• Tom Lane's avatar
    Convert newlines to spaces in names written in pg_dump comments. · 89e0bac8
    Tom Lane authored
    pg_dump was incautious about sanitizing object names that are emitted
    within SQL comments in its output script.  A name containing a newline
    would at least render the script syntactically incorrect.  Maliciously
    crafted object names could present a SQL injection risk when the script
    is reloaded.
    
    Reported by Heikki Linnakangas, patch by Robert Haas
    
    Security: CVE-2012-0868
    89e0bac8
pg_backup_archiver.c 105 KB