Re: "Bug" report - Serious (local shell)

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: "Bug" report - Serious (local shell)
Дата
Msg-id 6915.1060888963@sss.pgh.pa.us
обсуждение исходный текст
Ответ на "Bug" report - Serious (local shell)  (Diego Linke - GAMK <linke@calnet.com.br>)
Список pgsql-bugs
Diego Linke - GAMK <linke@calnet.com.br> writes:
> The problem is that postgresql when calls a function in external C,
> calls with user of the postgres.

The ability to create C functions is reserved to superusers, for exactly
this reason.  If you have the rights to make the backend execute
arbitrary C code, you hardly need a shell to do something nasty.

In short, this is not a bug.  Don't give superuser privileges to people
you cannot trust.

            regards, tom lane

В списке pgsql-bugs по дате отправления:

Предыдущее
От: Stephan Szabo
Дата:
Сообщение: Re: "Bug" report - Serious (local shell)
Следующее
От: Diego Linke - GAMK
Дата:
Сообщение: Re: "Bug" report - Serious (local shell)