Re: [SECURITY] DoS attack on backend possible (was: Re: - Mailing list pgsql-hackers

From Christopher Kings-Lynne
Subject Re: [SECURITY] DoS attack on backend possible (was: Re:
Date
Msg-id GNELIHDDFBOCMGBFGEFOKEKACDAA.chriskl@familyhealth.com.au
Whole thread Raw
In response to Re: [SECURITY] DoS attack on backend possible (was: Re:  (Tom Lane <tgl@sss.pgh.pa.us>)
List pgsql-hackers
> Justin Clift <justin@postgresql.org> writes:
> > Am I understanding this right:
> >  - A PostgreSQL 7.2.1 server can be crashed if it gets passed certain
> > date values which would be accepted by standard "front end" parsing?
>
> AFAIK it's a buffer overrun issue, so anything that looks like a
> reasonable date would *not* cause the problem.

Still, I believe this should require a 7.2.2 release.  Imagine a university
database server for a course for example - the students would just crash it
all the time.

Chris



pgsql-hackers by date:

Previous
From: "Christopher Kings-Lynne"
Date:
Subject: Re: python patch
Next
From: Justin Clift
Date:
Subject: Re: [SECURITY] DoS attack on backend possible (was: Re: