Re: Dissecting PostgreSQL CVE-2013-1899 (blackwinghq.com)

Поиск
Список
Период
Сортировка
От Josh Berkus
Тема Re: Dissecting PostgreSQL CVE-2013-1899 (blackwinghq.com)
Дата
Msg-id 5167496C.7040406@agliodbs.com
обсуждение исходный текст
Ответ на Re: Dissecting PostgreSQL CVE-2013-1899 (blackwinghq.com)  (Douglas J Hunley <doug.hunley@gmail.com>)
Список pgsql-advocacy
>
> I would hope people have tripwire/aide/et al configured to watch for these
> sorts of things already
>

Most of our non-cloud users connect to the DB from the application as
the superuser (the cloud users don't only because they're not allowed
to).  I think Tripwire is a little beyond them.

Anyway, the Blackwing analysis points out a whole set of potential
exploits which our security team hadn't thought of.

--
Josh Berkus
PostgreSQL Experts Inc.
http://pgexperts.com


В списке pgsql-advocacy по дате отправления:

Предыдущее
От: Bruce Momjian
Дата:
Сообщение: Re: Dissecting PostgreSQL CVE-2013-1899 (blackwinghq.com)
Следующее
От: "Greg Sabino Mullane"
Дата:
Сообщение: Re: Heroku early upgrade is raising serious questions