Re: Probably security hole in postgresql-7.4.1

Поиск
Список
Период
Сортировка
От Greg Stark
Тема Re: Probably security hole in postgresql-7.4.1
Дата
Msg-id 87k6zhr287.fsf@stark.xeocode.com
обсуждение исходный текст
Ответ на Re: Probably security hole in postgresql-7.4.1  (Shachar Shemesh <psql@shemesh.biz>)
Ответы Re: Probably security hole in postgresql-7.4.1
Список pgsql-hackers
Shachar Shemesh <psql@shemesh.biz> writes:

> Also, if we want greater flexibility in handling these cases in the future, we
> should set up an invite-only list for reporting security bugs, and advertise it
> on the web site as the place to report security issues. Had this vulnerability
> been reported there, we could reasonably hold on without releasing a fix until
> 7.4.3 was ready.

A lot of people would be unhappy with that approach. A) they don't know the
people on the invite-only list and have no basis to trust them and B) Often
when a white hat reports the problem the black hats have known about it for
much longer already.

-- 
greg



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Larry Rosenman
Дата:
Сообщение: Re: threads stuff/UnixWare
Следующее
От: Thomas Hallgren
Дата:
Сообщение: Parser change needed?