Re: [GENERAL] postgresql command line exploit found in the wild

2013-04-09 Thread Christoph Berg
Re: Daniel Verite 2013-04-08 > Merlin Moncure wrote: > > > if you have an internet facing database, patch it immediately! > > By the way: > > People running 9.1 on debian stable (squeeze) typically use this package: > http://packages.debian.org/squeeze-backports/postgresql-9.1 > > Curren

Re: [GENERAL] postgresql command line exploit found in the wild

2013-04-08 Thread Merlin Moncure
On Mon, Apr 8, 2013 at 10:48 AM, Daniel Verite wrote: > Merlin Moncure wrote: > >> if you have an internet facing database, patch it immediately! > > By the way: > > People running 9.1 on debian stable (squeeze) typically use this package: > http://packages.debian.org/squeeze-backports/pos

Re: [GENERAL] postgresql command line exploit found in the wild

2013-04-08 Thread Daniel Verite
Merlin Moncure wrote: > if you have an internet facing database, patch it immediately! By the way: People running 9.1 on debian stable (squeeze) typically use this package: http://packages.debian.org/squeeze-backports/postgresql-9.1 Currently, it looks like the fix is only available in

[GENERAL] postgresql command line exploit found in the wild

2013-04-08 Thread Merlin Moncure
see: http://schemaverse.tumblr.com/post/47312545952/the-schemaverse-was-hacked if you have an internet facing database, patch it immediately! (personally, I would only do this through a service such as pgbouncer runnning under extremely limited account). do not delay! merlin -- Sent via pgsql