Re: [GENERAL] PostgreSQL 7.2.2: Security Release
От | Marc G. Fournier |
---|---|
Тема | Re: [GENERAL] PostgreSQL 7.2.2: Security Release |
Дата | |
Msg-id | 20020824010200.Y1769-100000@mail1.hub.org обсуждение исходный текст |
Ответ на | Re: [GENERAL] PostgreSQL 7.2.2: Security Release (Neil Conway <neilc@samurai.com>) |
Ответы |
Re: [GENERAL] PostgreSQL 7.2.2: Security Release
|
Список | pgsql-hackers |
On 23 Aug 2002, Neil Conway wrote: > Bruce Momjian <pgman@candle.pha.pa.us> writes: > > Marc G. Fournier wrote: > > > Although v7.2.2 is a purely plug-n-play upgrade from v7.2.1, requiring no > > > dump-n-reload of the database, it should be noted that these > > > vulnerabilities are only critical on "open" or "shared" systems, as they > > > require the ability to be able to connect to the database before they can > > > be exploited. > > > > Excellent idea you pointed this out. > > ... except that it's not correct. The datetime overrun does not > require the ability to connect to the database. Ack ... obviously I missed something, but, if you can't get a connection to the database, how exactly is this one triggered? :(
В списке pgsql-hackers по дате отправления: