| From: | Bruce Momjian <bruce(at)momjian(dot)us> |
|---|---|
| To: | Alvaro Herrera <alvherre(at)commandprompt(dot)com> |
| Cc: | Dave Page <dpage(at)pgadmin(dot)org>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, Lars Olson <leolson1(at)uiuc(dot)edu>, PostgreSQL www <pgsql-www(at)postgresql(dot)org> |
| Subject: | Submitting security bugs |
| Date: | 2008-05-09 03:37:02 |
| Message-ID: | 200805090337.m493b2204043@momjian.us |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-bugs pgsql-www |
Alvaro Herrera wrote:
> Dave Page wrote:
> > On Mon, Mar 31, 2008 at 10:46 PM, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us> wrote:
> > > If this were a security issue, you already spilled the beans by
> > > reporting it to a public mailing list; so I'm unsure what you are
> > > concerned about.
> >
> > I'd wager that Lars didn't realise the bug form goes straight to the
> > list. We should probably make that more clear.
> >
> > On the other hand it does say to report security issues to security(at)(dot)(dot)(dot)
>
> Let's have a checkbox "I am reporting a security issue" and send the
> mail to security@ if checked.
Do we want to do this?
--
Bruce Momjian <bruce(at)momjian(dot)us> http://momjian.us
EnterpriseDB http://enterprisedb.com
+ If your life is a hard drive, Christ can be your backup. +
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Christian.Strobl | 2008-05-09 08:31:48 | reproducible database crash with simple sql command on postgres 8.3.1 |
| Previous Message | Andrew Chernow | 2008-05-08 17:04:49 | Re: Re: BUG #4053: libpq documentation should express clearly, that integers are passed in network octet order |
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Magnus Hagander | 2008-05-09 06:03:10 | Re: IM |
| Previous Message | Josh Berkus | 2008-05-09 03:13:49 | Re: IM |