pgsql: array_in() and array_recv() need to be more paranoid about - Mailing list pgsql-committers

From [email protected] (Tom Lane)
Subject pgsql: array_in() and array_recv() need to be more paranoid about
Date
Msg-id [email protected]
Whole thread Raw
List pgsql-committers
Log Message:
-----------
array_in() and array_recv() need to be more paranoid about validating
their OID parameter.  It was possible to crash the backend with
select array_in('{123}',0,0); because that would bypass the needed step
of initializing the workspace.  These seem to be the only two places
with a problem, though (record_in and record_recv don't have the issue,
and the other array functions aren't depending on user-supplied input).
Back-patch as far as 7.4; 7.3 does not have the bug.

Modified Files:
--------------
    pgsql/src/backend/utils/adt:
        arrayfuncs.c (r1.121 -> r1.122)
        (http://developer.postgresql.org/cvsweb.cgi/pgsql/src/backend/utils/adt/arrayfuncs.c.diff?r1=1.121&r2=1.122)

pgsql-committers by date:

Previous
From: [email protected] (Tom Lane)
Date:
Subject: pgsql: int_array_enum function should be using fcinfo->flinfo->fn_extra
Next
From: [email protected] (Tom Lane)
Date:
Subject: pgsql: array_in() and array_recv() need to be more paranoid about