pgsql: Fix null-dereference crash in parse_xml_decl(). - Mailing list pgsql-committers

From Tom Lane
Subject pgsql: Fix null-dereference crash in parse_xml_decl().
Date
Msg-id E1QQMWz-0000ag-1g@gemulon.postgresql.org
Whole thread Raw
List pgsql-committers
Fix null-dereference crash in parse_xml_decl().

parse_xml_decl's header comment says you can pass NULL for any unwanted
output parameter, but it failed to honor this contract for the "standalone"
flag.  The only currently-affected caller is xml_recv, so the net effect is
that sending a binary XML value containing a standalone parameter in its
xml declaration would crash the backend.  Per bug #6044 from Christopher
Dillard.

In passing, remove useless initializations of parse_xml_decl's output
parameters in xml_parse.

Back-patch to 8.3, where this code was introduced.

Branch
------
REL8_3_STABLE

Details
-------
http://git.postgresql.org/pg/commitdiff/f064a4f2633088ffb3269907fe58d9a410dc021f

Modified Files
--------------
src/backend/utils/adt/xml.c |   10 ++++++----
1 files changed, 6 insertions(+), 4 deletions(-)


pgsql-committers by date:

Previous
From: Tom Lane
Date:
Subject: pgsql: Fix null-dereference crash in parse_xml_decl().
Next
From: Peter Eisentraut
Date:
Subject: pgsql: Avoid compiler warning when building without zlib