1
0
mirror of https://github.com/postgres/postgres.git synced 2025-04-22 23:02:54 +03:00
Tom Lane ce9ab88981 Make REPLICATION privilege checks test current user not authenticated user.
The pg_start_backup() and pg_stop_backup() functions checked the privileges
of the initially-authenticated user rather than the current user, which is
wrong.  For example, a user-defined index function could successfully call
these functions when executed by ANALYZE within autovacuum.  This could
allow an attacker with valid but low-privilege database access to interfere
with creation of routine backups.  Reported and fixed by Noah Misch.

Security: CVE-2013-1901
2013-04-01 13:09:24 -04:00
..
2013-03-10 14:16:02 -04:00
2013-01-01 17:15:01 -05:00
2013-03-17 12:06:42 -04:00
2013-03-17 12:06:42 -04:00
2013-03-10 14:16:02 -04:00
2011-08-17 14:07:46 +03:00
2013-03-17 12:06:42 -04:00
2013-01-01 17:15:01 -05:00
2013-01-01 17:15:01 -05:00
2013-02-21 22:46:17 -03:00