summaryrefslogtreecommitdiff
path: root/src/tutorial/complex.source
diff options
context:
space:
mode:
authorTom Lane <tgl@sss.pgh.pa.us>2012-02-23 15:53:24 -0500
committerTom Lane <tgl@sss.pgh.pa.us>2012-02-23 15:53:24 -0500
commit02f013ee0228337626071d71abaf2dcb143614a4 (patch)
tree786dafcc6e91244cf910f9228f479815eecad090 /src/tutorial/complex.source
parent850d341ff72b2be53ecea7e05a0bdf9a88ade154 (diff)
Convert newlines to spaces in names written in pg_dump comments.
pg_dump was incautious about sanitizing object names that are emitted within SQL comments in its output script. A name containing a newline would at least render the script syntactically incorrect. Maliciously crafted object names could present a SQL injection risk when the script is reloaded. Reported by Heikki Linnakangas, patch by Robert Haas Security: CVE-2012-0868
Diffstat (limited to 'src/tutorial/complex.source')
0 files changed, 0 insertions, 0 deletions