Re: OpenSSL v1.1.1n in postgres - Mailing list pgsql-bugs

From Daniel Gustafsson
Subject Re: OpenSSL v1.1.1n in postgres
Date
Msg-id 3CF81050-F834-4000-99C0-8BC2E805CFAB@yesql.se
Whole thread Raw
In response to OpenSSL v1.1.1n in postgres  ("Vibhu Chauhan (iDEAS-ER&D)" <vibhu.chauhan@wipro.com>)
Responses Re: OpenSSL v1.1.1n in postgres
List pgsql-bugs
> On 26 Mar 2022, at 18:32, Vibhu Chauhan (iDEAS-ER&D) <vibhu.chauhan@wipro.com> wrote:

> Hi Postgres support,

This is the bug reporting mailing list, and this is not a bug report.  Please
use pgsql-general for future questions like these.

> In one security scan we found that OpenSSL v1.1.1k is vulnerable which is sub-component of postgres 13.3.  From below
linkwe came to know that affected OpenSSL version 1.1.1k is fixed in 1.1.1n version. We wanted to know which postgres
versionhaving this fix version of OpenSSL? And is there any steps to mitigate the risk of version 1.1.1k? 

PostgreSQL doesn't come statically linked to any OpenSSL version, you need to
ask your system administrators and/or PostgreSQL service provider about this.

--
Daniel Gustafsson        https://vmware.com/




pgsql-bugs by date:

Previous
From: "Vibhu Chauhan (iDEAS-ER&D)"
Date:
Subject: OpenSSL v1.1.1n in postgres
Next
From: Tom Lane
Date:
Subject: Re: OpenSSL v1.1.1n in postgres