Re: [BUGS] bug or not bug, xmlvalidate(xml, text) can read and show one line from file - Mailing list pgsql-hackers

From Alvaro Herrera
Subject Re: [BUGS] bug or not bug, xmlvalidate(xml, text) can read and show one line from file
Date
Msg-id 20080229194227.GO4673@alvh.no-ip.org
Whole thread Raw
In response to Re: [BUGS] bug or not bug, xmlvalidate(xml, text) can read and show one line from file  (Peter Eisentraut <peter_e@gmx.net>)
Responses Re: [BUGS] bug or not bug, xmlvalidate(xml, text) can read and show one line from file  (Tom Lane <tgl@sss.pgh.pa.us>)
List pgsql-hackers
Peter Eisentraut escribió:
> Am Freitag, 29. Februar 2008 schrieb Tom Lane:
> > Sergey Burladyan <eshkinkot@gmail.com> writes:
> > > [ xmlvalidate is a security hole ]
> >
> > Given that this function is not documented nor tested in the regression
> > tests, I propose diking it out entirely.
> 
> Yes, it was accidentally left over from previous work.  We should have removed 
> it before the release, but that would have required an initdb.

So let's change it for a function that elog(ERROR)s on entry.

-- 
Alvaro Herrera                                http://www.CommandPrompt.com/
PostgreSQL Replication, Consulting, Custom Development, 24x7 support


pgsql-hackers by date:

Previous
From: "Webb Sprague"
Date:
Subject: Re: creating new aggregate function
Next
From: Tom Lane
Date:
Subject: Re: [BUGS] bug or not bug, xmlvalidate(xml, text) can read and show one line from file