Re: pl/pgsql enabled by default - Mailing list pgsql-hackers

From Neil Conway
Subject Re: pl/pgsql enabled by default
Date
Msg-id 427B0291.5020709@samurai.com
Whole thread Raw
In response to Re: pl/pgsql enabled by default  (Josh Berkus <josh@agliodbs.com>)
Responses Re: pl/pgsql enabled by default
Re: pl/pgsql enabled by default
List pgsql-hackers
Josh Berkus wrote:
> The only one I can think of is "security", which is pretty weak -- we've never 
> had a plpgsql security issue that I know of.

Well, no -- for instance,

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0245
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0247

But I agree security is not a good argument against enabling it by default.

-Neil


pgsql-hackers by date:

Previous
From: Josh Berkus
Date:
Subject: Re: pl/pgsql enabled by default
Next
From: "Jim C. Nasby"
Date:
Subject: Re: Views, views, views! (long)