Re: BUG #1198: Linux PostgreSQL Server Input Validation Vulnerability

Lists: pgsql-bugs
From: "PostgreSQL Bugs List" <pgsql-bugs(at)postgresql(dot)org>
To: pgsql-bugs(at)postgresql(dot)org
Subject: BUG #1198: Linux PostgreSQL Server Input Validation Vulnerability
Date: 2004-07-20 14:57:47
Message-ID: 20040720145747.B2118CF4CED@www.postgresql.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-bugs


The following bug has been logged online:

Bug reference: 1198
Logged by: iDEFENSE Vendor Disclosure

Email address: vendor-disclosure(at)idefense(dot)com

PostgreSQL version: 7.4

Operating system: Linux

Description: Linux PostgreSQL Server Input Validation Vulnerability

Details:

iDEFENSE has identified an input validation vulnerability in PostgreSQL .
This vulnerability was submitted to iDEFENSE through our Vulnerability
Contributor Program (http://www.idefense.com/poi/teams/vcp.jsp). iDEFENSE
Labs has validated this vulnerability and has drafted an advisory. I have
not included the advisory in this web form submission as it is unclear who
the target audience is. Please contact me at vendor-disclosure(at)idefense(dot)com
for a copy so that we can continue the process.

Regards,
Pedram Amini
Assistant Director, iDEFENSE Labs
pamini(at)idefense(dot)com

7/20/2004


From: Peter Eisentraut <peter_e(at)gmx(dot)net>
To: "iDEFENSE Vendor Disclosure" <vendor-disclosure(at)idefense(dot)com>, "PostgreSQL Bugs List" <pgsql-bugs(at)postgresql(dot)org>
Subject: Re: BUG #1198: Linux PostgreSQL Server Input Validation Vulnerability
Date: 2004-07-20 16:17:34
Message-ID: 200407201817.34587.peter_e@gmx.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-bugs

PostgreSQL Bugs List wrote:
> iDEFENSE has identified an input validation vulnerability in
> PostgreSQL . This vulnerability was submitted to iDEFENSE through our
> Vulnerability Contributor Program
> (http://www.idefense.com/poi/teams/vcp.jsp). iDEFENSE Labs has
> validated this vulnerability and has drafted an advisory. I have not
> included the advisory in this web form submission as it is unclear
> who the target audience is. Please contact me at
> vendor-disclosure(at)idefense(dot)com for a copy so that we can continue the
> process.

If you have a bug to report, this (pgsql-bugs(at)postgresql(dot)org) is the
right place.

--
Peter Eisentraut
http://developer.postgresql.org/~petere/