Re: logfile subprocess and Fancy File Functions - Mailing list pgsql-patches

From Andrew Dunstan
Subject Re: logfile subprocess and Fancy File Functions
Date
Msg-id 410293CD.5040802@dunslane.net
Whole thread Raw
In response to Re: logfile subprocess and Fancy File Functions  (Bruce Momjian <pgman@candle.pha.pa.us>)
Responses Re: logfile subprocess and Fancy File Functions
List pgsql-patches

Bruce Momjian wrote:

>As a super-user, could an attacker load a server-side language and
>access the backend environment variable PGDATA.
>
>

plperl won't do it, but plperlu will (as expected I guess). But the
superuser will have to jump through some explicit hoops in order to get
there, which is different from providing such facilities out of the box.

cheers

andrew

pgsql-patches by date:

Previous
From: Tom Lane
Date:
Subject: Re: logfile subprocess and Fancy File Functions
Next
From: Bruce Momjian
Date:
Subject: Re: logfile subprocess and Fancy File Functions