Re: Why does Postgres need the /bin/sh?

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: Why does Postgres need the /bin/sh?
Дата
Msg-id 26941.1020524035@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: Why does Postgres need the /bin/sh?  (Stephen Amadei <amadei@dandy.net>)
Ответы Re: Why does Postgres need the /bin/sh?  (Stephen Amadei <amadei@dandy.net>)
Список pgsql-bugs
Stephen Amadei <amadei@dandy.net> writes:
> However, if someone was to know that Postgres needs a /bin/rm, an exploit
> could be created that runs /bin/rm instead of /bin/sh and trashes the
> databases postgres owns.  Of course, this is a big IF.  ;-)

The attacker won't be able to do any of this unless he's already managed
to connect to the database, no?  There are much easier ways to zap your
data at the SQL level.  Sorry but I'm having a hard time getting excited
about this proposition...

            regards, tom lane

В списке pgsql-bugs по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: 7.2.1 segfaults.
Следующее
От: Stephen Amadei
Дата:
Сообщение: Re: 7.2.1 segfaults.