Files
postgresql/src
Tom Lane 89e0bac86d Convert newlines to spaces in names written in pg_dump comments.
pg_dump was incautious about sanitizing object names that are emitted
within SQL comments in its output script.  A name containing a newline
would at least render the script syntactically incorrect.  Maliciously
crafted object names could present a SQL injection risk when the script
is reloaded.

Reported by Heikki Linnakangas, patch by Robert Haas

Security: CVE-2012-0868
2012-02-23 15:53:09 -05:00
..
2011-11-27 22:42:32 +02:00
2012-02-15 12:13:32 -05:00
2012-02-15 12:13:32 -05:00
2012-02-02 20:33:29 +02:00