pgsql: Support explicit placement of the temporary-table schema within - Mailing list pgsql-committers

From tgl@postgresql.org (Tom Lane)
Subject pgsql: Support explicit placement of the temporary-table schema within
Date
Msg-id 20070420023749.315169FB3E7@postgresql.org
Whole thread Raw
List pgsql-committers
Log Message:
-----------
Support explicit placement of the temporary-table schema within search_path.
This is needed to allow a security-definer function to set a truly secure
value of search_path.  Without it, a malicious user can use temporary objects
to execute code with the privileges of the security-definer function.  Even
pushing the temp schema to the back of the search path is not quite good
enough, because a function or operator at the back of the path might still
capture control from one nearer the front due to having a more exact datatype
match.  Hence, disable searching the temp schema altogether for functions and
operators.

Security: CVE-2007-2138

Tags:
----
REL8_2_STABLE

Modified Files:
--------------
    pgsql/doc/src/sgml/ref:
        create_function.sgml (r1.70 -> r1.70.2.1)

(http://developer.postgresql.org/cvsweb.cgi/pgsql/doc/src/sgml/ref/create_function.sgml.diff?r1=1.70&r2=1.70.2.1)
    pgsql/doc/src/sgml:
        release.sgml (r1.488.2.8 -> r1.488.2.9)
        (http://developer.postgresql.org/cvsweb.cgi/pgsql/doc/src/sgml/release.sgml.diff?r1=1.488.2.8&r2=1.488.2.9)
        config.sgml (r1.98.2.4 -> r1.98.2.5)
        (http://developer.postgresql.org/cvsweb.cgi/pgsql/doc/src/sgml/config.sgml.diff?r1=1.98.2.4&r2=1.98.2.5)
    pgsql/src/backend/catalog:
        aclchk.c (r1.133 -> r1.133.2.1)
        (http://developer.postgresql.org/cvsweb.cgi/pgsql/src/backend/catalog/aclchk.c.diff?r1=1.133&r2=1.133.2.1)
        namespace.c (r1.88 -> r1.88.2.1)
        (http://developer.postgresql.org/cvsweb.cgi/pgsql/src/backend/catalog/namespace.c.diff?r1=1.88&r2=1.88.2.1)
    pgsql/src/test/regress/expected:
        temp.out (r1.12 -> r1.12.2.1)
        (http://developer.postgresql.org/cvsweb.cgi/pgsql/src/test/regress/expected/temp.out.diff?r1=1.12&r2=1.12.2.1)
    pgsql/src/test/regress/sql:
        temp.sql (r1.7 -> r1.7.2.1)
        (http://developer.postgresql.org/cvsweb.cgi/pgsql/src/test/regress/sql/temp.sql.diff?r1=1.7&r2=1.7.2.1)

pgsql-committers by date:

Previous
From: tgl@postgresql.org (Tom Lane)
Date:
Subject: pgsql: Fix markup.
Next
From: tgl@postgresql.org (Tom Lane)
Date:
Subject: pgsql: Support explicit placement of the temporary-table schema within