Re: [Bug] Server Crash, possible security exploit, where to send security report?

From: Martijn van Oosterhout <kleptog(at)svana(dot)org>
To: "Francisco Figueiredo Jr(dot)" <fxjrlists(at)yahoo(dot)com(dot)br>
Cc: pgsql-hackers(at)postgresql(dot)org
Subject: Re: [Bug] Server Crash, possible security exploit, where to send security report?
Date: 2005-12-12 22:01:20
Message-ID: 20051212220112.GE30160@svana.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

On Mon, Dec 12, 2005 at 06:26:25PM -0200, Francisco Figueiredo Jr. wrote:
>
>
>
> Hi all,
>
> while playing with Npgsql I faced an
> strange behavior of Postgresql server.
>
>
> I have all the details of it and I thought it could be a severe security
> exploit, so I don't send it in clear to this mailing list directly as, I
> think, anybody with this information could Dos postgresql servers.

Well, you're not giving any details but if you can cause the server to
dump core in a standard installation, we're interested. You didn't
specify your version BTW.

Here has instructions, including for security related stuff:
http://www.postgresql.org/docs/current/static/bug-reporting.html

Have a nice day,
--
Martijn van Oosterhout <kleptog(at)svana(dot)org> http://svana.org/kleptog/
> Patent. n. Genius is 5% inspiration and 95% perspiration. A patent is a
> tool for doing 5% of the work and then sitting around waiting for someone
> else to do the other 95% so you can sue them.

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Jim C. Nasby 2005-12-12 22:12:12 Re: Something I don't understand with the use of schemas
Previous Message Tom Lane 2005-12-12 22:00:45 Re: Something I don't understand with the use of schemas