Re: [COMMITTERS] pgsql-server/src include/utils/timestamp.h bac ...

Поиск
Список
Период
Сортировка
От Florian Weimer
Тема Re: [COMMITTERS] pgsql-server/src include/utils/timestamp.h bac ...
Дата
Msg-id 87ado27boy.fsf@CERT.Uni-Stuttgart.DE
обсуждение исходный текст
Ответы Re: [COMMITTERS] pgsql-server/src include/utils/timestamp.h bac ...
Список pgsql-hackers
thomas@postgresql.org (Thomas Lockhart) writes:

> Log message:
>     Add guard code to protect from buffer overruns on long date/time input
>     strings. Should go back in and look at doing this a bit more elegantly
>     and (hopefully) cheaper. Probably not too bad anyway, but it seems a
>     shame to scan the strings twice: once for length for this buffer overrun
>     protection, and once to parse the line.

Are these changes available for 7.2, too?  There is at least a DoS
potential lurking here. :-(

-- 
Florian Weimer                       Weimer@CERT.Uni-Stuttgart.DE
University of Stuttgart           http://CERT.Uni-Stuttgart.DE/people/fw/
RUS-CERT                          fax +49-711-685-5898


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: [COMMITTERS] pgsql-server/src backend/tcop/postgres.c backe ...
Следующее
От: Bruce Momjian
Дата:
Сообщение: Re: [COMMITTERS] pgsql-server/src backend/tcop/postgres.c