response to OpenSSL Vulnerabilities  (Saravanan Subramaniyan <sara1479@gmail.com>)
Responses Re: OpenSSL Vulnerabilities
List pgsql-general
On Thu, Jun 12, 2014 at 8:43 AM, Saravanan Subramaniyan <sara1479@gmail.com> wrote:
Hi All,
  Recently OpenSSL released Security Advisory. Please refer below link


We are using postgresql version 9.2.8 which is vulnerable. Is postgresql planning to release new version which include OpenSSL 1.0.1h?


PostgreSQL itself is not vulnerable, so we will not release a new version.

If you are using the EnterpriseDB graphical installers, they are indeed bundling the OpenSSL and it at least used to be the vulnerable version. Unfortunately they don't seem to have information about the updates yet - I will see if i can ping them about making sure that goes on there. I think they have already patched it - but it's not confirmed on the website.

--
 Magnus Hagander
 Me: http://www.hagander.net/
 Work: http://www.redpill-linpro.com/

pgsql-general by date:

Previous
From: Saravanan Subramaniyan
Date:
Subject: OpenSSL Vulnerabilities
Next
From: Krystian Bigaj
Date:
Subject: Re: Re: Cannot start Postgresql 9.3 as a service in Windows 2012 Server with a domain account