Tom,
> We don't really have an official security contact. The next best thing
> is to send such reports to pgsql-core, which is not an open list, but
> will reach a good chunk of those with an interest in fixing such
> problems.
Is there any reason not to set up a "security@postgresql.org" mail alias?
--
Josh Berkus
Aglio Database Solutions
San Francisco