aboutsummaryrefslogtreecommitdiff
path: root/src/backend/executor
diff options
context:
space:
mode:
authorTom Lane <tgl@sss.pgh.pa.us>2009-09-03 22:09:06 +0000
committerTom Lane <tgl@sss.pgh.pa.us>2009-09-03 22:09:06 +0000
commitfd28d83bdc1d357d2e21e416cf52c0e20ab6da16 (patch)
treea4bc7ca8463086b1c4237fdcff4212ab2d82d198 /src/backend/executor
parent8422728a2bf00f997058411897dc1016daafdbe3 (diff)
downloadpostgresql-fd28d83bdc1d357d2e21e416cf52c0e20ab6da16.tar.gz
postgresql-fd28d83bdc1d357d2e21e416cf52c0e20ab6da16.zip
Disallow RESET ROLE and RESET SESSION AUTHORIZATION inside security-definer
functions. This extends the previous patch that forbade SETting these variables inside security-definer functions. RESET is equally a security hole, since it would allow regaining privileges of the caller; furthermore it can trigger Assert failures and perhaps other internal errors, since the code is not expecting these variables to change in such contexts. The previous patch did not cover this case because assign hooks don't really have enough information, so move the responsibility for preventing this into guc.c. Problem discovered by Heikki Linnakangas. Security: no CVE assigned yet, extends CVE-2007-6600
Diffstat (limited to 'src/backend/executor')
0 files changed, 0 insertions, 0 deletions