Bug#308597: postgresl-8.0: server socket created in /tmp

2005-05-11 Thread Florian Weimer
Package: postgresl-8.0
Version: 8.0.2-1
Severity: grave
Tags: security
Justification: user security hole

The server creates a socket in /tmp, which is unsafe.  Any local user
can create a similar socket and impersonate the database server.

This bug also breaks backwards comaptibility with old client libraries.


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Processed: Re: Bug#308597: postgresl-8.0: server socket created in /tmp

2005-05-11 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

 reassign 308597 postgresql-8.0
Bug#308597: postgresl-8.0: server socket created in /tmp
Warning: Unknown package 'postgresl-8.0'
Bug reassigned from package `postgresl-8.0' to `postgresql-8.0'.

 thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]