Re: @(#)Mordred Labs advisory 0x0003: Buffer overflow in

From: "Marc G(dot) Fournier" <scrappy(at)hub(dot)org>
To: Justin Clift <justin(at)postgresql(dot)org>
Cc: Bruce Momjian <pgman(at)candle(dot)pha(dot)pa(dot)us>, Robert Treat <xzilla(at)users(dot)sourceforge(dot)net>, Neil Conway <neilc(at)samurai(dot)com>, Gavin Sherry <swm(at)linuxworld(dot)com(dot)au>, Christopher Kings-Lynne <chriskl(at)familyhealth(dot)com(dot)au>, <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: @(#)Mordred Labs advisory 0x0003: Buffer overflow in
Date: 2002-08-21 17:52:27
Message-ID: 20020821145058.D36114-100000@mail1.hub.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

On Thu, 22 Aug 2002, Justin Clift wrote:

> - Find out from Sir Mordred if he wants to take a look at the CVS
> version of code and audit in that for a bit, Just In Case he turns
> up something that's serious and requires substantial re-work.
> Although it means he wouldn't have a bunch of "I found this existing
> exploit" type releases, we could instead offer him credit on the
> press release along the lines of "This released has been audited for
> security flaws in its code by Sir Mordred". Am pretty sure he'd
> do a very thorough job for that, as it means he'd have an official
> "product reputation" he'd need to stand by for it.

"Security Relatd Fixed" are applicable for adoption during the beta
period, leading up to release ...

> - Patches to the CVS tree which let us have a truly native windows
> version. This is of huge significance and would *very* much improve
> our growth and adoption by being in this release in comparison to
> being in the release afterwards. Not in an airy fairy way, but
> quite definitely and solidly.

If they aren't in by now, they should wait until the next dev cycle ...
unless they are *small* changes ...

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message Marc G. Fournier 2002-08-21 17:57:35 Re: @(#)Mordred Labs advisory 0x0003: Buffer overflow in
Previous Message Marc G. Fournier 2002-08-21 17:50:36 Re: @(#)Mordred Labs advisory 0x0003: Buffer overflow in