• Tom Lane's avatar
    Fix bug that allowed any logged-in user to SET ROLE to any other database user · 226a980b
    Tom Lane authored
    id (CVE-2006-0553).  Also fix related bug in SET SESSION AUTHORIZATION that
    allows unprivileged users to crash the server, if it has been compiled with
    Asserts enabled.  The escalation-of-privilege risk exists only in 8.1.0-8.1.2.
    However, the Assert-crash risk exists in all releases back to 7.3.
    Thanks to Akio Ishida for reporting this problem.
    226a980b
guc_tables.h 5.74 KB