Re: CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10 - Mailing list pgsql-general

From David G. Johnston
Subject Re: CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10
Date
Msg-id CAKFQuwZFPGLtMS4DS8AAm8iMQ7iu6fCxj5syL-DU9srcUmjQ6A@mail.gmail.com
Whole thread Raw
In response to Re: CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10  (Matthias Apitz <guru@unixarea.de>)
List pgsql-general
On Friday, November 22, 2024, Matthias Apitz <guru@unixarea.de> wrote:

Especially the version V7.2 (released in 2021) can't be updated on the
client side, the cluster will be migrated to 16.5. I assume that
CVE-2024-10979 affects the server side, and not the client side.

Yes, it is the server that executes procedural language code like plperl.

David J.

pgsql-general by date:

Previous
From: walther@technowledgy.de
Date:
Subject: Re: Fwd: A million users
Next
From: Laurenz Albe
Date:
Subject: Re: CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10