Re: Postgres Security fixes

Tom Diehl <tdiehl-Vm+IDG5ujV1Wk0Htik3J/[email protected]> Wed, 24 May 2006 18:52:43 -0400 (EDT)
Newsgroups gmane.comp.web.sql-ledger.user
Message-ID <[email protected]>
On Wed, 24 May 2006, Dieter Simader wrote:

> Strings are escaped with DBI's quote function.

Not to be dense but does that mean we do or do not have to worry
about the security updates wrt sql-ledger? If we do than specifically what
needs to be done?

Regards,

Tom Diehl		tdiehl-Vm+IDG5ujV1Wk0Htik3J/[email protected]		Spamtrap address mtd123-Vm+IDG5ujV1Wk0Htik3J/[email protected]

> 
> -- 
> Dieter Simader    http://www.sql-ledger.com   (780) 472-8161
> DWS Systems Inc.     Accounting Software       Fax: 478-5281
> ============ On a clear disk you can seek forever ==========
> 
> This email and any attachments is intended only for the recipient(s)
> named above. It may contain confidential or privileged information and
> should not be read, copied or otherwise used by any other person. If you
> are not the named recipient, please notify the sender and delete the
> email from your system.
> 
> 
> On Wed, 24 May 2006, Darrick Hartman wrote:
> 
> > Dieter,
> >
> > How will the latest set of Postgresql security fixes affect SQL-Ledger?
> >
> >  From the technical information:
> > http://www.postgresql.org/docs/techdocs.52
> >
> > "The widely-used practice of escaping ASCII single quote "'" by turning
> > it into "\'" is unsafe when operating in multibyte encodings that allow
> > 0x5c (ASCII code for backslash) as the trailing byte of a multibyte
> > character; this includes at least SJIS, BIG5, GBK, GB18030, and UHC."
> >
> > Darrick
> >
> >
> 
> 
> 
> 
> _______________________________________________
> sql-ledger-users mailing list
> sql-ledger-users-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
> https://lists.sourceforge.net/lists/listinfo/sql-ledger-users
> 



_______________________________________________
sql-ledger-users mailing list
sql-ledger-users-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
https://lists.sourceforge.net/lists/listinfo/sql-ledger-users