Re: Fwd: init scripts and su

Поиск
Список
Период
Сортировка
От Peter Eisentraut
Тема Re: Fwd: init scripts and su
Дата
Msg-id 200408091017.02555.peter_e@gmx.net
обсуждение исходный текст
Ответ на Re: Fwd: init scripts and su  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-hackers
Tom Lane wrote:
> (a) And there would be untrusted code running as postgres exactly
> why?

Because someone has cracked the PostgreSQL server.

> (b) Seems to me the real security bug here is the mere existence of
> that ioctl call.

Probably.  I'm just pointing out the findings about the environment 
we're operating in.  The fact is that right now "run as postgres to 
protect your root account" won't work on some systems and with 
unfortunately written init scripts.

-- 
Peter Eisentraut
http://developer.postgresql.org/~petere/



В списке pgsql-hackers по дате отправления:

Предыдущее
От: "Dave Page"
Дата:
Сообщение: Re: Windows binary in the beta directory?
Следующее
От: Christopher Kings-Lynne
Дата:
Сообщение: Changing the type of timestamp columns