Re: [SECURITY] DoS attack on backend possible (was: Re:

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Justin Clift <justin(at)postgresql(dot)org>
Cc: Florian Weimer <Weimer(at)CERT(dot)Uni-Stuttgart(dot)DE>, pgsql-hackers(at)postgresql(dot)org
Subject: Re: [SECURITY] DoS attack on backend possible (was: Re:
Date: 2002-08-11 17:09:41
Message-ID: 14467.1029085781@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-committers pgsql-hackers

Justin Clift <justin(at)postgresql(dot)org> writes:
> Am I understanding this right:
> - A PostgreSQL 7.2.1 server can be crashed if it gets passed certain
> date values which would be accepted by standard "front end" parsing?

AFAIK it's a buffer overrun issue, so anything that looks like a
reasonable date would *not* cause the problem.

regards, tom lane

In response to

Responses

Browse pgsql-committers by date

  From Date Subject
Next Message Florian Weimer 2002-08-11 17:17:20 Re: [SECURITY] DoS attack on backend possible (was: Re:
Previous Message Justin Clift 2002-08-11 16:26:56 Re: [SECURITY] DoS attack on backend possible (was: Re:

Browse pgsql-hackers by date

  From Date Subject
Next Message Joe Conway 2002-08-11 17:15:43 Re: [GENERAL] workaround for lack of REPLACE() function
Previous Message Justin Clift 2002-08-11 16:26:56 Re: [SECURITY] DoS attack on backend possible (was: Re: