pgsql: Sort out paired double quotes in \connect, \password and \crosst - Mailing list pgsql-committers

From Noah Misch
Subject pgsql: Sort out paired double quotes in \connect, \password and \crosst
Date
Msg-id E1bWlGS-0006pp-Nt@gemulon.postgresql.org
Whole thread Raw
List pgsql-committers
Sort out paired double quotes in \connect, \password and \crosstabview.

In arguments, these meta-commands wrongly treated each pair as closing
the double quoted string.  Make the behavior match the documentation.
This is a compatibility break, but I more expect to find software with
untested reliance on the documented behavior than software reliant on
today's behavior.  Back-patch to 9.1 (all supported versions).

Reviewed by Tom Lane and Peter Eisentraut.

Security: CVE-2016-5424

Branch
------
REL9_1_STABLE

Details
-------
http://git.postgresql.org/pg/commitdiff/aed766ab55c7d0f25653427789f78a6e12c2ae7b

Modified Files
--------------
src/bin/psql/psqlscan.l | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)


pgsql-committers by date:

Previous
From: Noah Misch
Date:
Subject: pgsql: Obstruct shell, SQL, and conninfo injection via database and rol
Next
From: Noah Misch
Date:
Subject: pgsql: Sort out paired double quotes in \connect, \password and \crosst