Re: [GENERAL] PostgreSQL Security Release(s) for 7.2, 7.3 and 7.4

2004-10-24 Thread Tom Lane
Neil Conway <[EMAIL PROTECTED]> writes: > On Mon, 2004-10-25 at 00:43, Tom Lane wrote: >> He's not. There were two other recent security reports, which core kept >> to ourselves until the release could be made. > Ah, ok -- fair enough. Are those additional security fixes mentioned in > the releas

Re: [GENERAL] PostgreSQL Security Release(s) for 7.2, 7.3 and 7.4

2004-10-24 Thread Neil Conway
On Mon, 2004-10-25 at 00:43, Tom Lane wrote: > He's not. There were two other recent security reports, which core kept > to ourselves until the release could be made. Ah, ok -- fair enough. Are those additional security fixes mentioned in the release notes? -Neil ---(e

Re: [GENERAL] PostgreSQL Security Release(s) for 7.2, 7.3 and 7.4

2004-10-24 Thread Tom Lane
Neil Conway <[EMAIL PROTECTED]> writes: > Marc G. Fournier wrote: >> In order to address a recent security report from iDefence, we have >> released 3 new "point" releases: 7.2.6, 7.3.8 and 7.4.6 > Assuming you're referring to the make_oidjoins_check bug, He's not. There were two other recent s

Re: [GENERAL] PostgreSQL Security Release(s) for 7.2, 7.3 and 7.4

2004-10-24 Thread Neil Conway
Marc G. Fournier wrote: In order to address a recent security report from iDefence, we have released 3 new "point" releases: 7.2.6, 7.3.8 and 7.4.6 Assuming you're referring to the make_oidjoins_check bug, I don't think it is accurate to bill these as "security releases". As the 7.4.6 release no

[GENERAL] PostgreSQL Security Release(s) for 7.2, 7.3 and 7.4

2004-10-23 Thread Marc G. Fournier
In order to address a recent security report from iDefence, we have released 3 new "point" releases: 7.2.6, 7.3.8 and 7.4.6 Although rated only a Medium risk, according to their web site: "A vulnerability exists due to the insecure creation of temporary files, which could possibly let a malicio