Fwd: BUG #14998: XXS vulnerabilities in PostgreSQL 'utf8 4-byte truncation'

Поиск
Список
Период
Сортировка
От Thu Luu
Тема Fwd: BUG #14998: XXS vulnerabilities in PostgreSQL 'utf8 4-byte truncation'
Дата
Msg-id CAJ4jF7Vhc0b3gNHAJUMsNG8UDwKWyDGxrwVZNLH_RWGZFR8iug@mail.gmail.com
обсуждение исходный текст
Ответ на BUG #14998: XXS vulnerabilities in PostgreSQL 'utf8 4-byte truncation'  (PG Bug reporting form <noreply@postgresql.org>)
Ответы Re: BUG #14998: XXS vulnerabilities in PostgreSQL 'utf8 4-byte truncation'  (Sergei Kornilov <sk@zsrv.org>)
Список pgsql-bugs
Hi Andres, 

My application uses PostgreSQL 9.6.2: 

Inline image 1

When we try inputing to my application as the below: 
Inline image 3
The result: 
Inline image 5

As far as I know, this error is fixed by using MySQL's strict mode. For PostgreSQL, can there be any other way?  

We appreciate your help in this matter and look forward to hearing from you soon.

Thanks, 
Thu Luu

On Thu, Jan 4, 2018 at 11:22 AM, Andres Freund <andres@anarazel.de> wrote:
On 2018-01-04 04:19:19 +0000, PG Bug reporting form wrote:
> The following bug has been logged on the website:
>
> Bug reference:      14998
> Logged by:          Thu Luu
> Email address:      ltthu2810@gmail.com
> PostgreSQL version: 9.6.2
> Operating system:   CentOs 6.x
> Description:
>
> My application uses the Postgresql 9.6.2. But, when I use the tool to scan
> the vulnerabilities. There are some errors related to DB: 'MYSQL utf8 4-byte
> truncation'.
> Refer:
> https://www.acunetix.com/vulnerabilities/web/mysql-utf8-4-byte-truncation

Postgres is not mysql, and to my knowledge does not suffer from an
equivalent vulnerability. So this more looks like a weakness in your
scanning tool.

Greetings,

Andres Freund


Вложения

В списке pgsql-bugs по дате отправления:

Предыдущее
От: Andres Freund
Дата:
Сообщение: Re: BUG #14998: XXS vulnerabilities in PostgreSQL 'utf8 4-bytetruncation'
Следующее
От: Sergei Kornilov
Дата:
Сообщение: Re: BUG #14998: XXS vulnerabilities in PostgreSQL 'utf8 4-byte truncation'