Re: Probably security hole in postgresql-7.4.1

From: Shachar Shemesh <psql(at)shemesh(dot)biz>
To: Bruno Wolff III <bruno(at)wolff(dot)to>
Cc: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, Bruce Momjian <pgman(at)candle(dot)pha(dot)pa(dot)us>, pgsql-hackers(at)postgresql(dot)org
Subject: Re: Probably security hole in postgresql-7.4.1
Date: 2004-05-12 20:36:49
Message-ID: 40A28AE1.8030304@shemesh.biz
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Bruno Wolff III wrote:

>On Wed, May 12, 2004 at 10:46:00 +0300,
> Shachar Shemesh <psql(at)shemesh(dot)biz> wrote:
>
>
>>Industry practices dictate that we do issue SOMETHING now. The bug is
>>now public, and can be exploited.
>>
>>
>
>The description of the problem indicates that it can only be exploited
>after you have authenticated to the database. Since people who can
>connect to a postgres database can already cause denial of service
>attacks, this problem isn't a huge deal.
>
My take on this is different. To me, a DoS is a nuisance, but an
arbitrary code execution vulnerability means information leak, and a
major escalation (from which further escalation may be possible).

> It makes breaches in other
>programs (web server process especially) worse and provides another
>way for authorized users to cause problems.
>
>
Not to mention being another chain.

>A release should probably be made soon, as a way to advertise the problem
>so that people are aware of it and can take appropiate steps. I don't think
>that this problem warrants bypassing normal minor release proceedure.
>
>
Ok. How about an official patch against 7.4.2 that fixes it, so that
packagers can make their own informed decision. Also, has anybody
checked what other versions are affected? Is 7.3? 7.2? Some people can't
afford to upgrade due to data inconsistancy.

For those reasons I suggested a seperate mailing list.

Shachar

--
Shachar Shemesh
Lingnu Open Source Consulting
http://www.lingnu.com/

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Tom Lane 2004-05-12 21:29:55 Re: Probably security hole in postgresql-7.4.1
Previous Message Jan Wieck 2004-05-12 20:32:24 Re: pgsql-server/src backend/utils/adt/acl.c inclu ...