Re: Postgres Security fixes
Dieter Simader <[email protected]> Wed, 24 May 2006 09:22:12 -0600 (MDT)
| Newsgroups | gmane.comp.web.sql-ledger.user |
|---|---|
| Message-ID | <[email protected]> |
Strings are escaped with DBI's quote function. -- Dieter Simader http://www.sql-ledger.com (780) 472-8161 DWS Systems Inc. Accounting Software Fax: 478-5281 ============ On a clear disk you can seek forever ========== This email and any attachments is intended only for the recipient(s) named above. It may contain confidential or privileged information and should not be read, copied or otherwise used by any other person. If you are not the named recipient, please notify the sender and delete the email from your system. On Wed, 24 May 2006, Darrick Hartman wrote: > Dieter, > > How will the latest set of Postgresql security fixes affect SQL-Ledger? > > From the technical information: > http://www.postgresql.org/docs/techdocs.52 > > "The widely-used practice of escaping ASCII single quote "'" by turning > it into "\'" is unsafe when operating in multibyte encodings that allow > 0x5c (ASCII code for backslash) as the trailing byte of a multibyte > character; this includes at least SJIS, BIG5, GBK, GB18030, and UHC." > > Darrick > > _______________________________________________ sql-ledger-users mailing list sql-ledger-users-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org https://lists.sourceforge.net/lists/listinfo/sql-ledger-users