Re: Postgres Security fixes

Dieter Simader <[email protected]> Wed, 24 May 2006 09:22:12 -0600 (MDT)
Newsgroups gmane.comp.web.sql-ledger.user
Message-ID <[email protected]>
Strings are escaped with DBI's quote function.

-- 
Dieter Simader    http://www.sql-ledger.com   (780) 472-8161
DWS Systems Inc.     Accounting Software       Fax: 478-5281
============ On a clear disk you can seek forever ==========

This email and any attachments is intended only for the recipient(s)
named above. It may contain confidential or privileged information and
should not be read, copied or otherwise used by any other person. If you
are not the named recipient, please notify the sender and delete the
email from your system.


On Wed, 24 May 2006, Darrick Hartman wrote:

> Dieter,
>
> How will the latest set of Postgresql security fixes affect SQL-Ledger?
>
>  From the technical information:
> http://www.postgresql.org/docs/techdocs.52
>
> "The widely-used practice of escaping ASCII single quote "'" by turning
> it into "\'" is unsafe when operating in multibyte encodings that allow
> 0x5c (ASCII code for backslash) as the trailing byte of a multibyte
> character; this includes at least SJIS, BIG5, GBK, GB18030, and UHC."
>
> Darrick
>
>




_______________________________________________
sql-ledger-users mailing list
sql-ledger-users-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
https://lists.sourceforge.net/lists/listinfo/sql-ledger-users