1. 01 Dec, 2008 2 commits
  2. 27 Nov, 2008 1 commit
  3. 26 Jul, 2008 1 commit
    • Alexey Botchkov's avatar
      Bug#32167 another privilege bypass with DATA/INDEX DIRECTORY. · c5132800
      Alexey Botchkov authored
            
            test_if_data_home_dir fixed to look into real path.
            Checks added to mi_open for symlinks into data home directory.
      modified:
        include/my_sys.h
        include/myisam.h
        myisam/mi_check.c
        myisam/mi_open.c
        myisam/mi_static.c
        myisam/myisamchk.c
        myisam/myisamdef.h
        mysql-test/r/symlink.result
        mysys/my_symlink.c
        sql/mysql_priv.h
        sql/mysqld.cc
        sql/sql_parse.cc
      
      per-file messages:
        include/my_sys.h
          Bug#32167 another privilege bypass with DATA/INDEX DIRECTORY.
          
          my_is_symlink interface added
        include/myisam.h
          Bug#32167 another privilege bypass with DATA/INDEX DIRECTORY.
          
          myisam_test_invalid_symlink interface added
        myisam/mi_check.c
          Bug#32167 another privilege bypass with DATA/INDEX DIRECTORY.
          
          mi_open_datafile calls modified
        myisam/mi_open.c
          Bug#32167 another privilege bypass with DATA/INDEX DIRECTORY.
          
          code added to mi_open to check for symlinks into data home directory.
          mi_open_datafile now accepts 'original' file path to check if it's
          an allowed symlink.
        myisam/mi_static.c
          Bug#32167 another privilege bypass with DATA/INDEX DIRECTORY.
          
          myisam_test_invlaid_symlink defined
        myisam/myisamchk.c
          Bug#32167 another privilege bypass with DATA/INDEX DIRECTORY.
          
          mi_open_datafile call modified
        myisam/myisamdef.h
          Bug#32167 another privilege bypass with DATA/INDEX DIRECTORY.
          
          mi_open_datafile interface modified - 'real_path' parameter added
        mysql-test/r/symlink.test
          Bug#32167 another privilege bypass with DATA/INDEX DIRECTORY.
          
          error codes corrected as some patch now rejected pointing inside datahome
        mysql-test/r/symlink.result
          Bug#32167 another privilege bypass with DATA/INDEX DIRECTORY.
          
          error messages corrected in the result
        mysys/my_symlink.c
          Bug#32167 another privilege bypass with DATA/INDEX DIRECTORY.
          
          my_is_symlink() implementsd
          my_realpath() now returns the 'realpath' even if a file isn't a symlink
        sql/mysql_priv.h
          Bug#32167 another privilege bypass with DATA/INDEX DIRECTORY.
          
          test_if_data_home_dir interface
        sql/mysqld.cc
          Bug#32167 another privilege bypass with DATA/INDEX DIRECTORY.
          
          myisam_test_invalid_symlik set with the 'test_if_data_home_dir'
        sql/sql_parse.cc
          Bug#32167 another privilege bypass with DATA/INDEX DIRECTORY.
          
          error messages corrected
          test_if_data_home_dir code fixed
      c5132800
  4. 11 Jun, 2008 1 commit
  5. 21 May, 2008 1 commit
  6. 22 Mar, 2008 1 commit
  7. 19 Mar, 2008 3 commits
  8. 17 Mar, 2008 2 commits
  9. 14 Mar, 2008 1 commit
  10. 12 Mar, 2008 1 commit
  11. 01 Mar, 2008 1 commit
    • kent@mysql.com/kent-amd64.(none)'s avatar
      mysql.spec.sh: · ab309491
      kent@mysql.com/kent-amd64.(none) authored
        - Aligned copyright headers and text with 5.0
        - Don't strip binaries on SuSE 9
        - Formatting alignment with spec file in 5.0
        - Run full test on "normal" binary, and less on "Max"
        - Let test runs on "Max" identify the runs with "max" and "max+ps"
      ab309491
  12. 29 Feb, 2008 2 commits
  13. 26 Feb, 2008 1 commit
    • kent@mysql.com/kent-amd64.(none)'s avatar
      configure.in: · ff25b925
      kent@mysql.com/kent-amd64.(none) authored
        Corrected calculation of version id, incorrect last two digits if < 10
        Keep "sp1" or "a" in MYSQL_NO_DASH_VERSION, to set correct version in
        RPM spec file
        Added MYSQL_NUMERIC_VERSION that is like MYSQL_NO_DASH_VERSION before
        Added clear doc how the different version variables differ
      SocketServer.cpp:
        Corrected typo in debug error message
      ff25b925
  14. 17 Feb, 2008 1 commit
  15. 10 Feb, 2008 1 commit
  16. 31 Jan, 2008 1 commit
  17. 29 Jan, 2008 1 commit
  18. 28 Jan, 2008 1 commit
  19. 25 Jan, 2008 1 commit
    • cmiller@zippy.cornsilk.net's avatar
      Bug#33841: mysql client crashes when returning results for long-\ · b040a97c
      cmiller@zippy.cornsilk.net authored
      	running queries
      
      Bug#33976: buffer overflow of variable time_buff in function com_go()
      
      An internal buffer was too short.  Overextending could smash the 
      stack on some architectures and cause SEGVs.  This is not a problem
      that could be exploited to run arbitrary code.
      
      To fix, I expanded one buffer to cover all the size that could be
      written to (we know the abolute max).
      b040a97c
  20. 22 Jan, 2008 1 commit
  21. 21 Jan, 2008 1 commit
  22. 03 Jan, 2008 2 commits
  23. 27 Dec, 2007 1 commit
    • joerg@trift2.'s avatar
      scripts/make_binary_distribution.sh: · dc1fb075
      joerg@trift2. authored
      Fix the code to get the "libgcc" file name so that the failure of Intel's ICC
      to provide this information does not cause any problems.
      
      This fixes  bug#33536  Option "--print-libgcc-file" does not work with ICC compiler
      dc1fb075
  24. 17 Dec, 2007 3 commits
  25. 13 Dec, 2007 1 commit
  26. 10 Dec, 2007 2 commits
  27. 06 Dec, 2007 2 commits
  28. 05 Dec, 2007 1 commit
  29. 01 Dec, 2007 2 commits