aboutsummaryrefslogtreecommitdiff
path: root/src/tutorial/basics.source
diff options
context:
space:
mode:
authorTom Lane <tgl@sss.pgh.pa.us>2008-03-01 02:46:55 +0000
committerTom Lane <tgl@sss.pgh.pa.us>2008-03-01 02:46:55 +0000
commit25819aaee3c319088fff39e5efab68b3280d7eaf (patch)
treef3fc2f0742cd4074bbc8010f7553d96c98cef2d7 /src/tutorial/basics.source
parentda956ae76fa08924bb6c1bcd7323ef0566a0194b (diff)
downloadpostgresql-25819aaee3c319088fff39e5efab68b3280d7eaf.tar.gz
postgresql-25819aaee3c319088fff39e5efab68b3280d7eaf.zip
Disable the undocumented xmlvalidate() function, which was unintentionally
left in the code though it was not meant to be provided. It represents a security hole because unprivileged users could use it to look at (at least the first line of) any file readable by the backend. Fortunately, this is only possible if the backend was built with XML support, so the damage is at least mitigated; and 8.3 probably hasn't propagated into any security-critical uses yet anyway. Per report from Sergey Burladyan.
Diffstat (limited to 'src/tutorial/basics.source')
0 files changed, 0 insertions, 0 deletions