3 ms·
Not necessarily: that email reported a legitimate bug and identifies a buffer overflow. They don't mention anything about it being exploitable or try to work t
by owenmarshall 3y ago
Not necessarily: that email reported a legitimate bug and identifies a buffer overflow. They don't mention anything about it being exploitable or try to work towards this. Then the CVE was published >20 days later. It's very possible someone else watching the Postgres DL saw an email with "buffer overflow" and pushed it out.