[MDEV-20110] libmysqlclient allows invalid plugin names Created: 2019-07-21  Updated: 2019-07-22  Resolved: 2019-07-22

Status: Closed
Project: MariaDB Server
Component/s: libmariadb
Affects Version/s: 5.5, 10.1
Fix Version/s: 5.5.65, 10.1.41

Type: Bug Priority: Blocker
Reporter: Sergei Golubchik Assignee: Sergei Golubchik
Resolution: Fixed Votes: 0
Labels: None

Issue Links:
Relates
relates to CONC-429 libmariadb allows invalid plugin names Closed

 Description   

During authentication the server tells client what plugin to load.

The client does not sanitize plugin names as they're coming from the server.



 Comments   
Comment by Sergei Golubchik [ 2019-07-22 ]

Commit 82563c5fc0a

Generated at Thu Feb 08 08:56:54 UTC 2024 using Jira 8.20.16#820016-sha1:9d11dbea5f4be3d4cc21f03a88dd11d8c8687422.