Re: [GENERAL] postgresql command line exploit found in the wild

2013-04-09 Thread Christoph Berg
Re: Daniel Verite 2013-04-08 cd81d201-e9fa-4567-ac49-e3e762935747@mm Merlin Moncure wrote: if you have an internet facing database, patch it immediately! By the way: People running 9.1 on debian stable (squeeze) typically use this package:

[GENERAL] postgresql command line exploit found in the wild

2013-04-08 Thread Merlin Moncure
see: http://schemaverse.tumblr.com/post/47312545952/the-schemaverse-was-hacked if you have an internet facing database, patch it immediately! (personally, I would only do this through a service such as pgbouncer runnning under extremely limited account). do not delay! merlin -- Sent via

Re: [GENERAL] postgresql command line exploit found in the wild

2013-04-08 Thread Daniel Verite
Merlin Moncure wrote: if you have an internet facing database, patch it immediately! By the way: People running 9.1 on debian stable (squeeze) typically use this package: http://packages.debian.org/squeeze-backports/postgresql-9.1 Currently, it looks like the fix is only available in

Re: [GENERAL] postgresql command line exploit found in the wild

2013-04-08 Thread Merlin Moncure
On Mon, Apr 8, 2013 at 10:48 AM, Daniel Verite dan...@manitou-mail.org wrote: Merlin Moncure wrote: if you have an internet facing database, patch it immediately! By the way: People running 9.1 on debian stable (squeeze) typically use this package: