]> git.ipfire.org Git - thirdparty/postgresql.git/commit
Fix Windows shell argument quoting.
authorNoah Misch <noah@leadboat.com>
Mon, 8 Aug 2016 14:07:46 +0000 (10:07 -0400)
committerNoah Misch <noah@leadboat.com>
Mon, 8 Aug 2016 14:07:50 +0000 (10:07 -0400)
commit2e5e90d8d10ca568381adfaaf53e8a9e8e342375
tree7f2c9b7b64991d968d3a9406e0944cd528e2fa20
parentec3aebdbdf0137c8ff27ae089d1431cf61bc15b5
Fix Windows shell argument quoting.

The incorrect quoting may have permitted arbitrary command execution.
At a minimum, it gave broader control over the command line to actors
supposed to have control over a single argument.  Back-patch to 9.1 (all
supported versions).

Security: CVE-2016-5424
src/bin/pg_dump/pg_dumpall.c