Re: PostgreSQL buffer exploits

From: Bruce Momjian <pgman(at)candle(dot)pha(dot)pa(dot)us>
To: Justin Clift <justin(at)postgresql(dot)org>
Cc: PostgreSQL General Mailing List <pgsql-general(at)postgresql(dot)org>, PostgreSQL Hackers Mailing List <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: PostgreSQL buffer exploits
Date: 2001-08-16 13:33:16
Message-ID: 200108161333.f7GDXGj12094@candle.pha.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general pgsql-hackers

> Hi all,
>
> Just wondering if anyone knows of or has tested for PostgreSQL buffer
> exploits over the various interfaces (JDBC, ODBC, psql, etc) or directly
> through socket connections?
>
> Working on a sensitive application at the moment, and I've realised I've
> never seen anyone mention testing PostgreSQL in this regard yet.

I never heard of any tests, nor any security failures either.

--
Bruce Momjian | http://candle.pha.pa.us
pgman(at)candle(dot)pha(dot)pa(dot)us | (610) 853-3000
+ If your life is a hard drive, | 830 Blythe Avenue
+ Christ can be your backup. | Drexel Hill, Pennsylvania 19026

In response to

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Jason Earl 2001-08-16 13:39:31 Re: Roll Back dont roll back counters
Previous Message Bruce Momjian 2001-08-16 13:32:12 Re: The -o command line option of pg_dump for a database using foreign keys

Browse pgsql-hackers by date

  From Date Subject
Next Message Tom Lane 2001-08-16 13:43:30 Re: encoding names
Previous Message Karel Zak 2001-08-16 13:31:41 Re: encoding names