From fcfb218f71b7d371a10df020994fc0a618639327 Mon Sep 17 00:00:00 2001 From: unknown Date: Sun, 9 May 2010 21:30:06 +0200 Subject: Cherry-pick fix for Bug#53371, security hole with bypassing grants using special path in db/table names. Bump MariaDB version for security fix release. --- sql/sql_yacc.yy | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'sql/sql_yacc.yy') diff --git a/sql/sql_yacc.yy b/sql/sql_yacc.yy index e0f5cd9a562..a1f5547e103 100644 --- a/sql/sql_yacc.yy +++ b/sql/sql_yacc.yy @@ -6149,7 +6149,7 @@ alter_list_item: { MYSQL_YYABORT; } - if (check_table_name($3->table.str,$3->table.length) || + if (check_table_name($3->table.str,$3->table.length, FALSE) || ($3->db.str && check_db_name(&$3->db))) { my_error(ER_WRONG_TABLE_NAME, MYF(0), $3->table.str); -- cgit v1.2.1