Re: [GENERAL] PostgreSQL 7.2.2: Security Release - Mailing list pgsql-hackers

From Neil Conway
Subject Re: [GENERAL] PostgreSQL 7.2.2: Security Release
Date
Msg-id 87k7mgamnf.fsf@mailbox.samurai.com
Whole thread Raw
In response to Re: [GENERAL] PostgreSQL 7.2.2: Security Release  (Bruce Momjian <pgman@candle.pha.pa.us>)
Responses Re: [GENERAL] PostgreSQL 7.2.2: Security Release  (Bruce Momjian <pgman@candle.pha.pa.us>)
List pgsql-hackers
Bruce Momjian <pgman@candle.pha.pa.us> writes:
> The issue is data-provoked crashes vs. query-invoked crashes.  Marc's
> point, and I think it was clear enough, is that you can't just poke at
> the TCP port and hope to do anything bad, which was the thrust of the
> argument, I think.

The point I objected to is the suggestion that only those running
"shared" or "open" systems are vulnerable to the security
problem. That is simply incorrect.

Cheers,

Neil

-- 
Neil Conway <neilc@samurai.com> || PGP Key ID: DB3C29FC



pgsql-hackers by date:

Previous
From: Tom Lane
Date:
Subject: Re: Large file support available
Next
From: Mark Kirkwood
Date:
Subject: Re: Large file support available