# Request postgresql update to 9.5.12

**URL:** https://www.finalbuilder.com/forums/t/request-postgresql-update-to-9-5-12/5616
**Category:** Discussion
**Created:** [March 15, 2018, 1:26am UTC](https://www.finalbuilder.com/forums/t/request-postgresql-update-to-9-5-12/5616 "2018-03-15T01:26:43Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![bkwalker](https://www.finalbuilder.com/forums/letter_avatar_proxy/v4/letter/b/c0e974/32.png) [@bkwalker](https://www.finalbuilder.com/forums/u/bkwalker)
#### Post date: [March 15, 2018, 1:26am UTC](https://www.finalbuilder.com/forums/t/request-postgresql-update-to-9-5-12/5616/1 "2018-03-15T01:26:43Z")

</div>

9.5.3 in the latest release of CI is vulnerable to CVE-2018-1052, CVE-2018-1053 and CVE-2018-1058.  
  
9.5.11 contains fixes for CVE-2018-1052, CVE-2018-1053:  
https://www.postgresql.org/about/news/1834/  
https://www.postgresql.org/about/news/1829/  
  
9.5.12 contains fixes for CVE-2018-1058, CI may not be vulnerable as the attack vector requires specific configuration. However probably makes sense to move to 9.5.12.  
https://wiki.postgresql.org/wiki/A\_Guide\_to\_CVE-2018-1058:\_Protect\_Your\_Search\_Path

---

<div class="post-metadata">

### Author: ![Vincent](https://www.finalbuilder.com/forums/user_avatar/www.finalbuilder.com/vincent/32/938_2.png) [@Vincent](https://www.finalbuilder.com/forums/u/Vincent)
#### Post date: [March 15, 2018, 10:43am UTC](https://www.finalbuilder.com/forums/t/request-postgresql-update-to-9-5-12/5616/2 "2018-03-15T10:43:26Z")

</div>

Thanks for bringing this to our attention. The version we currently ship is 9.5.8 - we’ll get that updated asap. In the future, please send this sort of issue to our support email rather than posting on the forums - [https://en.wikipedia.org/wiki/Responsible\_disclosure](https://en.wikipedia.org/wiki/Responsible_disclosure)

---

<div class="post-metadata">

### Author: ![bkwalker](https://www.finalbuilder.com/forums/letter_avatar_proxy/v4/letter/b/c0e974/32.png) [@bkwalker](https://www.finalbuilder.com/forums/u/bkwalker)
#### Post date: [March 16, 2018, 1:08am UTC](https://www.finalbuilder.com/forums/t/request-postgresql-update-to-9-5-12/5616/3 "2018-03-16T01:08:16Z")

</div>

Thanks. I posted here because these issues are already public. Responsible disclosure isn’t relevant in this situation, I’m not disclosing anything that wasn’t already public for weeks.   
  
 You might want to have someone monitoring weekly vulnerability bulletins ([https://www.us-cert.gov/ncas/bulletins](https://www.us-cert.gov/ncas/bulletins) is where we get them, probably others) it shouldn’t take long to scan them for anything that might affect CI.   
  
 Next time I’ll send to support email.

---

<div class="post-metadata">

### Author: ![Vincent](https://www.finalbuilder.com/forums/user_avatar/www.finalbuilder.com/vincent/32/938_2.png) [@Vincent](https://www.finalbuilder.com/forums/u/Vincent)
#### Post date: [March 16, 2018, 9:51am UTC](https://www.finalbuilder.com/forums/t/request-postgresql-update-to-9-5-12/5616/4 "2018-03-16T09:51:41Z")

</div>

Yes they were already known to the postgres community, but probably not general knowledge here.   
  
 I would love to have someone monitoring vulnerabilities but were extremely resource strapped at the moment and there isn’t anyone here (myself included) I can pile more work onto.

---

<div class="post-metadata">

### Author: ![bkwalker](https://www.finalbuilder.com/forums/letter_avatar_proxy/v4/letter/b/c0e974/32.png) [@bkwalker](https://www.finalbuilder.com/forums/u/bkwalker)
#### Post date: [March 16, 2018, 10:00am UTC](https://www.finalbuilder.com/forums/t/request-postgresql-update-to-9-5-12/5616/5 "2018-03-16T10:00:46Z")

</div>

Understood. Can you provide a list any other third party tools/components used to build or incorporated into CI? I review these bulletins weekly, and I’d be happy to pass along information via email. Just need to know what you’d be interested in.   
  
 Anything that affect CI ends up being my concern anyway, I’d not bug you with IIS issues of course… you can’t do anything about that 😉

---

<div class="post-metadata">

### Author: ![Vincent](https://www.finalbuilder.com/forums/user_avatar/www.finalbuilder.com/vincent/32/938_2.png) [@Vincent](https://www.finalbuilder.com/forums/u/Vincent)
#### Post date: [March 18, 2018, 10:54am UTC](https://www.finalbuilder.com/forums/t/request-postgresql-update-to-9-5-12/5616/6 "2018-03-18T10:54:50Z")

</div>

We ship postgresql, mercurial. As for third party code libraries, there are many, and we do keep on top of those (open source and commercial), as it’s relatively easy with nuget. FWIW we are working on upgrading the version of mercurial we ship, however the most recent builds broke some of the extensions we use/require, and it also has a major performance regression (I sumitted a fix for that to mercurial for the next mercurial release).

---

<div class="post-metadata">

### Author: ![bkwalker](https://www.finalbuilder.com/forums/letter_avatar_proxy/v4/letter/b/c0e974/32.png) [@bkwalker](https://www.finalbuilder.com/forums/u/bkwalker)
#### Post date: [March 19, 2018, 12:04pm UTC](https://www.finalbuilder.com/forums/t/request-postgresql-update-to-9-5-12/5616/7 "2018-03-19T12:04:29Z")

</div>

In he future I’ll pass on anything for postgresql, svn and git clients as well. I’m on top of svn and git already.   
  
 Thanks for the great product, and quick response… your support is top notch!

---

<div class="post-metadata">

### Author: ![Sparky](https://www.finalbuilder.com/forums/user_avatar/www.finalbuilder.com/sparky/32/10_2.png) [@Sparky](https://www.finalbuilder.com/forums/u/Sparky)
#### Post date: [March 20, 2018, 11:55am UTC](https://www.finalbuilder.com/forums/t/request-postgresql-update-to-9-5-12/5616/8 "2018-03-20T11:55:36Z")

</div>

Hi Brenden,  
  
Version [1.8.1.801](https://www.finalbuilder.com/downloads/continuaci/continuaci-version-history-v1.8.1) upgrades the bundled version of PostgreSQL to [version 9.6.8](https://www.postgresql.org/docs/9.6/static/release-9-6-8.html).&nbsp;  
  
Note that we do not bundle svn and git clients with Continua CI - these need to be upgraded independently.&nbsp;

---

<div class="post-metadata">

### Author: ![bkwalker](https://www.finalbuilder.com/forums/letter_avatar_proxy/v4/letter/b/c0e974/32.png) [@bkwalker](https://www.finalbuilder.com/forums/u/bkwalker)
#### Post date: [March 21, 2018, 1:16am UTC](https://www.finalbuilder.com/forums/t/request-postgresql-update-to-9-5-12/5616/9 "2018-03-21T01:16:54Z")

</div>

Thanks, scheduled the update this weekend…   
  
 I forgot that git/svn clients are handled separately… I’ll pass along postgresql CVE’s… that makes it simple.
