Vulnerability identified with Postgres 13.4 for Windows

Поиск
Список
Период
Сортировка
От Joel Mariadasan (jomariad)
Тема Vulnerability identified with Postgres 13.4 for Windows
Дата
Msg-id DM6PR11MB3452AFC9925606D0DA0E3EDBD7879@DM6PR11MB3452.namprd11.prod.outlook.com
обсуждение исходный текст
Ответы Re: Vulnerability identified with Postgres 13.4 for Windows  ("David G. Johnston" <david.g.johnston@gmail.com>)
Re: Vulnerability identified with Postgres 13.4 for Windows  (Justin Pryzby <pryzby@telsasoft.com>)
Список pgsql-hackers

Hi,

 

The scanning tool used by our organization has detected the presence of vulnerable libxml version in the latest Postgres 13.4 release for windows (Zip version).

 

Detected by Automated Scanning tool:

libxml   2.9.10

 

Can you confirm if this is the same version of libxml used in Postgres?

We want to confirm if the detection is a false positive or a vulnerability.

 

Regards,

Joel

В списке pgsql-hackers по дате отправления:

Предыдущее
От: gkokolatos@pm.me
Дата:
Сообщение: Re: Teach pg_receivewal to use lz4 compression
Следующее
От: Greg Nancarrow
Дата:
Сообщение: Skip vacuum log report code in lazy_scan_heap() if possible