1
0
mirror of https://github.com/MariaDB/server.git synced 2025-08-01 03:47:19 +03:00

Bug#7391 - Multi-table UPDATE security regression

Add in missing privilege checks. 
  Tests for the privileges.
This commit is contained in:
antony@ltantony.rdg.cyberkinetica.homeunix.net
2004-12-18 02:07:32 +00:00
parent d54d79fae3
commit 3047649845
3 changed files with 156 additions and 0 deletions

View File

@ -465,21 +465,34 @@ int mysql_multi_update(THD *thd,
*/
for (tl= table_list ; tl ; tl=tl->next)
{
TABLE_LIST *save= tl->next;
TABLE *table= tl->table;
uint wants;
tl->next= 0;
if (update_map & table->map)
{
DBUG_PRINT("info",("setting table `%s` for update", tl->alias));
tl->lock_type= thd->lex.lock_option;
tl->updating= 1;
wants= UPDATE_ACL;
}
else
{
DBUG_PRINT("info",("setting table `%s` for read-only", tl->alias));
tl->lock_type= TL_READ;
tl->updating= 0;
wants= SELECT_ACL;
}
if (!using_lock_tables)
tl->table->reginfo.lock_type= tl->lock_type;
if (check_access(thd, wants, tl->db, &tl->grant.privilege, 0, 0) ||
(grant_option && check_grant(thd, wants, tl, 0, 0)))
{
tl->next= save;
DBUG_RETURN(0);
}
tl->next= save;
}
/* Relock the tables with the correct modes */
@ -541,6 +554,13 @@ int mysql_multi_update(THD *thd,
}
}
/*
If we have no WHERE clause, make it true otherwise the Select
examines the privileges
*/
if (!conds)
conds= new Item_int("1", 1LL, 1);
if (!(result=new multi_update(thd, table_list, fields, values,
handle_duplicates)))
DBUG_RETURN(-1);