Forum OpenACS Q&A: Response to Bugtraq: Buffer overflow in PostgreSQL

Collapse
Posted by Don Baccus on
Well, Oracle isn't making a special release to fix the fact that one can reliably crash the entire Oracle database server (not just one connection as is the case here) on Solaris if someone connects with a Linux client that uses the OCI.

They're just saying "don't do that".

PG 7.3 will be in beta in about two weeks and final about four weeks later.  It looks like the PG team will have a release out that fixes the problem much earlier than Oracle will have one which fixes theirs.

Note that the PG developers aren't saying they're not fixing it, merely that they're not going through a full release cycle to get out a new PG 7.2 release.

What does this mean in practice?  Instead of waiting a week or two for a PG 7.2 release with the fix  you'll have to wait two or three weeks for a PG 7.3 beta and about 6-7 weeks for PG 7.3 final.