| From: | Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us> |
|---|---|
| To: | Justin Clift <justin(at)postgresql(dot)org> |
| Cc: | Florian Weimer <Weimer(at)CERT(dot)Uni-Stuttgart(dot)DE>, pgsql-hackers(at)postgresql(dot)org |
| Subject: | Re: [SECURITY] DoS attack on backend possible (was: Re: |
| Date: | 2002-08-11 17:09:41 |
| Message-ID: | 14467.1029085781@sss.pgh.pa.us |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-committers pgsql-hackers |
Justin Clift <justin(at)postgresql(dot)org> writes:
> Am I understanding this right:
> - A PostgreSQL 7.2.1 server can be crashed if it gets passed certain
> date values which would be accepted by standard "front end" parsing?
AFAIK it's a buffer overrun issue, so anything that looks like a
reasonable date would *not* cause the problem.
regards, tom lane
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Florian Weimer | 2002-08-11 17:17:20 | Re: [SECURITY] DoS attack on backend possible (was: Re: |
| Previous Message | Justin Clift | 2002-08-11 16:26:56 | Re: [SECURITY] DoS attack on backend possible (was: Re: |
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Joe Conway | 2002-08-11 17:15:43 | Re: [GENERAL] workaround for lack of REPLACE() function |
| Previous Message | Justin Clift | 2002-08-11 16:26:56 | Re: [SECURITY] DoS attack on backend possible (was: Re: |