Discussion:
pgsql: Use temp files in current directory, not /tmp, to reduce security
(too old to reply)
Tom Lane
2004-10-20 16:42:46 UTC
Permalink
Log Message:
-----------
Use temp files in current directory, not /tmp, to reduce security risk
while running this script.

Modified Files:
--------------
pgsql/contrib/findoidjoins:
make_oidjoins_check (r1.4 -> r1.5)
(http://developer.postgresql.org/cvsweb.cgi/pgsql/contrib/findoidjoins/make_oidjoins_check.diff?r1=1.4&r2=1.5)

---------------------------(end of broadcast)---------------------------
TIP 1: subscribe and unsubscribe commands go to ***@postgresql.org
Neil Conway
2004-10-20 23:32:04 UTC
Permalink
Post by Tom Lane
Use temp files in current directory, not /tmp, to reduce security risk
while running this script.
IMHO this should be backpatched to REL7_4_STABLE.

-Neil



---------------------------(end of broadcast)---------------------------
TIP 2: you can get off all lists at once with the unregister command
(send "unregister YourEmailAddressHere" to ***@postgresql.org)
Neil Conway
2004-10-21 03:58:39 UTC
Permalink
This is well out in the get-a-life region of security issues.
Oh, absolutely, but if it's worth fixing at all, I think we may as well
backpatch it to 7.4 -- for no other reason than the security advisories
that are open right now can be closed.

-Neil



---------------------------(end of broadcast)---------------------------
TIP 9: the planner will ignore your desire to choose an index scan if your
joining column's datatypes do not match
Tom Lane
2004-10-21 02:51:39 UTC
Permalink
Post by Neil Conway
Post by Tom Lane
Use temp files in current directory, not /tmp, to reduce security risk
while running this script.
IMHO this should be backpatched to REL7_4_STABLE.
Who exactly will ever use this script again against 7.4?

This is well out in the get-a-life region of security issues.

regards, tom lane

---------------------------(end of broadcast)---------------------------
TIP 2: you can get off all lists at once with the unregister command
(send "unregister YourEmailAddressHere" to ***@postgresql.org)
Loading...