mirror of https://github.com/postgres/postgres
The two methods don't cooperate, so set_config_option("search_path", ...) has been ineffective under non-empty overrideStack. This defect enabled an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. While that particular attack requires v13+ for the trusted extension attribute, other attacks are feasible in all supported versions. Standardize on the combination of NewGUCNestLevel() and set_config_option("search_path", ...). It is newer than PushOverrideSearchPath(), more-prevalent, and has no known disadvantages. The "override" mechanism remains for now, for compatibility with out-of-tree code. Users should update such code, which likely suffers from the same sort of vulnerability closed here. Back-patch to v11 (all supported versions). Alexander Lakhin. Reported by Alexander Lakhin. Security: CVE-2023-2454pull/137/head
parent
b8c3f6df85
commit
681d9e4621
@ -0,0 +1,32 @@ |
|||||||
|
-- |
||||||
|
-- Test extension script protection against search path overriding |
||||||
|
-- |
||||||
|
CREATE ROLE regress_seg_role; |
||||||
|
SELECT current_database() AS datname \gset |
||||||
|
GRANT CREATE ON DATABASE :"datname" TO regress_seg_role; |
||||||
|
SET ROLE regress_seg_role; |
||||||
|
CREATE SCHEMA regress_seg_schema; |
||||||
|
CREATE FUNCTION regress_seg_schema.exfun(i int) RETURNS int AS $$ |
||||||
|
BEGIN |
||||||
|
CREATE EXTENSION seg VERSION '1.2'; |
||||||
|
|
||||||
|
CREATE FUNCTION regress_seg_schema.compare(oid, regclass) RETURNS boolean AS |
||||||
|
'BEGIN RAISE EXCEPTION ''overloaded compare() called by %'', current_user; END;' LANGUAGE plpgsql; |
||||||
|
|
||||||
|
CREATE OPERATOR = (LEFTARG = oid, RIGHTARG = regclass, PROCEDURE = regress_seg_schema.compare); |
||||||
|
|
||||||
|
ALTER EXTENSION seg UPDATE TO '1.3'; |
||||||
|
|
||||||
|
RETURN i; |
||||||
|
END; $$ LANGUAGE plpgsql; |
||||||
|
CREATE SCHEMA test_schema |
||||||
|
CREATE TABLE t(i int) PARTITION BY RANGE (i) |
||||||
|
CREATE TABLE p1 PARTITION OF t FOR VALUES FROM (1) TO (regress_seg_schema.exfun(2)); |
||||||
|
DROP SCHEMA test_schema CASCADE; |
||||||
|
NOTICE: drop cascades to 3 other objects |
||||||
|
DETAIL: drop cascades to table test_schema.t |
||||||
|
drop cascades to extension seg |
||||||
|
drop cascades to operator test_schema.=(oid,regclass) |
||||||
|
RESET ROLE; |
||||||
|
DROP OWNED BY regress_seg_role; |
||||||
|
DROP ROLE regress_seg_role; |
@ -0,0 +1,32 @@ |
|||||||
|
-- |
||||||
|
-- Test extension script protection against search path overriding |
||||||
|
-- |
||||||
|
|
||||||
|
CREATE ROLE regress_seg_role; |
||||||
|
SELECT current_database() AS datname \gset |
||||||
|
GRANT CREATE ON DATABASE :"datname" TO regress_seg_role; |
||||||
|
SET ROLE regress_seg_role; |
||||||
|
CREATE SCHEMA regress_seg_schema; |
||||||
|
|
||||||
|
CREATE FUNCTION regress_seg_schema.exfun(i int) RETURNS int AS $$ |
||||||
|
BEGIN |
||||||
|
CREATE EXTENSION seg VERSION '1.2'; |
||||||
|
|
||||||
|
CREATE FUNCTION regress_seg_schema.compare(oid, regclass) RETURNS boolean AS |
||||||
|
'BEGIN RAISE EXCEPTION ''overloaded compare() called by %'', current_user; END;' LANGUAGE plpgsql; |
||||||
|
|
||||||
|
CREATE OPERATOR = (LEFTARG = oid, RIGHTARG = regclass, PROCEDURE = regress_seg_schema.compare); |
||||||
|
|
||||||
|
ALTER EXTENSION seg UPDATE TO '1.3'; |
||||||
|
|
||||||
|
RETURN i; |
||||||
|
END; $$ LANGUAGE plpgsql; |
||||||
|
|
||||||
|
CREATE SCHEMA test_schema |
||||||
|
CREATE TABLE t(i int) PARTITION BY RANGE (i) |
||||||
|
CREATE TABLE p1 PARTITION OF t FOR VALUES FROM (1) TO (regress_seg_schema.exfun(2)); |
||||||
|
|
||||||
|
DROP SCHEMA test_schema CASCADE; |
||||||
|
RESET ROLE; |
||||||
|
DROP OWNED BY regress_seg_role; |
||||||
|
DROP ROLE regress_seg_role; |
Loading…
Reference in new issue