Forum OpenACS Q&A: Re: DB Proxy format string vulnerability

Collapse
Posted by David Walker on
Most openacs installs do not call for external db drivers.  Neither Postgres or Oracle use them.  Sybase is the only database I am aware of that uses external db drivers.

So unless you're using nsext.so for db connections I think you don't need to worry about this issue.

Collapse
Posted by Larry Nguyen on
Thanks a lot, David. I follow your tip on hiding server info, it works great.

I'm glad to hear about not worrying the format string vuln.