1
0
mirror of https://github.com/postgres/postgres.git synced 2025-08-11 04:22:52 +03:00

Fix markup.

Security: CVE-2007-2138
This commit is contained in:
Tom Lane
2007-04-20 03:27:54 +00:00
parent 566331a2e9
commit cfe1b04c66

View File

@@ -1,5 +1,5 @@
<!-- <!--
$PostgreSQL: pgsql/doc/src/sgml/release.sgml,v 1.321.4.35 2007/04/20 02:38:31 tgl Exp $ $PostgreSQL: pgsql/doc/src/sgml/release.sgml,v 1.321.4.36 2007/04/20 03:27:54 tgl Exp $
--> -->
<appendix id="release"> <appendix id="release">
@@ -45,8 +45,7 @@ $PostgreSQL: pgsql/doc/src/sgml/release.sgml,v 1.321.4.35 2007/04/20 02:38:31 tg
truly secure value of <varname>search_path</>. Without it, truly secure value of <varname>search_path</>. Without it,
an unprivileged SQL user can use temporary objects to execute code an unprivileged SQL user can use temporary objects to execute code
with the privileges of the security-definer function (CVE-2007-2138). with the privileges of the security-definer function (CVE-2007-2138).
See <xref linkend="sql-createfunction" See <command>CREATE FUNCTION</> for more information.
endterm="sql-createfunction-title"> for more information.
</para> </para>
</listitem> </listitem>
@@ -3554,8 +3553,7 @@ typedefs (Michael)</para></listitem>
truly secure value of <varname>search_path</>. Without it, truly secure value of <varname>search_path</>. Without it,
an unprivileged SQL user can use temporary objects to execute code an unprivileged SQL user can use temporary objects to execute code
with the privileges of the security-definer function (CVE-2007-2138). with the privileges of the security-definer function (CVE-2007-2138).
See <xref linkend="sql-createfunction" See <command>CREATE FUNCTION</> for more information.
endterm="sql-createfunction-title"> for more information.
</para> </para>
</listitem> </listitem>
@@ -6739,8 +6737,7 @@ DROP SCHEMA information_schema CASCADE;
truly secure value of <varname>search_path</>. Without it, truly secure value of <varname>search_path</>. Without it,
an unprivileged SQL user can use temporary objects to execute code an unprivileged SQL user can use temporary objects to execute code
with the privileges of the security-definer function (CVE-2007-2138). with the privileges of the security-definer function (CVE-2007-2138).
See <xref linkend="sql-createfunction" See <command>CREATE FUNCTION</> for more information.
endterm="sql-createfunction-title"> for more information.
</para> </para>
</listitem> </listitem>