Re: [HACKERS] [GENERAL] PostgreSQL 7.2.2: Security Release

2002-08-26 Thread Marc G. Fournier
; Cc: Gavin Sherry; Neil Conway; PostgreSQL Hackers > > Subject: Re: [HACKERS] [GENERAL] PostgreSQL 7.2.2: Security Release > > > > > > On Sun, 25 Aug 2002, Bruce Momjian wrote: > > > > > > > > OK, I understand your point. What do we need to do now tha

Re: [HACKERS] [GENERAL] PostgreSQL 7.2.2: Security Release

2002-08-25 Thread Christopher Kings-Lynne
iginal Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED]]On Behalf Of Marc G. Fournier > Sent: Monday, 26 August 2002 10:17 AM > To: Bruce Momjian > Cc: Gavin Sherry; Neil Conway; PostgreSQL Hackers > Subject: Re: [HACKERS] [GENERAL] PostgreSQL 7.2.2: Security Rele

Re: [HACKERS] [GENERAL] PostgreSQL 7.2.2: Security Release

2002-08-25 Thread Marc G. Fournier
On Sun, 25 Aug 2002, Bruce Momjian wrote: > > OK, I understand your point. What do we need to do now that the > announcement has already been made? I'm still slightly confused here ... from what Neil/Gavin have stated so far, all it sounds like is that if I pass a wrong date/time string, it wil

Re: [HACKERS] [GENERAL] PostgreSQL 7.2.2: Security Release

2002-08-25 Thread Bruce Momjian
OK, I understand your point. What do we need to do now that the announcement has already been made? --- Gavin Sherry wrote: > On Sat, 24 Aug 2002, Bruce Momjian wrote: > > > > > The issue is data-provoked crashes vs. que

Re: [HACKERS] [GENERAL] PostgreSQL 7.2.2: Security Release

2002-08-25 Thread Gavin Sherry
On Sat, 24 Aug 2002, Bruce Momjian wrote: > > The issue is data-provoked crashes vs. query-invoked crashes. Marc's > point, and I think it was clear enough, is that you can't just poke at > the TCP port and hope to do anything bad, which was the thrust of the > argument, I think. Bruce, I am