Re: Zlib vulnerability heads-up. - Mailing list pgsql-hackers

From Neil Conway
Subject Re: Zlib vulnerability heads-up.
Date
Msg-id 1015959074.4927.30.camel@jiro
Whole thread Raw
In response to Re: Zlib vulnerability heads-up.  (Lamar Owen <lamar.owen@wgcr.org>)
List pgsql-hackers
On Tue, 2002-03-12 at 11:46, Lamar Owen wrote:
> On Tuesday 12 March 2002 11:24 am, Trond Eivind Glomsrød wrote:
> > Lamar Owen <lamar.owen@wgcr.org> writes:
> > > Updating zlib is strongly recommended by many sources, and a patch is
> > > available.
>
> > FWIW, I really doubt this is much of a problem for postgresql. It's
> > mainly a problem for applications dealing with untrusted, compressed
> > data (webbrowsers, imageviewers, programs with skins downloaded from
> > the Internet) etc.
>
> It's probably NOT a big problem; but it IS a bug in an underlying library.

Can we just add an item to the 7.2.1 release notes suggesting that zlib
1.1.4 or greater is installed? AFAICT that should be sufficient.

Cheers,

Neil

--
Neil Conway <neilconway@rogers.com>
PGP Key ID: DB3C29FC



pgsql-hackers by date:

Previous
From: Andrew Sullivan
Date:
Subject: Re: Zlib vulnerability heads-up.
Next
From: Greg Copeland
Date:
Subject: Re: Zlib vulnerability heads-up.