Heavy security bug in 7.2.2-16? - Mailing list pgsql-novice

From Heiko Schroeder
Subject Heavy security bug in 7.2.2-16?
Date
Msg-id 200212270327.21106.heikos@foni.net
Whole thread Raw
Responses Re: Heavy security bug in 7.2.2-16?
List pgsql-novice
Dear list,

as far as I have made my experiences in version 7.2.2-16 (SuSE Linux 8.1) it
is possible for *every* user which is able to create a database and/or is
able to create new users to delete a database from every other user. I did
not find any hints in the FAQ or archives.

Especially when the superuser postmaster creates a database, e.g. test, a
normal user although he is *not* the owner, if it is not denied that he can
create new databases AND that he can create new users, can delete the
database even if there are restrictions made on a table within the database
by the owner (GRANT).

I cannot find the mistake I have made, since in an older version this problem
did not occur. Thanks a lot.

Heiko
--
Heiko Schroeder
Ahrensburg, Germany
http://home.foni.net/~heikos

pgsql-novice by date:

Previous
From: "Reshat Sabiq"
Date:
Subject: Re: Moving a database-sos
Next
From: Tom Lane
Date:
Subject: Re: Heavy security bug in 7.2.2-16?