Re: [COMMITTERS] pgsql: Fix failure due to accessing an

From: Tatsuo Ishii <ishii(at)postgresql(dot)org>
To: tgl(at)sss(dot)pgh(dot)pa(dot)us
Cc: ishii(at)sraoss(dot)co(dot)jp, pgsql-hackers(at)postgresql(dot)org
Subject: Re: [COMMITTERS] pgsql: Fix failure due to accessing an
Date: 2007-01-18 22:30:41
Message-ID: 20070119.073041.77425384.t-ishii@sraoss.co.jp
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-committers pgsql-hackers

Ok, understood.
--
Tatsuo Ishii
SRA OSS, Inc. Japan

> Tatsuo Ishii <ishii(at)sraoss(dot)co(dot)jp> writes:
> > One of our engineer claimed that double free bug itself is a
> > vulnerability, thus 8.2.1 release should be called as "security
> > release".
>
> [ shrug... ] AFAICS the crashing bugs we fixed in 8.2.1 can't be
> exploited for anything beyond crashing the backend, and only by an
> attacker who can issue arbitrary SQL commands. There are plenty of
> other ways to cause momentary DOS if you can do that, so it doesn't
> strike me as a big security vulnerability. But if you want to call
> it one, you can.
>
> regards, tom lane
>
> ---------------------------(end of broadcast)---------------------------
> TIP 1: if posting/reading through Usenet, please send an appropriate
> subscribe-nomail command to majordomo(at)postgresql(dot)org so that your
> message can get through to the mailing list cleanly
>

In response to

Browse pgsql-committers by date

  From Date Subject
Next Message Alvaro Herrera 2007-01-18 23:13:12 Windows buildfarm failures
Previous Message Tom Lane 2007-01-18 16:42:20 Re: [COMMITTERS] pgsql: Fix failure due to accessing an

Browse pgsql-hackers by date

  From Date Subject
Next Message Alvaro Herrera 2007-01-18 23:13:12 Windows buildfarm failures
Previous Message Adnan DURSUN 2007-01-18 22:09:17 Re: Temparary disable constraint