Re: Side effect of CVE-2017-7484 fix?

Поиск
Список
Период
Сортировка
От Bruce Momjian
Тема Re: Side effect of CVE-2017-7484 fix?
Дата
Msg-id ZU1tF9Ev33ayhNt5@momjian.us
обсуждение исходный текст
Ответ на Re: Side effect of CVE-2017-7484 fix?  (Robert Haas <robertmhaas@gmail.com>)
Ответы Re: Side effect of CVE-2017-7484 fix?  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-hackers
On Wed, Oct 24, 2018 at 04:01:29PM -0400, Robert Haas wrote:
> On Mon, Oct 22, 2018 at 9:47 AM Tom Lane <tgl@sss.pgh.pa.us> wrote:
> > Dilip Kumar <dilipbalaut@gmail.com> writes:
> > > As part of the security fix
> > > (e2d4ef8de869c57e3bf270a30c12d48c2ce4e00c), we have restricted the
> > > users from accessing the statistics of the table if the user doesn't
> > > have privileges on the table and the function is not leakproof.  Now,
> > > as a side effect of this, if the user has the privileges on the root
> > > partitioned table but does not have privilege on the child tables, the
> > > user will be able to access the data of the child table but it won't
> > > be able to access the statistics of the child table. This may result
> > > in a bad plan.
> >
> > This was complained of already,
> > https://www.postgresql.org/message-id/flat/3876.1531261875%40sss.pgh.pa.us
> 
> I guess you never followed up on that part, though.  Any special
> reason for that, or just lack of round tuits?

Should this be added as a TODO item?

-- 
  Bruce Momjian  <bruce@momjian.us>        https://momjian.us
  EDB                                      https://enterprisedb.com

  Only you can decide what is important to you.



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Bruce Momjian
Дата:
Сообщение: Re: pg_walfile_name_offset can return inconsistent values
Следующее
От: Bruce Momjian
Дата:
Сообщение: Re: remove deprecated @@@ operator ?