Re: CVE-2019-9193 about COPY FROM/TO PROGRAM

Поиск
Список
Период
Сортировка
От Brad Nicholson
Тема Re: CVE-2019-9193 about COPY FROM/TO PROGRAM
Дата
Msg-id OF1C5515C9.AC2B9DD6-ON852583D0.0044DEB2-852583D0.0045202D@notes.na.collabserv.com
обсуждение исходный текст
Ответ на Re: CVE-2019-9193 about COPY FROM/TO PROGRAM  (Michael Paquier <michael@paquier.xyz>)
Ответы Re: CVE-2019-9193 about COPY FROM/TO PROGRAM
Re: CVE-2019-9193 about COPY FROM/TO PROGRAM
Список pgsql-general

Michael Paquier <michael@paquier.xyz> wrote on 04/02/2019 01:05:01 AM:

> From: Michael Paquier <michael@paquier.xyz>

> To: "Jonathan S. Katz" <jkatz@postgresql.org>
> Cc: Tom Lane <tgl@sss.pgh.pa.us>, Magnus Hagander
> <magnus@hagander.net>, Daniel Verite <daniel@manitou-mail.org>,
> pgsql-general <pgsql-general@lists.postgresql.org>

> Date: 04/02/2019 01:05 AM
> Subject: Re: CVE-2019-9193 about COPY FROM/TO PROGRAM
>
> On Mon, Apr 01, 2019 at 10:04:32AM -0400, Jonathan S. Katz wrote:
> > +1, though I’d want to see if people get noisier about it before we rule
> > out an official response.
> >
> > A blog post from a reputable author who can speak to security should
> > be good enough and we can make noise through our various channels.
>
> Need a hand?  Not sure if I am reputable enough though :)
>
> By the way, it could be the occasion to consider an official
> PostgreSQL blog on the main website.  News are not really a model
> adapted for problem analysis and for entering into technical details.

A blog post would be nice, but it seems to me have something about this clearly in the manual would be best, assuming it's not there already.  I took a quick look, and couldn't find anything.

Brad

В списке pgsql-general по дате отправления:

Предыдущее
От: Alban Hertroys
Дата:
Сообщение: Re: WAL Archive Cleanup?
Следующее
От: "Jonathan S. Katz"
Дата:
Сообщение: Re: CVE-2019-9193 about COPY FROM/TO PROGRAM