Re: pg_largeobject is a security hole - Mailing list pgsql-hackers

From Tom Lane
Subject Re: pg_largeobject is a security hole
Date
Msg-id 22691.993685766@sss.pgh.pa.us
Whole thread Raw
In response to Re: pg_largeobject is a security hole  (Philip Warner <pjw@rhyme.com.au>)
Responses Re: pg_largeobject is a security hole
List pgsql-hackers
Philip Warner <pjw@rhyme.com.au> writes:
> At 12:27 27/06/01 -0400, Tom Lane wrote:
>> I propose that initdb should do
>> REVOKE ALL on pg_largeobject FROM public

> May have an issue with PG_DUMP, which does a 'select oid from
> pg_largeobject', I think.

Hmm.  [sound of grepping]  So does psql's \lo_list command.  That's
annoying ... the list of large object OIDs is *exactly* what you'd want
to hide from the unwashed masses.  Oh well, I'll leave bad enough alone
for now.
        regards, tom lane


pgsql-hackers by date:

Previous
From: Tom Lane
Date:
Subject: Re: functions returning records
Next
From: "Dmitry G. Mastrukov"
Date:
Subject: Re: New data type: uniqueidentifier