~ubuntu-branches/ubuntu/natty/mysql-5.1/natty-proposed

« back to all changes in this revision

Viewing changes to mysql-test/r/sp-security.result

  • Committer: Package Import Robot
  • Author(s): Marc Deslauriers
  • Date: 2012-02-22 08:30:45 UTC
  • mfrom: (1.4.1)
  • Revision ID: package-import@ubuntu.com-20120222083045-2rd53r4bnyx7qus4
Tags: 5.1.61-0ubuntu0.11.04.1
* SECURITY UPDATE: Update to 5.1.61 to fix multiple security issues
  (LP: #937869)
  - http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
  - CVE-2011-2262
  - CVE-2012-0075
  - CVE-2012-0112
  - CVE-2012-0113
  - CVE-2012-0114
  - CVE-2012-0115
  - CVE-2012-0116
  - CVE-2012-0117
  - CVE-2012-0118
  - CVE-2012-0119
  - CVE-2012-0120
  - CVE-2012-0484
  - CVE-2012-0485
  - CVE-2012-0486
  - CVE-2012-0487
  - CVE-2012-0488
  - CVE-2012-0489
  - CVE-2012-0490
  - CVE-2012-0491
  - CVE-2012-0492
  - CVE-2012-0493
  - CVE-2012-0494
  - CVE-2012-0495
  - CVE-2012-0496

Show diffs side-by-side

added added

removed removed

Lines of Context:
567
567
DROP USER 'Tester';
568
568
DROP DATABASE B48872;
569
569
End of 5.0 tests.
 
570
#
 
571
# Bug#11882603 SELECT_ACL ON ANY COLUMN IN MYSQL.PROC ALLOWS TO SEE
 
572
#              DEFINITION OF ANY ROUTINE. 
 
573
#
 
574
DROP DATABASE IF EXISTS db1;
 
575
CREATE DATABASE db1;
 
576
CREATE PROCEDURE db1.p1() SELECT 1;
 
577
CREATE USER user2@localhost IDENTIFIED BY '';
 
578
GRANT SELECT(db) ON mysql.proc TO user2@localhost;
 
579
# Connection con2 as user2
 
580
# The statement below before disclosed info from body_utf8 column.
 
581
SHOW CREATE PROCEDURE db1.p1;
 
582
ERROR 42000: PROCEDURE p1 does not exist
 
583
# Check that SHOW works with SELECT grant on whole table
 
584
# Connection default
 
585
GRANT SELECT ON mysql.proc TO user2@localhost;
 
586
# Connection con2
 
587
# This should work
 
588
SHOW CREATE PROCEDURE db1.p1;
 
589
Procedure       sql_mode        Create Procedure        character_set_client    collation_connection    Database Collation
 
590
p1              CREATE DEFINER=`root`@`localhost` PROCEDURE `p1`()
 
591
SELECT 1        latin1  latin1_swedish_ci       latin1_swedish_ci
 
592
# Connection default
 
593
DROP USER user2@localhost;
 
594
DROP DATABASE db1;