diff options
author | Tom Lane <tgl@sss.pgh.pa.us> | 2010-09-25 15:57:05 -0400 |
---|---|---|
committer | Tom Lane <tgl@sss.pgh.pa.us> | 2010-09-25 17:01:39 -0400 |
commit | 42c387166d4cd3e7151c88692a157bfe9a621a4d (patch) | |
tree | ed09a4da8a9950783f9a57bac91309939ef1d6d7 /src/pl/plperl/plperl.c | |
parent | dbf859c711b3d5981a5343a26a35236511b8d0aa (diff) |
Further fixes to the pg_get_expr() security fix in back branches.
It now emerges that the JDBC driver expects to be able to use pg_get_expr()
on an output of a sub-SELECT. So extend the check logic to be able to recurse
into a sub-SELECT to see if the argument is ultimately coming from an
appropriate column. Per report from Thomas Kellerer.
Diffstat (limited to 'src/pl/plperl/plperl.c')
0 files changed, 0 insertions, 0 deletions