Merge branch 'm35_MDL-61626_PgSQL_Table_Name_Could_Be_Schema_Qualified' of https://github.com/scara/moodle

This commit is contained in:
Jake Dallimore
2018-03-13 15:37:19 +08:00
+5 -3
View File
@@ -351,13 +351,15 @@ class pgsql_native_moodle_database extends moodle_database {
if ($result) {
while ($row = pg_fetch_assoc($result)) {
if (!preg_match('/CREATE (|UNIQUE )INDEX ([^\s]+) ON '.$tablename.' USING ([^\s]+) \(([^\)]+)\)/i', $row['indexdef'], $matches)) {
// The index definition could be generated schema-qualifying the target table name
// for safety, depending on the pgsql version (CVE-2018-1058).
if (!preg_match('/CREATE (|UNIQUE )INDEX ([^\s]+) ON (|'.$row['schemaname'].'\.)'.$tablename.' USING ([^\s]+) \(([^\)]+)\)/i', $row['indexdef'], $matches)) {
continue;
}
if ($matches[4] === 'id') {
if ($matches[5] === 'id') {
continue;
}
$columns = explode(',', $matches[4]);
$columns = explode(',', $matches[5]);
foreach ($columns as $k=>$column) {
$column = trim($column);
if ($pos = strpos($column, ' ')) {