- Notifications
You must be signed in to change notification settings - Fork5
Commit226a980
committed
Fix bug that allowed any logged-in user to SET ROLE to any other database user
id (CVE-2006-0553). Also fix related bug in SET SESSION AUTHORIZATION thatallows unprivileged users to crash the server, if it has been compiled withAsserts enabled. The escalation-of-privilege risk exists only in 8.1.0-8.1.2.However, the Assert-crash risk exists in all releases back to 7.3.Thanks to Akio Ishida for reporting this problem.1 parent2a5180c commit226a980
File tree
4 files changed
+22
-11
lines changed- src
- backend
- commands
- utils
- mb
- misc
- include/utils
4 files changed
+22
-11
lines changedLines changed: 4 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
9 | 9 |
| |
10 | 10 |
| |
11 | 11 |
| |
12 |
| - | |
| 12 | + | |
13 | 13 |
| |
14 | 14 |
| |
15 | 15 |
| |
| |||
586 | 586 |
| |
587 | 587 |
| |
588 | 588 |
| |
589 |
| - | |
| 589 | + | |
| 590 | + | |
| 591 | + | |
590 | 592 |
| |
591 | 593 |
| |
592 | 594 |
| |
|
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
2 | 2 |
| |
3 | 3 |
| |
4 | 4 |
| |
5 |
| - | |
| 5 | + | |
6 | 6 |
| |
7 | 7 |
| |
8 | 8 |
| |
| |||
449 | 449 |
| |
450 | 450 |
| |
451 | 451 |
| |
452 |
| - | |
| 452 | + | |
453 | 453 |
| |
454 | 454 |
| |
455 | 455 |
| |
|
Lines changed: 14 additions & 6 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
10 | 10 |
| |
11 | 11 |
| |
12 | 12 |
| |
13 |
| - | |
| 13 | + | |
14 | 14 |
| |
15 | 15 |
| |
16 | 16 |
| |
| |||
48 | 48 |
| |
49 | 49 |
| |
50 | 50 |
| |
| 51 | + | |
51 | 52 |
| |
52 | 53 |
| |
53 | 54 |
| |
| |||
1707 | 1708 |
| |
1708 | 1709 |
| |
1709 | 1710 |
| |
1710 |
| - | |
| 1711 | + | |
1711 | 1712 |
| |
1712 | 1713 |
| |
1713 | 1714 |
| |
| |||
1787 | 1788 |
| |
1788 | 1789 |
| |
1789 | 1790 |
| |
1790 |
| - | |
| 1791 | + | |
| 1792 | + | |
1791 | 1793 |
| |
1792 | 1794 |
| |
1793 | 1795 |
| |
| |||
1945 | 1947 |
| |
1946 | 1948 |
| |
1947 | 1949 |
| |
1948 |
| - | |
| 1950 | + | |
1949 | 1951 |
| |
1950 | 1952 |
| |
1951 | 1953 |
| |
| |||
1967 | 1969 |
| |
1968 | 1970 |
| |
1969 | 1971 |
| |
1970 |
| - | |
| 1972 | + | |
1971 | 1973 |
| |
1972 | 1974 |
| |
1973 | 1975 |
| |
| |||
1978 | 1980 |
| |
1979 | 1981 |
| |
1980 | 1982 |
| |
1981 |
| - | |
| 1983 | + | |
1982 | 1984 |
| |
1983 | 1985 |
| |
1984 | 1986 |
| |
| |||
3988 | 3990 |
| |
3989 | 3991 |
| |
3990 | 3992 |
| |
| 3993 | + | |
| 3994 | + | |
| 3995 | + | |
| 3996 | + | |
| 3997 | + | |
| 3998 | + | |
3991 | 3999 |
| |
3992 | 4000 |
| |
3993 | 4001 |
| |
|
Lines changed: 2 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
7 | 7 |
| |
8 | 8 |
| |
9 | 9 |
| |
10 |
| - | |
| 10 | + | |
11 | 11 |
| |
12 | 12 |
| |
13 | 13 |
| |
| |||
126 | 126 |
| |
127 | 127 |
| |
128 | 128 |
| |
| 129 | + | |
129 | 130 |
| |
130 | 131 |
| |
131 | 132 |
| |
|
0 commit comments
Comments
(0)