Re: reuse sysids security hole?

Поиск
Список
Период
Сортировка
От Gavin Sherry
Тема Re: reuse sysids security hole?
Дата
Msg-id Pine.LNX.4.21.0308130039410.17517-100000@linuxworld.com.au
обсуждение исходный текст
Ответ на reuse sysids security hole?  (Andrew Dunstan <andrew@dunslane.net>)
Ответы Re: reuse sysids security hole?  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-hackers
On Tue, 12 Aug 2003, Andrew Dunstan wrote:

> 
> (Thought triggered by something Tom said the other day)
> 
> Is this a security hole? Looks like one to me. Would it be better to use 
> a sequence generator for sysids instead of using max+1 on the user 
> table? Or else store the last sysid used somewhere?

This issue has been discussed before and it was agreed that since most
UNIX systems will behave in the same way, there's no way to know. Also, it
is not possible for a given database to know the max(sysid) of pg_user in
another database.

Thanks,

Gavin



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Andrew Dunstan
Дата:
Сообщение: reuse sysids security hole?
Следующее
От: Andrew Sullivan
Дата:
Сообщение: Re: Farewell