Not fully investgiated, but the following is my
response to the users list regarding the latest
postgres security hole:
The problem in question is quite complex, and I haven't
had much time to
go over this in depth. It would appear that MailManager
may be vulnerable
in the case that the database encoding is set to a
multibyte encoding type.
This will depend on your distribution's configuration
of postgres, and can
be checked using the command \l+ in the psql command
line client.
For now, if this security vulnerability is a concern I
would advise that
you upgrade to the latest version of postgres, which
should resolve the
issue. Looking at the DTML layer in Zope, it appears to
use the '' string
escaping method which should be safe for all encoding
types with postgres
8.1.4.
Our SQL layer which we introduced to allow us to
convert and wrap queries
should mean that any exploit can be prevented from
within MailManager
itself, rather than having to rely on a fix in Zope's
DTML layer or in
Postgres. I will investigate this properly and issue a
fix if necessary
asap.
Kevin Campbell
Security
v2.0.9
Public
|
Date: 2006-05-26 14:23 Logged In: YES |
|
Date: 2006-05-25 09:32 Logged In: YES |
|
Date: 2006-05-24 15:00 Logged In: YES |
|
Date: 2006-05-24 14:58 Logged In: YES |
|
Date: 2006-05-24 13:33 Logged In: YES |
|
Date: 2006-05-24 13:26 Logged In: YES |
| Field | Old Value | Date | By |
|---|---|---|---|
| status_id | Open | 2006-05-26 14:23 | kevca |
| resolution_id | None | 2006-05-26 14:23 | kevca |
| close_date | - | 2006-05-26 14:23 | kevca |
| artifact_group_id | v2.1-rc3 | 2006-05-24 13:26 | kevca |
Copyright © 2010 Geeknet, Inc. All rights reserved. Terms of Use