1
0
mirror of https://github.com/MariaDB/server.git synced 2025-12-03 05:41:09 +03:00
Files
mariadb/mysql-test/t
unknown 12c6d1f355 BUG#49124 Security issue with /*!-versioned */ SQL statements on Slave
Backport to 5.0.

/*![:version:] Query Code */, where [:version:] is a sequence of 5 
digits representing the mysql server version(e.g /*!50200 ... */),
is a special comment that the query in it can be executed on those 
servers whose versions are larger than the version appearing in the 
comment. It leads to a security issue when slave's version is larger 
than master's. A malicious user can improve his privileges on slaves. 
Because slave SQL thread is running with SUPER privileges, so it can
execute queries that he/she does not have privileges on master.
      
This bug is fixed with the logic below: 
- To replace '!' with ' ' in the magic comments which are not applied on
  master. So they become common comments and will not be applied on slave.
      
- Example:
  'INSERT INTO t1 VALUES (1) /*!10000, (2)*/ /*!99999 ,(3)*/
   will be binlogged as
  'INSERT INTO t1 VALUES (1) /*!10000, (2)*/ /* 99999 ,(3)*/
2011-01-15 13:48:16 +08:00
..
2008-01-27 16:41:29 +01:00
2007-11-06 20:31:40 +02:00
2009-11-03 19:58:54 +03:00
2009-11-03 19:58:54 +03:00
2007-08-07 05:35:20 -04:00
2007-10-19 17:07:08 +02:00
2009-12-21 14:40:08 +03:00
2009-02-06 18:25:08 +01:00
2009-02-09 21:52:40 +01:00
2007-11-02 13:40:34 +03:00
2007-11-02 13:40:34 +03:00
2008-12-17 15:01:34 -05:00
2007-08-31 16:59:07 +05:00
2007-11-05 20:18:22 +01:00
2007-10-26 08:42:33 +02:00
2008-01-27 16:41:29 +01:00
2007-11-05 20:18:22 +01:00
2008-01-22 14:18:47 +01:00
2007-11-20 20:15:20 +04:00
2007-11-30 18:06:28 +01:00
2008-08-22 19:49:51 +02:00
2009-12-10 11:44:19 +08:00
2008-04-04 01:16:55 +04:00
2008-04-04 01:16:55 +04:00
2009-07-03 10:19:32 +02:00
2007-07-22 18:26:16 -07:00
2008-03-14 20:51:32 +01:00
2008-02-07 02:33:21 +04:00
2010-03-10 19:28:49 +04:00