pgsql: Fix bug that allowed any logged-in user to SET ROLE to any other

From: tgl(at)postgresql(dot)org (Tom Lane)
To: pgsql-committers(at)postgresql(dot)org
Subject: pgsql: Fix bug that allowed any logged-in user to SET ROLE to any other
Date: 2006-02-12 22:32:57
Message-ID: 20060212223257.06A629DC84D@postgresql.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-committers

Log Message:
-----------
Fix bug that allowed any logged-in user to SET ROLE to any other database user
id (CVE-2006-0553). Also fix related bug in SET SESSION AUTHORIZATION that
allows unprivileged users to crash the server, if it has been compiled with
Asserts enabled. The escalation-of-privilege risk exists only in 8.1.0-8.1.2.
However, the Assert-crash risk exists in all releases back to 7.3.
Thanks to Akio Ishida for reporting this problem.

Tags:
----
REL8_1_STABLE

Modified Files:
--------------
pgsql/src/backend/commands:
variable.c (r1.114.2.1 -> r1.114.2.2)
(http://developer.postgresql.org/cvsweb.cgi/pgsql/src/backend/commands/variable.c.diff?r1=1.114.2.1&r2=1.114.2.2)
pgsql/src/backend/utils/mb:
encnames.c (r1.26 -> r1.26.2.1)
(http://developer.postgresql.org/cvsweb.cgi/pgsql/src/backend/utils/mb/encnames.c.diff?r1=1.26&r2=1.26.2.1)
pgsql/src/backend/utils/misc:
guc.c (r1.299.2.1 -> r1.299.2.2)
(http://developer.postgresql.org/cvsweb.cgi/pgsql/src/backend/utils/misc/guc.c.diff?r1=1.299.2.1&r2=1.299.2.2)
pgsql/src/include/utils:
guc_tables.h (r1.20 -> r1.20.2.1)
(http://developer.postgresql.org/cvsweb.cgi/pgsql/src/include/utils/guc_tables.h.diff?r1=1.20&r2=1.20.2.1)

Browse pgsql-committers by date

  From Date Subject
Next Message Tom Lane 2006-02-12 22:33:14 pgsql: Fix bug in SET SESSION AUTHORIZATION that allows unprivileged
Previous Message Tom Lane 2006-02-12 22:32:43 pgsql: Fix bug that allowed any logged-in user to SET ROLE to any other