diff options
| author | Tom Lane <tgl@sss.pgh.pa.us> | 2012-02-23 15:53:09 -0500 |
|---|---|---|
| committer | Tom Lane <tgl@sss.pgh.pa.us> | 2012-02-23 15:53:09 -0500 |
| commit | 89e0bac86dbca40dfc321926205f2a90d3da5437 (patch) | |
| tree | eb6b9b1d6336ca592914e3d83485b4d84b426eaa /contrib/btree_gist/sql | |
| parent | 077711c2e3e86384d19d833233bd35e05b921cfc (diff) | |
Convert newlines to spaces in names written in pg_dump comments.
pg_dump was incautious about sanitizing object names that are emitted
within SQL comments in its output script. A name containing a newline
would at least render the script syntactically incorrect. Maliciously
crafted object names could present a SQL injection risk when the script
is reloaded.
Reported by Heikki Linnakangas, patch by Robert Haas
Security: CVE-2012-0868
Diffstat (limited to 'contrib/btree_gist/sql')
0 files changed, 0 insertions, 0 deletions
