Re: [WEBMASTER] 'www/html/devel-corner index.html'

From: Vince Vielhaber <vev(at)michvhf(dot)com>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: Alfred Perlstein <bright(at)wintelcom(dot)net>, pg-web(at)hub(dot)org, pgsql-committers(at)postgresql(dot)org
Subject: Re: [WEBMASTER] 'www/html/devel-corner index.html'
Date: 2000-09-25 20:32:40
Message-ID: Pine.BSF.4.21.0009251632300.15433-100000@paprika.michvhf.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-committers

On Mon, 25 Sep 2000, Tom Lane wrote:

> Alfred Perlstein <bright(at)wintelcom(dot)net> writes:
> > It's on security focus:
>
> > Cvsweb 1.80 makes an insecure call to the
> > perl OPEN function, providing attackers with
> > write access to a cvs repository the ability to
> ^^^^^^^^^^^^
> > execute arbitrary commands on the host
> > machine. The code that is being exploited
> > here is the following: open($fh, "rlog
> > '$filenames' 2>/dev/null |")
>
> > Actually, now that I've looked at it you guys seem to be using 1.93
> > a bit newer than the vulnerable version.
>
> Since we don't hand out cvs write access very freely, this doesn't seem
> like a big problem. Still, it might be a good idea to actually remove
> the old version of cvsweb (cvswebtest) rather than just not have it
> linked to anymore ...

Done.

>
>
> > Do you guys have a private developers' list that doesn't get broadcast
> > back out that I can use if anything like this pops up in the future?
>
> You can send security concerns to pgsql-core(at)postgreSQL(dot)org --- the core
> list isn't publicly readable (or even archived anywhere, AFAIK).
>
> regards, tom lane
>

--
==========================================================================
Vince Vielhaber -- KA8CSH email: vev(at)michvhf(dot)com http://www.pop4.net
128K ISDN from $22.00/mo - 56K Dialup from $16.00/mo at Pop4 Networking
Online Campground Directory http://www.camping-usa.com
Online Giftshop Superstore http://www.cloudninegifts.com
==========================================================================

In response to

Browse pgsql-committers by date

  From Date Subject
Next Message Peter Eisentraut - PostgreSQL 2000-09-25 22:22:53 pgsql (aclocal.m4 configure configure.in)
Previous Message Tom Lane 2000-09-25 20:04:05 Re: [WEBMASTER] 'www/html/devel-corner index.html'