Re: BUG #5938: PostgreSQL Installer outputs log file with superuser password in clear text

From: Dave Page <dpage(at)pgadmin(dot)org>
To: Craig Sacco <craig(dot)sacco(at)gmail(dot)com>
Cc: pgsql-bugs(at)postgresql(dot)org
Subject: Re: BUG #5938: PostgreSQL Installer outputs log file with superuser password in clear text
Date: 2011-03-24 09:12:38
Message-ID: AANLkTikX8oZO0Vc-5yn_==e2_HnJsvVh3WkLWk0rX9cB@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-bugs

On Tue, Mar 22, 2011 at 4:09 PM, Dave Page <dpage(at)pgadmin(dot)org> wrote:
>
>
> On Tue, Mar 22, 2011 at 3:45 PM, Dave Page <dpage(at)pgadmin(dot)org> wrote:
>>
>>
>> On Tue, Mar 22, 2011 at 5:10 AM, Craig Sacco <craig(dot)sacco(at)gmail(dot)com>
>> wrote:
>>>
>>> The following bug has been logged online:
>>>
>>> Bug reference:      5938
>>> Logged by:          Craig Sacco
>>> Email address:      craig(dot)sacco(at)gmail(dot)com
>>> PostgreSQL version: 9.0.3
>>> Operating system:   Microsoft Windows (all variants, 32 and 64 bit)
>>> Description:        PostgreSQL Installer outputs log file with superuser
>>> password in clear text
>>> Details:
>>>
>>> The PostgreSQL installer outputs a log file to the temporary directory
>>> with
>>> the superuser password in clear text. We are deploying PostgreSQL as part
>>> of
>>> a commercial product and would like to ensure that the password is not
>>> available to ordinary users.
>>>
>>
>> This has been fixed for the next releases.
>
> For the sake of the archives, it should also be noted that the file is in a
> secure directory, much as a .pgpass file would be, so this is generally only
> an issue for the situation described above, and not when a user installs a
> copy himself.

Updated "one click" installers for 9.0.3 on win32 and win64 and for
8.4.7 on win32 are now available from
http://www.postgresql.org/download/windows

--
Dave Page
Blog: http://pgsnake.blogspot.com
Twitter: @pgsnake

EnterpriseDB UK: http://www.enterprisedb.com
The Enterprise PostgreSQL Company

In response to

Browse pgsql-bugs by date

  From Date Subject
Next Message Fujii Masao 2011-03-24 12:13:44 Re: postgres 9 streaming replication
Previous Message Viner, Adrian 2011-03-24 09:12:12 Service Wont Start