mirror of https://github.com/postgres/postgres
lo_put() surely should require UPDATE permission, the same as lowrite(), but it failed to check for that, as reported by Chapman Flack. Oversight in commit c50b7c09d; backpatch to 9.4 where that was introduced. Tom Lane and Michael Paquier Security: CVE-2017-7548pull/24/head
parent
e568e1eee4
commit
8d9881911f
Loading…
Reference in new issue