Re: Securing "make check" (CVE-2014-0067) - Mailing list pgsql-hackers

From Stephen Frost
Subject Re: Securing "make check" (CVE-2014-0067)
Date
Msg-id 20140303075021.GG12995@tamriel.snowman.net
Whole thread Raw
In response to Re: Securing "make check" (CVE-2014-0067)  (Tom Lane <tgl@sss.pgh.pa.us>)
List pgsql-hackers
* Tom Lane (tgl@sss.pgh.pa.us) wrote:
> Noah Misch <noah@leadboat.com> writes:
> > Concerning the immediate fix for non-Windows systems, does any modern system
> > ignore modes of Unix domain sockets?  It appears to be a long-fixed problem:
>
> What I was envisioning was that we'd be relying on the permissions of the
> containing directory to keep out bad guys.  Permissions on the socket
> itself might be sufficient, but what does it save us to assume that?

Agreed- the general approach to this, from what I've seen, is to handle
it with the directory.
Thanks,
    Stephen

pgsql-hackers by date:

Previous
From: Tom Lane
Date:
Subject: Re: Securing "make check" (CVE-2014-0067)
Next
From: Fabien COELHO
Date:
Subject: Re: gaussian distribution pgbench