Re: postgres vulnerability

From: David Garamond <lists(at)zara(dot)6(dot)isreserved(dot)com>
To: Gaetano Mendola <mendola(at)bigfoot(dot)com>
Cc: Neil Conway <neilc(at)samurai(dot)com>, pgsql-hackers(at)postgresql(dot)org
Subject: Re: postgres vulnerability
Date: 2004-10-10 11:07:54
Message-ID: 4169180A.6090901@zara.6.isreserved.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Gaetano Mendola wrote:
> Neil Conway wrote:
> > Gaetano Mendola wrote:
> >
> >> Here http://www.sans.org/top20/#u9
> >> are listed postgres vulnerability it's sad see that almost all
> >> are related to third part components
> >
> >
> > "Almost all"? By my count, 12 of the 17 vulnerabilities refer to
> > legitimate problems in PostgreSQL, its RPM distribution, or the ODBC
> > driver.
>
> I consider RPM distribution and ODBC driver as third part component.

Unless the vulnerability is introduced by a patch in the RPM, RPM is
just a compiled version of the original. Thus, not third party code.

> However doing a full scan :-) on all bugs I widthraw "almost all".

--
dave

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Gaetano Mendola 2004-10-10 12:38:40 Re: postgres vulnerability
Previous Message Gaetano Mendola 2004-10-10 09:25:23 Re: First set of OSDL Shared Mem scalability results, some wierdness