Skip to main content
pcdslka
New Member
April 19, 2020
Question

False positive critical vulnerability for postgres reported

  • April 19, 2020
  • 0 replies
  • 1727 views

I installed latest postgres 11.7 (postgresql-11.7-2-windows-x64).

FortiClient (6.0.8.0261) "Vulnerability Scan" reports critical CVE-2018-16850. This vulnerability belongs to versions before 11.1 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16850)

 

File version of psql.exe is "11.0.7.20080" but product version is "11.7". Looks like FortiClient checks file version instead product version.

 

Regards

Maki

 

 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!