Re: CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10 - Mailing list pgsql-general

From David G. Johnston
Subject Re: CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10
Date
Msg-id CAKFQuwZr=j14Da+n=b8zWERQYBic3iYx0ynTjH3K5Do2=ZLfDw@mail.gmail.com
Whole thread Raw
In response to Re: CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10  (Subhash Udata <subhashudata@gmail.com>)
List pgsql-general
On Thursday, November 21, 2024, Subhash Udata <subhashudata@gmail.com> wrote:

Currently, my environment is running PostgreSQL 15.0. I understand that version 15.9 contains the fix for CVE-2024-10979, as mentioned in the release notes.

Given that I am not using the PL/Perl extension in my environment


IIUC, any user that can execute “create extension plperl” in a database they are connected to (or, it having been installed, users that have been granted usage on the language) can exploit this vulnerability.  Whether that is possible in your environment is something you’d need to determine.

I believe this particular detail probably should have been part of the release announcement but was not.

In any case if you aren’t willing to update consistently you really shouldn’t be deploying .0 releases.

David J.

pgsql-general by date:

Previous
From: Adrian Klaver
Date:
Subject: Re: CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10
Next
From: Laurenz Albe
Date:
Subject: Re: CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10