summaryrefslogtreecommitdiff
path: root/src/test
diff options
context:
space:
mode:
authorNoah Misch2023-01-21 14:08:00 +0000
committerNoah Misch2023-01-21 14:08:05 +0000
commit8f70de7e0106dc0df8b31994e2b3ad06691f5836 (patch)
tree4de7d4a986bf1b712a890b80c223c091c7bd2dd9 /src/test
parentb69e9dfab14f3602eac6a97afaf1a593cfa34424 (diff)
Reject CancelRequestPacket having unexpected length.
When the length was too short, the server read outside the allocation. That yielded the same log noise as sending the correct length with (backendPID,cancelAuthCode) matching nothing. Change to a message about the unexpected length. Given the attacker's lack of control over the memory layout and the general lack of diversity in memory layouts at the code in question, we doubt a would-be attacker could cause a segfault. Hence, while the report arrived via security@postgresql.org, this is not a vulnerability. Back-patch to v11 (all supported versions). Andrey Borodin, reviewed by Tom Lane. Reported by Andrey Borodin.
Diffstat (limited to 'src/test')
0 files changed, 0 insertions, 0 deletions