Re: Side effect of CVE-2017-7484 fix?

2023-11-09 Thread Bruce Momjian
On Thu, Nov 9, 2023 at 06:44:42PM -0500, Tom Lane wrote: > Bruce Momjian writes: > > On Wed, Oct 24, 2018 at 04:01:29PM -0400, Robert Haas wrote: > >>> This was complained of already, > >>> https://www.postgresql.org/message-id/flat/3876.1531261875%40sss.pgh.pa.us > > >> I guess you never

Re: Side effect of CVE-2017-7484 fix?

2023-11-09 Thread Tom Lane
Bruce Momjian writes: > On Wed, Oct 24, 2018 at 04:01:29PM -0400, Robert Haas wrote: >>> This was complained of already, >>> https://www.postgresql.org/message-id/flat/3876.1531261875%40sss.pgh.pa.us >> I guess you never followed up on that part, though. Any special >> reason for that, or just

Re: Side effect of CVE-2017-7484 fix?

2023-11-09 Thread Bruce Momjian
On Wed, Oct 24, 2018 at 04:01:29PM -0400, Robert Haas wrote: > On Mon, Oct 22, 2018 at 9:47 AM Tom Lane wrote: > > Dilip Kumar writes: > > > As part of the security fix > > > (e2d4ef8de869c57e3bf270a30c12d48c2ce4e00c), we have restricted the > > > users from accessing the statistics of the table

Re: Side effect of CVE-2017-7484 fix?

2018-10-24 Thread Tom Lane
Robert Haas writes: > On Mon, Oct 22, 2018 at 9:47 AM Tom Lane wrote: >> This was complained of already, >> https://www.postgresql.org/message-id/flat/3876.1531261875%40sss.pgh.pa.us > I guess you never followed up on that part, though. Any special > reason for that, or just lack of round

Re: Side effect of CVE-2017-7484 fix?

2018-10-24 Thread Robert Haas
On Mon, Oct 22, 2018 at 9:47 AM Tom Lane wrote: > Dilip Kumar writes: > > As part of the security fix > > (e2d4ef8de869c57e3bf270a30c12d48c2ce4e00c), we have restricted the > > users from accessing the statistics of the table if the user doesn't > > have privileges on the table and the function

Re: Side effect of CVE-2017-7484 fix?

2018-10-24 Thread Dilip Kumar
On Mon, Oct 22, 2018 at 7:40 PM David Fetter wrote: > > On Mon, Oct 22, 2018 at 04:43:52PM +0530, Dilip Kumar wrote: > > On Mon, Oct 22, 2018 at 11:22 AM David Fetter wrote: > > > > > > On Mon, Oct 22, 2018 at 11:10:09AM +0530, Dilip Kumar wrote: > > > > As part of the security fix > > > >

Re: Side effect of CVE-2017-7484 fix?

2018-10-23 Thread Dilip Kumar
On Mon, Oct 22, 2018 at 7:16 PM Tom Lane wrote: > > Dilip Kumar writes: > > As part of the security fix > > (e2d4ef8de869c57e3bf270a30c12d48c2ce4e00c), we have restricted the > > users from accessing the statistics of the table if the user doesn't > > have privileges on the table and the

Re: Side effect of CVE-2017-7484 fix?

2018-10-22 Thread David Fetter
On Mon, Oct 22, 2018 at 04:43:52PM +0530, Dilip Kumar wrote: > On Mon, Oct 22, 2018 at 11:22 AM David Fetter wrote: > > > > On Mon, Oct 22, 2018 at 11:10:09AM +0530, Dilip Kumar wrote: > > > As part of the security fix > > > (e2d4ef8de869c57e3bf270a30c12d48c2ce4e00c), we have restricted the > > >

Re: Side effect of CVE-2017-7484 fix?

2018-10-22 Thread Tom Lane
Dilip Kumar writes: > As part of the security fix > (e2d4ef8de869c57e3bf270a30c12d48c2ce4e00c), we have restricted the > users from accessing the statistics of the table if the user doesn't > have privileges on the table and the function is not leakproof. Now, > as a side effect of this, if the

Re: Side effect of CVE-2017-7484 fix?

2018-10-22 Thread Dilip Kumar
On Mon, Oct 22, 2018 at 12:05 PM Amit Langote wrote: > > Hi, > > On 2018/10/22 14:41, Stephen Frost wrote: > > Greetings, > > > > * Dilip Kumar (dilipbal...@gmail.com) wrote: > >> As part of the security fix > >> (e2d4ef8de869c57e3bf270a30c12d48c2ce4e00c), we have restricted the > >> users from

Re: Side effect of CVE-2017-7484 fix?

2018-10-22 Thread Dilip Kumar
On Mon, Oct 22, 2018 at 11:22 AM David Fetter wrote: > > On Mon, Oct 22, 2018 at 11:10:09AM +0530, Dilip Kumar wrote: > > As part of the security fix > > (e2d4ef8de869c57e3bf270a30c12d48c2ce4e00c), we have restricted the > > users from accessing the statistics of the table if the user doesn't > >

Re: Side effect of CVE-2017-7484 fix?

2018-10-22 Thread Amit Langote
Hi, On 2018/10/22 14:41, Stephen Frost wrote: > Greetings, > > * Dilip Kumar (dilipbal...@gmail.com) wrote: >> As part of the security fix >> (e2d4ef8de869c57e3bf270a30c12d48c2ce4e00c), we have restricted the >> users from accessing the statistics of the table if the user doesn't >> have

Re: Side effect of CVE-2017-7484 fix?

2018-10-21 Thread David Fetter
On Mon, Oct 22, 2018 at 11:10:09AM +0530, Dilip Kumar wrote: > As part of the security fix > (e2d4ef8de869c57e3bf270a30c12d48c2ce4e00c), we have restricted the > users from accessing the statistics of the table if the user doesn't > have privileges on the table and the function is not leakproof. >

Re: Side effect of CVE-2017-7484 fix?

2018-10-21 Thread Stephen Frost
Greetings, * Dilip Kumar (dilipbal...@gmail.com) wrote: > As part of the security fix > (e2d4ef8de869c57e3bf270a30c12d48c2ce4e00c), we have restricted the > users from accessing the statistics of the table if the user doesn't > have privileges on the table and the function is not leakproof. Now,

Side effect of CVE-2017-7484 fix?

2018-10-21 Thread Dilip Kumar
As part of the security fix (e2d4ef8de869c57e3bf270a30c12d48c2ce4e00c), we have restricted the users from accessing the statistics of the table if the user doesn't have privileges on the table and the function is not leakproof. Now, as a side effect of this, if the user has the privileges on the