Re: CVE-2019-9193 about COPY FROM/TO PROGRAM

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: CVE-2019-9193 about COPY FROM/TO PROGRAM
Дата
Msg-id 31048.1554407141@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: CVE-2019-9193 about COPY FROM/TO PROGRAM  (Jeremy Schneider <schnjere@amazon.com>)
Ответы Re: CVE-2019-9193 about COPY FROM/TO PROGRAM  (Magnus Hagander <magnus@hagander.net>)
Список pgsql-general
Jeremy Schneider <schnjere@amazon.com> writes:
> I'm all for having clear documentation about the security model in
> PostgreSQL, but I personally wouldn't be in favor of adding extra
> wording to the docs just to pacify concerns about a CVE which may have
> been erroneously granted by an assigning authority, who possibly should
> have done better due diligence reviewing the content. Particularly if
> there's any possibility that the decision to assign the number can be
> appealed/changed, though admittedly I know very little about the CVE
> process.

Just FYI, we have filed a dispute with Mitre about the CVE, and also
reached out to trustwave to try to find out why they filed the CVE
despite the earlier private discussion.

            regards, tom lane



В списке pgsql-general по дате отправления:

Предыдущее
От: Jeremy Schneider
Дата:
Сообщение: Re: CVE-2019-9193 about COPY FROM/TO PROGRAM
Следующее
От: Magnus Hagander
Дата:
Сообщение: Re: CVE-2019-9193 about COPY FROM/TO PROGRAM