aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorTom Lane <tgl@sss.pgh.pa.us>2007-04-20 03:27:54 +0000
committerTom Lane <tgl@sss.pgh.pa.us>2007-04-20 03:27:54 +0000
commitcfe1b04c66078a604aba5073133830e7fd5ce7d0 (patch)
treedc2f28bcd2e19ba0bea8e88dd1dad4d3732178c5
parent566331a2e983cc6bf00baf11b4cfe9b906a2727d (diff)
downloadpostgresql-cfe1b04c66078a604aba5073133830e7fd5ce7d0.tar.gz
postgresql-cfe1b04c66078a604aba5073133830e7fd5ce7d0.zip
Fix markup.
Security: CVE-2007-2138
-rw-r--r--doc/src/sgml/release.sgml11
1 files changed, 4 insertions, 7 deletions
diff --git a/doc/src/sgml/release.sgml b/doc/src/sgml/release.sgml
index 18303fca6eb..d50a61677e0 100644
--- a/doc/src/sgml/release.sgml
+++ b/doc/src/sgml/release.sgml
@@ -1,5 +1,5 @@
<!--
-$PostgreSQL: pgsql/doc/src/sgml/release.sgml,v 1.321.4.35 2007/04/20 02:38:31 tgl Exp $
+$PostgreSQL: pgsql/doc/src/sgml/release.sgml,v 1.321.4.36 2007/04/20 03:27:54 tgl Exp $
-->
<appendix id="release">
@@ -45,8 +45,7 @@ $PostgreSQL: pgsql/doc/src/sgml/release.sgml,v 1.321.4.35 2007/04/20 02:38:31 tg
truly secure value of <varname>search_path</>. Without it,
an unprivileged SQL user can use temporary objects to execute code
with the privileges of the security-definer function (CVE-2007-2138).
- See <xref linkend="sql-createfunction"
- endterm="sql-createfunction-title"> for more information.
+ See <command>CREATE FUNCTION</> for more information.
</para>
</listitem>
@@ -3554,8 +3553,7 @@ typedefs (Michael)</para></listitem>
truly secure value of <varname>search_path</>. Without it,
an unprivileged SQL user can use temporary objects to execute code
with the privileges of the security-definer function (CVE-2007-2138).
- See <xref linkend="sql-createfunction"
- endterm="sql-createfunction-title"> for more information.
+ See <command>CREATE FUNCTION</> for more information.
</para>
</listitem>
@@ -6739,8 +6737,7 @@ DROP SCHEMA information_schema CASCADE;
truly secure value of <varname>search_path</>. Without it,
an unprivileged SQL user can use temporary objects to execute code
with the privileges of the security-definer function (CVE-2007-2138).
- See <xref linkend="sql-createfunction"
- endterm="sql-createfunction-title"> for more information.
+ See <command>CREATE FUNCTION</> for more information.
</para>
</listitem>