diff options
| author | Tom Lane <tgl@sss.pgh.pa.us> | 2017-08-07 10:19:01 -0400 | 
|---|---|---|
| committer | Tom Lane <tgl@sss.pgh.pa.us> | 2017-08-07 10:19:19 -0400 | 
| commit | 8d9881911f0d30e0783a6bb1363b94a2c817433d (patch) | |
| tree | 90d5c2e6f403433d8c308cd9fd524b499f74ad9c /src/bin/pg_upgrade/exec.c | |
| parent | e568e1eee4650227170cf8c64eedb74bafd7d1f0 (diff) | |
Require update permission for the large object written by lo_put().
lo_put() surely should require UPDATE permission, the same as lowrite(),
but it failed to check for that, as reported by Chapman Flack.  Oversight
in commit c50b7c09d; backpatch to 9.4 where that was introduced.
Tom Lane and Michael Paquier
Security: CVE-2017-7548
Diffstat (limited to 'src/bin/pg_upgrade/exec.c')
0 files changed, 0 insertions, 0 deletions
