Re: Security lessons from liblzma

Поиск
Список
Период
Сортировка
От Thomas Munro
Тема Re: Security lessons from liblzma
Дата
Msg-id CA+hUKGK4ZewHeVtnbBc_pbZRHZa6GyO=UpJ5XDmomA9Lf0xpkA@mail.gmail.com
обсуждение исходный текст
Ответ на [MASSMAIL]Security lessons from liblzma  (Bruce Momjian <bruce@momjian.us>)
Список pgsql-hackers
On Sat, Mar 30, 2024 at 11:37 AM Bruce Momjian <bruce@momjian.us> wrote:
> You might have seen reports today about a very complex exploit added to
> recent versions of liblzma.  Fortunately, it was only enabled two months
> ago and has not been pushed to most stable operating systems like Debian
> and Ubuntu.  The original detection report is:
>
>         https://www.openwall.com/lists/oss-security/2024/03/29/4

Incredible work from Andres.  The attackers made a serious strategic
mistake: they made PostgreSQL slightly slower.



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Bruce Momjian
Дата:
Сообщение: [MASSMAIL]Security lessons from liblzma
Следующее
От: Andres Freund
Дата:
Сообщение: Re: Security lessons from liblzma