| From: | Bruce Momjian <pgman(at)candle(dot)pha(dot)pa(dot)us> |
|---|---|
| To: | Neil Conway <neilc(at)samurai(dot)com> |
| Cc: | "Marc G(dot) Fournier" <scrappy(at)hub(dot)org>, PostgreSQL Hackers <pgsql-hackers(at)postgresql(dot)org> |
| Subject: | Re: [GENERAL] PostgreSQL 7.2.2: Security Release |
| Date: | 2002-08-24 11:23:48 |
| Message-ID: | 200208241123.g7OBNmS08909@candle.pha.pa.us |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-announce pgsql-general pgsql-hackers |
Neil Conway wrote:
> Bruce Momjian <pgman(at)candle(dot)pha(dot)pa(dot)us> writes:
> > The issue is data-provoked crashes vs. query-invoked crashes. Marc's
> > point, and I think it was clear enough, is that you can't just poke at
> > the TCP port and hope to do anything bad, which was the thrust of the
> > argument, I think.
>
> The point I objected to is the suggestion that only those running
> "shared" or "open" systems are vulnerable to the security
> problem. That is simply incorrect.
Yes, I remember now. It is a bad data vunerability vs. a bad query
vulnerability.
--
Bruce Momjian | http://candle.pha.pa.us
pgman(at)candle(dot)pha(dot)pa(dot)us | (610) 359-1001
+ If your life is a hard drive, | 13 Roberts Road
+ Christ can be your backup. | Newtown Square, Pennsylvania 19073
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Vince Vielhaber | 2002-08-24 14:51:30 | Re: [GENERAL] PostgreSQL 7.2.2: Security Release |
| Previous Message | Neil Conway | 2002-08-24 04:47:16 | Re: [GENERAL] PostgreSQL 7.2.2: Security Release |
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Vince Vielhaber | 2002-08-24 14:51:30 | Re: [GENERAL] PostgreSQL 7.2.2: Security Release |
| Previous Message | Neil Conway | 2002-08-24 04:47:16 | Re: [GENERAL] PostgreSQL 7.2.2: Security Release |
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Bruce Momjian | 2002-08-24 11:27:56 | Re: Delayed... |
| Previous Message | Peter Eisentraut | 2002-08-24 07:22:38 | Delayed... |