Re: Vulnerability identified with Postgres 13.4 for Windows

2021-10-30 Thread Justin Pryzby
On Fri, Oct 29, 2021 at 10:40:06AM +, Joel Mariadasan (jomariad) wrote: > Hi, > > The scanning tool used by our organization has detected the presence of > vulnerable libxml version in the latest Postgres 13.4 release for windows > (Zip version). > > Detected by Automated Scanning tool: > l

Re: Vulnerability identified with Postgres 13.4 for Windows

2021-10-29 Thread David G. Johnston
On Friday, October 29, 2021, Joel Mariadasan (jomariad) wrote: > Detected by Automated Scanning tool: > > *libxml 2.9.10* > > > > Can you confirm if this is the same version of libxml used in Postgres? > > We want to confirm if the detection is a false positive or a vulnerability. > > > IIUC (t