]> git.ipfire.org Git - thirdparty/postgresql.git/commit
Fix Windows shell argument quoting.
authorNoah Misch <noah@leadboat.com>
Mon, 8 Aug 2016 14:07:46 +0000 (10:07 -0400)
committerNoah Misch <noah@leadboat.com>
Mon, 8 Aug 2016 14:07:53 +0000 (10:07 -0400)
commit4837155292f67f10576f3d7204ffd5379bbe3a7b
tree22e430cf8690d0980d76805874b4f79f63ca23a5
parentffbdab65d3451d72762319829b4bc26dc71a8b48
Fix Windows shell argument quoting.

The incorrect quoting may have permitted arbitrary command execution.
At a minimum, it gave broader control over the command line to actors
supposed to have control over a single argument.  Back-patch to 9.1 (all
supported versions).

Security: CVE-2016-5424
src/bin/pg_dump/pg_dumpall.c