Re: Why are absolute paths considered a security risk?

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: Why are absolute paths considered a security risk?
Дата
Msg-id 25797.1046219481@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Why are absolute paths considered a security risk?  (Hadley Willan <hadley.willan@deeperdesign.co.nz>)
Ответы Re: Why are absolute paths considered a security risk?
Список pgsql-general
Hadley Willan <hadley.willan@deeperdesign.co.nz> writes:
> The documentation (7.2.1) mentions that allowing absolute paths when
> creating a db is a security risk and is off by default.
> However, it seems fairly hard to exploit, and I was wondering if anybody
> has any examples of how much of a risk this is?
> Reason I ask is we're considering turning them on in our server and want
> to consider these risks.

The difficulty is that someone who is allowed to create databases (but
isn't necessarily a superuser) will be able to cause the backend to
scribble in any directory that the postgres user has write access to.
The potential damage is somewhat limited since "base/DBOID" gets tacked
onto the user-specified string, and the user has little if any control
over the DBOID part.  Still, it's a risk.

            regards, tom lane

В списке pgsql-general по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: 7.4?
Следующее
От: "Cristian Custodio"
Дата:
Сообщение: OID or lo