Re: [GENERAL] PostgreSQL 7.2.2: Security Release

Поиск
Список
Период
Сортировка
От Neil Conway
Тема Re: [GENERAL] PostgreSQL 7.2.2: Security Release
Дата
Msg-id 87adncc3hx.fsf@mailbox.samurai.com
обсуждение исходный текст
Ответ на Re: [GENERAL] PostgreSQL 7.2.2: Security Release  (Bruce Momjian <pgman@candle.pha.pa.us>)
Ответы Re: [GENERAL] PostgreSQL 7.2.2: Security Release
Список pgsql-hackers
Bruce Momjian <pgman@candle.pha.pa.us> writes:
> Marc G. Fournier wrote:
> > Although v7.2.2 is a purely plug-n-play upgrade from v7.2.1, requiring no
> > dump-n-reload of the database, it should be noted that these
> > vulnerabilities are only critical on "open" or "shared" systems, as they
> > require the ability to be able to connect to the database before they can
> > be exploited.
> 
> Excellent idea you pointed this out.

... except that it's not correct. The datetime overrun does not
require the ability to connect to the database.

Cheers,

Neil

-- 
Neil Conway <neilc@samurai.com> || PGP Key ID: DB3C29FC



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Bruce Momjian
Дата:
Сообщение: Re: Large file support available
Следующее
От: "Marc G. Fournier"
Дата:
Сообщение: Re: [GENERAL] PostgreSQL 7.2.2: Security Release