pgsql: to_char(): prevent writing beyond the allocated buffer - Mailing list pgsql-committers

From Bruce Momjian
Subject pgsql: to_char(): prevent writing beyond the allocated buffer
Date
Msg-id E1YIIVa-0008Pu-SI@gemulon.postgresql.org
Whole thread Raw
List pgsql-committers
to_char():  prevent writing beyond the allocated buffer

Previously very long localized month and weekday strings could
overflow the allocated buffers, causing a server crash.

Reported and patch reviewed by Noah Misch.  Backpatch to all
supported versions.

Security: CVE-2015-0241

Branch
------
REL9_1_STABLE

Details
-------
http://git.postgresql.org/pg/commitdiff/2ceb63deb2db905ac030130705e33d776a28472a

Modified Files
--------------
src/backend/utils/adt/formatting.c |  139 ++++++++++++++++++++++++++++++++----
1 file changed, 125 insertions(+), 14 deletions(-)


pgsql-committers by date:

Previous
From: Bruce Momjian
Date:
Subject: pgsql: to_char(): prevent writing beyond the allocated buffer
Next
From: Tom Lane
Date:
Subject: pgsql: Last-minute updates for release notes.