Skip site navigation (1) Skip section navigation (2)

Re: [BUGS] grant/revoke bug with delete/update

From: Jerome ALET <alet(at)unice(dot)fr>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: Peter Eisentraut <peter_e(at)gmx(dot)net>, Bruce Momjian <pgman(at)candle(dot)pha(dot)pa(dot)us>, Jerome ALET <alet(at)taloa(dot)unice(dot)fr>, pgsql-bugs(at)postgresql(dot)org
Subject: Re: [BUGS] grant/revoke bug with delete/update
Date: 2000-03-07 10:05:46
Message-ID: Pine.LNX.3.96.1000307102741.18666A-100000@cortex.unice.fr (view raw or flat)
Thread:
Lists: pgsql-bugspgsql-hackers
On Tue, 7 Mar 2000, Tom Lane wrote:
> It looked to me like a definition change that hadn't been adequately
> discussed.  We tend to be especially leery of those during beta;
> rushing in a "bug fix" that may prove to have been a bad idea is
> not productive.

ok, but what are you planning to do and when to correct this security
issue ?

I agree it's not a complete rewrite of acls in postgresql, which maybe (I
don't know) need to be rewritten from scratch, because I'm really not able
to do this. However saying that a quick fix to correct a major security
problem is a bad idea makes me laugh loudly (or cry, if you prefer).

for now and until someone acts correctly regarding this problem, I'll
patch my good old 6.5.2 version and use it, and you can throw my patch in
your ass or wherever you prefer if you don't want it.

Don't even expect me to rewrite this patch for 7.0, because it's not my
problem anymore, it's yours (and other postgresql users') !

I really don't mind you don't include my patch in postgresql, what I'm
concerned about is that you don't plan anything to quickly solve this
problem. Maybe you don't know, which would surprise me, but some people
write programs which rely on acls and other SQL features working
correctly.

At least you should document this security problem.

Don't try to tell me to use another product, because unfortunately for you
I really like postgresql. 

thank you for reading.

Peter: thanks again for your support.

bye,

Jerome



In response to

Responses

pgsql-hackers by date

Next:From: Patrick WelcheDate: 2000-03-07 14:52:27
Subject: alter_table.sql
Previous:From: Jacopo SilvaDate: 2000-03-07 08:45:44
Subject: pSQL auth

pgsql-bugs by date

Next:From: Bruce MomjianDate: 2000-03-07 22:50:57
Subject: Re: [HACKERS] Re: [BUGS] uniqueness not always correct
Previous:From: Tom LaneDate: 2000-03-07 06:51:32
Subject: Re: [BUGS] grant/revoke bug with delete/update

Privacy Policy | About PostgreSQL
Copyright © 1996-2014 The PostgreSQL Global Development Group