postgresql/contrib/seg
Noah Misch 681d9e4621 Replace last PushOverrideSearchPath() call with set_config_option().
The two methods don't cooperate, so set_config_option("search_path",
...) has been ineffective under non-empty overrideStack.  This defect
enabled an attacker having database-level CREATE privilege to execute
arbitrary code as the bootstrap superuser.  While that particular attack
requires v13+ for the trusted extension attribute, other attacks are
feasible in all supported versions.

Standardize on the combination of NewGUCNestLevel() and
set_config_option("search_path", ...).  It is newer than
PushOverrideSearchPath(), more-prevalent, and has no known
disadvantages.  The "override" mechanism remains for now, for
compatibility with out-of-tree code.  Users should update such code,
which likely suffers from the same sort of vulnerability closed here.
Back-patch to v11 (all supported versions).

Alexander Lakhin.  Reported by Alexander Lakhin.

Security: CVE-2023-2454
2023-05-08 06:14:07 -07:00
..
data
expected Replace last PushOverrideSearchPath() call with set_config_option(). 2023-05-08 06:14:07 -07:00
sql Replace last PushOverrideSearchPath() call with set_config_option(). 2023-05-08 06:14:07 -07:00
.gitignore Build all Flex files standalone 2022-09-04 12:09:01 +07:00
Makefile Replace last PushOverrideSearchPath() call with set_config_option(). 2023-05-08 06:14:07 -07:00
meson.build Update copyright for 2023 2023-01-02 15:00:37 -05:00
seg--1.0--1.1.sql
seg--1.1--1.2.sql
seg--1.1.sql
seg--1.2--1.3.sql
seg--1.3--1.4.sql
seg-validate.pl Update copyright for 2023 2023-01-02 15:00:37 -05:00
seg.c Convert contrib/seg's input function to report errors softly 2022-12-23 09:17:24 -05:00
seg.control
segdata.h Convert contrib/seg's input function to report errors softly 2022-12-23 09:17:24 -05:00
segparse.y Convert contrib/seg's input function to report errors softly 2022-12-23 09:17:24 -05:00
segscan.l Convert contrib/seg's input function to report errors softly 2022-12-23 09:17:24 -05:00
sort-segments.pl Update copyright for 2023 2023-01-02 15:00:37 -05:00