~ubuntu-branches/ubuntu/breezy/dovecot/breezy-security

Viewing all changes in revision 4.

  • Committer: Bazaar Package Importer
  • Author(s): Martin Pitt
  • Date: 2006-06-02 10:45:15 UTC
  • Revision ID: james.westby@ubuntu.com-20060602104515-hv6t9m5e33r9vrek
Tags: 0.99.14-1ubuntu1.1
* SECURITY UPDATE: SQL injection with certain client character encodings.
* src/lib/strescape.c, str_escape(): Escape ' as '', not as \'. In this
  version, this function is still only used for escaping database queries,
  so this does not break anything else.
* CVE-2006-2314

expand all expand all

Show diffs side-by-side

added added

removed removed

Lines of Context: