Aw: Information to CVE-2022-42889 - Mailing list pgsql-general

From Karsten Hilbert
Subject Aw: Information to CVE-2022-42889
Date
Msg-id trinity-b8a0fefe-4cc0-4049-818e-a3cb8180ca81-1667907219851@3c-app-gmx-bap70
Whole thread Raw
In response to Information to CVE-2022-42889  (Cedric Aaron Towstyka <Cedric-Aaron.Towstyka@barmenia.de>)
List pgsql-general
> the german bureau for IT-Security "BSI" (Bundesamt für Sicherheit in der Informationstechnik) has issued a warning
forCVE CVE-2022-42889 with the name commons-text. Insurance companies are obliged to analyse the installed software for
vulnerabilitiesof this type. 
As the Barmenia is using your product PostgreSQL Server it is necessary to obtain all information regarding any
vulnerabilityagainst above CVE. 
We kindly ask you to provide information if the above product is affected by the CVE and if yes, when a fix will be
available.
 
> With the request for short-term feedback.

It might be prudent for Barmenia, a large insurance company, to consider
purchasing commercial support rather than requesting short-term feedback
from volunteers.

Other than that there's also excellent documentation and freely
inspectable source code.

Best regards,
Karsten



pgsql-general by date:

Previous
From: Erik Wienhold
Date:
Subject: Re: Information to CVE-2022-42889
Next
From: Ron
Date:
Subject: Re: Feature suggestions for backup and replication