diff options
author | Tom Lane <tgl@sss.pgh.pa.us> | 2017-08-07 10:19:01 -0400 |
---|---|---|
committer | Tom Lane <tgl@sss.pgh.pa.us> | 2017-08-07 10:19:19 -0400 |
commit | 8d9881911f0d30e0783a6bb1363b94a2c817433d (patch) | |
tree | 90d5c2e6f403433d8c308cd9fd524b499f74ad9c /src/backend/utils/misc/check_guc | |
parent | e568e1eee4650227170cf8c64eedb74bafd7d1f0 (diff) |
Require update permission for the large object written by lo_put().
lo_put() surely should require UPDATE permission, the same as lowrite(),
but it failed to check for that, as reported by Chapman Flack. Oversight
in commit c50b7c09d; backpatch to 9.4 where that was introduced.
Tom Lane and Michael Paquier
Security: CVE-2017-7548
Diffstat (limited to 'src/backend/utils/misc/check_guc')
0 files changed, 0 insertions, 0 deletions