[
https://issues.apache.org/jira/browse/MADLIB-617?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Frank McQuillan reopened MADLIB-617:
------------------------------------
Assignee: Frank McQuillan (was: Jiali Yao)
> Sketch estimators make unsafe use of user supplied parameters
> -------------------------------------------------------------
>
> Key: MADLIB-617
> URL: https://issues.apache.org/jira/browse/MADLIB-617
> Project: Apache MADlib
> Issue Type: Bug
> Reporter: Caleb Welton
> Assignee: Frank McQuillan
> Priority: Critical
>
> In review of MADlib-567 it became clear that there are some followup tasks to
> clean up the sketch based estimators.
> Currently we pass user supplied bytea fields into the functions and treat the
> contents of that bytea as a pointer that we think we can safely follow. This
> is not safe coding practice and can result in severe security issues.
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)