Re: [COMMITTERS] pgsql: Fix failure due to accessing an

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: [COMMITTERS] pgsql: Fix failure due to accessing an
Дата
Msg-id 27900.1169138540@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: [COMMITTERS] pgsql: Fix failure due to accessing an  (Tatsuo Ishii <ishii@sraoss.co.jp>)
Ответы Re: [COMMITTERS] pgsql: Fix failure due to accessing an  (Tatsuo Ishii <ishii@postgresql.org>)
Список pgsql-hackers
Tatsuo Ishii <ishii@sraoss.co.jp> writes:
> One of our engineer claimed that double free bug itself is a
> vulnerability, thus 8.2.1 release should be called as "security
> release".

[ shrug... ]  AFAICS the crashing bugs we fixed in 8.2.1 can't be
exploited for anything beyond crashing the backend, and only by an
attacker who can issue arbitrary SQL commands.  There are plenty of
other ways to cause momentary DOS if you can do that, so it doesn't
strike me as a big security vulnerability.  But if you want to call
it one, you can.
        regards, tom lane


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: Design notes for EquivalenceClasses
Следующее
От: Alvaro Herrera
Дата:
Сообщение: Re: [GENERAL] Corrupt database? 8.1/FreeBSD6.0