forked frompostgres/postgres
- Notifications
You must be signed in to change notification settings - Fork6
Commite2d4ef8
committed
Add security checks to selectivity estimation functions
Some selectivity estimation functions run user-supplied operators overdata obtained from pg_statistic without security checks, which allowsthose operators to leak pg_statistic data without having privileges onthe underlying tables. Fix by checking that one of the following issatisfied: (1) the user has table or column privileges on the tableunderlying the pg_statistic data, or (2) the function implementing theuser-supplied operator is leak-proof. If neither is satisfied, planningwill proceed as if there are no statistics available.At least one of these is satisfied in most cases in practice. The onlysituations that are negatively impacted are user-defined ornot-leak-proof operators on a security-barrier view.Reported-by: Robert Haas <robertmhaas@gmail.com>Author: Peter Eisentraut <peter_e@gmx.net>Author: Tom Lane <tgl@sss.pgh.pa.us>Security:CVE-2017-74841 parenteb61136 commite2d4ef8
File tree
7 files changed
+377
-32
lines changed- doc/src/sgml
- src
- backend/utils/adt
- include/utils
- test/regress
- expected
- sql
7 files changed
+377
-32
lines changedLines changed: 61 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
582 | 582 |
| |
583 | 583 |
| |
584 | 584 |
| |
| 585 | + | |
| 586 | + | |
| 587 | + | |
| 588 | + | |
| 589 | + | |
| 590 | + | |
| 591 | + | |
| 592 | + | |
| 593 | + | |
| 594 | + | |
| 595 | + | |
| 596 | + | |
| 597 | + | |
| 598 | + | |
| 599 | + | |
| 600 | + | |
| 601 | + | |
| 602 | + | |
| 603 | + | |
| 604 | + | |
| 605 | + | |
| 606 | + | |
| 607 | + | |
| 608 | + | |
| 609 | + | |
| 610 | + | |
| 611 | + | |
| 612 | + | |
| 613 | + | |
| 614 | + | |
| 615 | + | |
| 616 | + | |
| 617 | + | |
| 618 | + | |
| 619 | + | |
| 620 | + | |
| 621 | + | |
| 622 | + | |
| 623 | + | |
| 624 | + | |
| 625 | + | |
| 626 | + | |
| 627 | + | |
| 628 | + | |
| 629 | + | |
| 630 | + | |
| 631 | + | |
| 632 | + | |
| 633 | + | |
| 634 | + | |
| 635 | + | |
| 636 | + | |
| 637 | + | |
| 638 | + | |
| 639 | + | |
| 640 | + | |
| 641 | + | |
| 642 | + | |
| 643 | + | |
| 644 | + | |
| 645 | + | |
585 | 646 |
|
Lines changed: 4 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
133 | 133 |
| |
134 | 134 |
| |
135 | 135 |
| |
136 |
| - | |
| 136 | + | |
| 137 | + | |
137 | 138 |
| |
138 | 139 |
| |
139 | 140 |
| |
| |||
364 | 365 |
| |
365 | 366 |
| |
366 | 367 |
| |
367 |
| - | |
| 368 | + | |
| 369 | + | |
368 | 370 |
| |
369 | 371 |
| |
370 | 372 |
| |
|
Lines changed: 22 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
255 | 255 |
| |
256 | 256 |
| |
257 | 257 |
| |
| 258 | + | |
258 | 259 |
| |
259 | 260 |
| |
260 | 261 |
| |
| |||
383 | 384 |
| |
384 | 385 |
| |
385 | 386 |
| |
| 387 | + | |
| 388 | + | |
| 389 | + | |
| 390 | + | |
| 391 | + | |
| 392 | + | |
| 393 | + | |
| 394 | + | |
| 395 | + | |
386 | 396 |
| |
387 | 397 |
| |
388 | 398 |
| |
| |||
420 | 430 |
| |
421 | 431 |
| |
422 | 432 |
| |
| 433 | + | |
| 434 | + | |
423 | 435 |
| |
| 436 | + | |
424 | 437 |
| |
425 | 438 |
| |
426 | 439 |
| |
| 440 | + | |
| 441 | + | |
| 442 | + | |
| 443 | + | |
427 | 444 |
| |
| 445 | + | |
428 | 446 |
| |
429 | 447 |
| |
430 | 448 |
| |
| |||
560 | 578 |
| |
561 | 579 |
| |
562 | 580 |
| |
| 581 | + | |
| 582 | + | |
| 583 | + | |
| 584 | + | |
563 | 585 |
| |
564 | 586 |
| |
565 | 587 |
| |
|
0 commit comments
Comments
(0)