CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10 - Mailing list pgsql-general

From David G. Johnston
Subject CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10
Date
Msg-id CAKFQuwbW-5yyVPCjyTJ0uwZZvn9J94s1XzuFnoBbMXp3BC3XyQ@mail.gmail.com
Whole thread Raw
In response to Re: CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10  (Subhash Udata <subhashudata@gmail.com>)
Responses Re: CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10
Re: CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10
List pgsql-general
On Thursday, November 21, 2024, Subhash Udata <subhashudata@gmail.com> wrote:


Thank you for your response regarding the affected versions of PostgreSQL. I have a follow-up question for clarification:

The PostgreSQL documentation mentions that the versions with a fix for CVE-2024-10979 are 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21. However, your reply states that any version greater than 13+ should suffice.

Could you please confirm if upgrading to one of the specific versions listed above is mandatory, or is it acceptable to upgrade to any version higher than 13


It was literally just reported and fixed.  If you are on a supported release of PostgreSQL you have the fix.  If you are not, you don’t.

At this point only major versions 13+ are supported.

Upgrading to an unsupported minor release is never recommended.

The fact you are on version 11 means you should not expect an answer to the question whether this newly discovered CVE affects you - that would be expecting support for a long-unsupported version.

Which of the 5 currently supported releases you should upgrade to is a decision you need to make given your circumstances.

David J.
 

pgsql-general by date:

Previous
From: Subhash Udata
Date:
Subject: Re: CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10
Next
From: Subhash Udata
Date:
Subject: Re: CVE-2024-10979 Vulnerability Impact on PostgreSQL 11.10