Security Issue on Postgresql ?!?!

Thanks for raising this issue!

is the actual security issue already in work on the proxmox-mail-gateway?
from a quick look through both the heise-article you posted and the postgresql security notice:
https://www.postgresql.org/support/security/CVE-2024-0985/
I'm quite confident that Proxmox Mail Gateway is not affected by this issue, as it does not use materialized views, thus also no "REFRESH MATERIALIZED VIEW CONCURRENTLY" command.

For completeness sake here the debian security advisory for the CVE:
https://security-tracker.debian.org/tracker/CVE-2024-0985
(this just says that currently the versions in Debian are affected, and will get updated with the versions of the fixed packages, PMG remains not vulnerable as it does not use the functionality).

I hope this helps!
 
  • Like
Reactions: Bob.Dig
To conclude this:
postgresql-15 version 15.6-0+deb12u1 is available in bookworm-security
postgresql-13 version 13.14-0+deb11u1is available in bullseye-security

both address the issue (which does not affect PMG)
 
  • Like
Reactions: Chris

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!