On Sun, Jan 20, 2013 at 4:59 PM, Tom Lane <t...@sss.pgh.pa.us> wrote:
> Magnus Hagander <mag...@hagander.net> writes:
>> +             PGresult *res = ExecuteSqlQueryForSingleRow(fout, "SELECT 
>> pg_is_in_recovery()");
>
> That function call needs to be schema-qualified for security.

Applied and backpatched, with that fix and a sentence in the
documentation added.

--
 Magnus Hagander
 Me: http://www.hagander.net/
 Work: http://www.redpill-linpro.com/


-- 
Sent via pgsql-bugs mailing list (pgsql-bugs@postgresql.org)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-bugs

Reply via email to