FW: iDefense Q2 2006 Vulnerability Challenge

From: "Magnus Hagander" <mha(at)sollentuna(dot)net>
To: <pgsql-hackers(at)postgresql(dot)org>
Subject: FW: iDefense Q2 2006 Vulnerability Challenge
Date: 2006-05-21 20:59:40
Message-ID: 6BCB9D8A16AC4241919521715F4D8BCEA0F996@algol.sollentuna.se
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

For those that haven't already seen it, this might give some extra
exposure to PostgreSQL wrt vulnerability research. Though I think nobody
will have a chance to find one (I just don't see how you could possibly
get root through postgresql, since we refuse to run as root), other
things might be exposed by someone who's poking around.

//Magnus

> -----Original Message-----
> From: labs-no-reply(at)idefense(dot)com [mailto:labs-no-reply(at)idefense(dot)com]
> Sent: Wednesday, May 17, 2006 7:15 AM
> To: bugtraq(at)securityfocus(dot)com; vulnwatch(at)vulnwatch(dot)org;
> full-disclosure(at)lists(dot)grok(dot)org(dot)uk
> Subject: iDefense Q2 2006 Vulnerability Challenge
>
> iDefense Labs is pleased to announce the launch of next
> installment in our quarterly vulnerability challenge. Last
> quarter's challenge focused on critical vulnerabilities in
> Microsoft products and was a great success. We would like to
> thank everyone that forwarded submissions prior to the
> deadline on March 31, 2006. We look forward to announcing
> award winners once public advisories become available for the
> vulnerabilities.
>
> For the second quarter of 2006, we're shifting the focus from
> vendor to technology. This time around, we're focusing on
> database vulnerabilities. For submissions received before
> June 30, 2006, iDefense Labs will pay $10,000 for each
> vulnerability submission that results in the discovery of a
> remotely exploitable database vulnerability that meets the
> following criteria.
>
> - Technologies:
> - Oracle Database 10G
> - Microsoft SQL Server 2005
> - IBM DB Universal Database 8.2
> - MySQL 5.0
> - PostgreSQL 8.1
> - The vulnerability must be original and not previously
> disclosed either
> publicly or to the vendor by another party
> - The vulnerability must be remotely exploitable in a default
> installation of one of the targeted technologies
> - The vulnerability must exist in the latest version of the affected
> technology with all current patches/upgrades applied
> - The vulnerability cannot be caused by or require third
> party software
> - The vulnerability must result in root access on the target machine
> - The vulnerability must not require the use of authentication
> credentials
> - The vulnerability must receive the vendor's maximum severity ranking
> when the advisory is published (if applicable).
>
> In order to qualify, the submission must be sent during the
> current quarter and be received by midnight EST on June 30,
> 2006. The $10,000 prizes will be paid out following
> confirmation with the affected vendor and will be paid in
> addition to any amount paid for the vulnerability when it is
> first accepted. Only the initial submission for a given
> vulnerability will qualify for the reward and a maximum of
> six awards will be paid out. Should more than six submissions
> qualify, the first six submissions will receive the reward.
>
> Further details on the iDefense Vulnerability Contributor
> Program (VCP) can be found at:
>
> http://labs.idefense.com/vcp.php
>
> Michael Sutton
> Director, iDefense Labs
>
>
>

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Jeff Frost 2006-05-21 21:16:15 Re: does wal archiving block the current client connection?
Previous Message Jaime Casanova 2006-05-21 18:31:01 Re: COMMIT leads to ROLLBACK