Re: CVE-2019-9193 about COPY FROM/TO PROGRAM

From: Michael Paquier <michael(at)paquier(dot)xyz>
To: "Jonathan S(dot) Katz" <jkatz(at)postgresql(dot)org>
Cc: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, Magnus Hagander <magnus(at)hagander(dot)net>, Daniel Verite <daniel(at)manitou-mail(dot)org>, pgsql-general <pgsql-general(at)lists(dot)postgresql(dot)org>
Subject: Re: CVE-2019-9193 about COPY FROM/TO PROGRAM
Date: 2019-04-02 05:05:01
Message-ID: 20190402050501.GN16093@paquier.xyz
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

On Mon, Apr 01, 2019 at 10:04:32AM -0400, Jonathan S. Katz wrote:
> +1, though I’d want to see if people get noisier about it before we rule
> out an official response.
>
> A blog post from a reputable author who can speak to security should
> be good enough and we can make noise through our various channels.

Need a hand? Not sure if I am reputable enough though :)

By the way, it could be the occasion to consider an official
PostgreSQL blog on the main website. News are not really a model
adapted for problem analysis and for entering into technical details.
--
Michael

In response to

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Alban Hertroys 2019-04-02 10:28:57 Re: WAL Archive Cleanup?
Previous Message 김준형 2019-04-02 05:03:57 Fwd: Postgresql with nextcloud in Windows Server