Re: [HACKERS] @(#)Mordred Labs advisory 0x0006: Two minor DoS conditions in PostgreSQL

2002-08-26 Thread Neil Conway
Sir Mordred The Traitor <[EMAIL PROTECTED]> writes: > template1=# select substring('',2,2147483647); With CVS HEAD (with database encoding = SQL_ASCII and UNICODE), I get: nconway=# select substring('',2,2147483647); ERROR: negative substring length not allowed With REL7_

[HACKERS] @(#)Mordred Labs advisory 0x0006: Two minor DoS conditions in PostgreSQL

2002-08-26 Thread Sir Mordred The Traitor
"..if someone has direct SQL access to your database, they can already do more damage than what this vulnerability addresses. Specifically DROP TABLE is available to users with direct SQL command line access..." That's true of course, but i really dont want to do any damage, i might even don't