Обсуждение: Multiple vulnerabilities in PostgreSQL

Поиск
Список
Период
Сортировка

Multiple vulnerabilities in PostgreSQL

От
Justin Clift
Дата:
Hi Mordred,

Thanks for doing this testing for vulnerabilities for us.

Some PostgreSQL team members have been looking to organise an "audit"
team to remove vulnerabilities like this, and your posts to BugTraq have
assisted in getting that further mobilised.

Something that is concerning us though, is that whilst one of these bugs
was known and on our "to fix" list, there are some that were not known
and you're not notifying us up front so we can fix them before details
are publicly released.

Would you be able to work in with us from here, notifying us of these
vulnerabilities with some decent amount of time in advance so we can
create the necessary patches/fixes, etc?

:-)

Regards and best wishes,

Justin Clift

-- 
"My grandfather once told me that there are two kinds of people: those
who work and those who take the credit. He told me to try to be in the
first group; there was less competition there."  - Indira Gandhi


Re: Multiple vulnerabilities in PostgreSQL

От
Justin Clift
Дата:
Hi Sir Mordred,

Forwarded your email on to that same "PostgreSQL Hackers" mailing list
(didn't seem to be anything confidential in it), just to let everyone
know that things will be ok from here on, etc.

No-one would generally even think to take credit for your work, as the
people in our community are the decent up-front kind of folk, and we
welcome your assistance and expertise in helping us find the
vulnerabilities in PostgreSQL.

So, yep, it's all cool with us.

:-)

Regards and best wishes,

Justin Clift


Sir Mordred The Traitor wrote:
> 
> Hi Justin.
> 
> >Something that is concerning us though, is that whilst one of these bugs
> >was known and on our "to fix" list, there are some that were not known
> >and you're not notifying us up front so we can fix them before details
> >are publicly released.
> 
> There is no reason to be concerned really.
> While a bastard like me do stupid things sometimes, from now i will be
> working with you guys.
> I'll be posting to pgsql-hackers@postgresql.org, and believe me, you will
> enough have time for fixing.
> After fixing, you will release an advisory and give me a credit. That will
> be enough for me.
> If that okay for you, let my know.
> 
> Best regards.
> 
> ________________________________________________________________________
> This letter has been delivered unencrypted. We'd like to remind you that
> the full protection of e-mail correspondence is provided by S-mail
> encryption mechanisms if only both, Sender and Recipient use S-mail.
> Register at S-mail.com: http://www.s-mail.com/inf/en

-- 
"My grandfather once told me that there are two kinds of people: those
who work and those who take the credit. He told me to try to be in the
first group; there was less competition there."  - Indira Gandhi