Re: Zlib vulnerability heads-up.

From: Jan Wieck <janwieck(at)yahoo(dot)com>
To: Lamar Owen <lamar(dot)owen(at)wgcr(dot)org>
Cc: pgsql-hackers(at)postgresql(dot)org
Subject: Re: Zlib vulnerability heads-up.
Date: 2002-03-12 16:34:13
Message-ID: 200203121634.g2CGYDr29777@saturn.janwieck.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general pgsql-hackers

Lamar Owen wrote:
[Charset iso-8859-15 unsupported, filtering to ASCII...]
> As PostgreSQL uses the zlib library (for TOAST?), this is a headsup that a
> bug has been found in the zlib library that could cause data corruption or a
> security breach.

PostgreSQL does not use the zlib library for toast. The
algorithm used in toast is based on Adisak Pochanayon's SLZ.

Jan

>
> See http://www.gzip.org/zlib/advisory-2002-03-11.txt for more details.
>
> Updating zlib is strongly recommended by many sources, and a patch is
> available.
>
> I have only posted this to HACKERS; if a cross-post to GENERAL or ADMIN is
> useful, that can be arranged.
> --
> Lamar Owen
> WGCR Internet Radio
> 1 Peter 4:11
>
> ---------------------------(end of broadcast)---------------------------
> TIP 2: you can get off all lists at once with the unregister command
> (send "unregister YourEmailAddressHere" to majordomo(at)postgresql(dot)org)
>

--

#======================================================================#
# It's easier to get forgiveness for being wrong than for being right. #
# Let's break this rule - forgive me. #
#================================================== JanWieck(at)Yahoo(dot)com #

_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com

In response to

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Doug McNaught 2002-03-12 16:40:36 Re: User permissions
Previous Message Trond Eivind =?iso-8859-1?q?Glomsr=F8d?= 2002-03-12 16:24:10 Re: Zlib vulnerability heads-up.

Browse pgsql-hackers by date

  From Date Subject
Next Message Zeugswetter Andreas SB SD 2002-03-12 16:42:43 Re: Rationalizing EXPLAIN VERBOSE output
Previous Message Luis Alberto Amigo Navarro 2002-03-12 16:34:03 bad performance on SMP