Received: from localhost (unknown [200.46.204.184]) by developer.postgresql.org (Postfix) with ESMTP id A94812E0067 for ; Fri, 9 May 2008 00:37:18 -0300 (ADT) Received: from developer.postgresql.org ([200.46.204.71]) by localhost (mx1.hub.org [200.46.204.184]) (amavisd-maia, port 10024) with ESMTP id 42457-04 for ; Fri, 9 May 2008 00:37:10 -0300 (ADT) X-Greylist: from auto-whitelisted by SQLgrey-1.7.6 Received: from momjian.us (momjian.us [70.90.9.53]) by developer.postgresql.org (Postfix) with ESMTP id A6F3D2E005A for ; Fri, 9 May 2008 00:37:09 -0300 (ADT) Received: (from bruce@localhost) by momjian.us (8.11.6/8.11.6) id m493b2204043; Thu, 8 May 2008 23:37:02 -0400 (EDT) From: Bruce Momjian Message-Id: <200805090337.m493b2204043@momjian.us> Subject: Submitting security bugs In-Reply-To: <20080331222247.GI24048@alvh.no-ip.org> To: Alvaro Herrera Date: Thu, 8 May 2008 23:37:02 -0400 (EDT) CC: Dave Page , Tom Lane , Lars Olson , PostgreSQL www X-Mailer: ELM [version 2.4ME+ PL124 (25)] MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Type: text/plain; charset="US-ASCII" X-Virus-Scanned: Maia Mailguard 1.0.1 X-Archive-Number: 200805/52 X-Sequence-Number: 15109 Alvaro Herrera wrote: > Dave Page wrote: > > On Mon, Mar 31, 2008 at 10:46 PM, Tom Lane wrote: > > > If this were a security issue, you already spilled the beans by > > > reporting it to a public mailing list; so I'm unsure what you are > > > concerned about. > > > > I'd wager that Lars didn't realise the bug form goes straight to the > > list. We should probably make that more clear. > > > > On the other hand it does say to report security issues to security@... > > Let's have a checkbox "I am reporting a security issue" and send the > mail to security@ if checked. Do we want to do this? -- Bruce Momjian http://momjian.us EnterpriseDB http://enterprisedb.com + If your life is a hard drive, Christ can be your backup. +