Alvaro Herrera wrote:
>> Actually I was thinking about things like formatting.c which take localized
>> strings and return them as data which can end up in the database. If they're
>> in the wrong encoding then they'll be invalidly encoded strings in the
>> database.
>>
>
> Oh, I didn't think of that. Let me see if I can get an invalid string
> into the database that way.
>
>
I was quite certain when we closed most of these holes recently that we
hadn't caught them all, so this wouldn't surprise me in the least.
cheers
andrew