Re: [SECURITY] DoS attack on backend possible (was: Re:

Поиск
Список
Период
Сортировка
От Christopher Kings-Lynne
Тема Re: [SECURITY] DoS attack on backend possible (was: Re:
Дата
Msg-id GNELIHDDFBOCMGBFGEFOKEKACDAA.chriskl@familyhealth.com.au
обсуждение исходный текст
Ответ на Re: [SECURITY] DoS attack on backend possible (was: Re:  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-hackers
> Justin Clift <justin@postgresql.org> writes:
> > Am I understanding this right:
> >  - A PostgreSQL 7.2.1 server can be crashed if it gets passed certain
> > date values which would be accepted by standard "front end" parsing?
>
> AFAIK it's a buffer overrun issue, so anything that looks like a
> reasonable date would *not* cause the problem.

Still, I believe this should require a 7.2.2 release.  Imagine a university
database server for a course for example - the students would just crash it
all the time.

Chris



В списке pgsql-hackers по дате отправления:

Предыдущее
От: "Christopher Kings-Lynne"
Дата:
Сообщение: Re: python patch
Следующее
От: Justin Clift
Дата:
Сообщение: Re: [SECURITY] DoS attack on backend possible (was: Re: