|
41 | 41 |
|
42 | 42 | <listitem>
|
43 | 43 | <!--
|
| 44 | +Author: Tom Lane < [email protected]> |
| 45 | +Branch: master [3492a0af0] 2018-02-05 10:37:30 -0500 |
| 46 | +Branch: REL_10_STABLE [fe921a360] 2018-02-05 10:37:30 -0500 |
| 47 | +--> |
| 48 | + <para> |
| 49 | + Fix processing of partition keys containing multiple expressions |
| 50 | + (Álvaro Herrera, David Rowley) |
| 51 | + </para> |
| 52 | + |
| 53 | + <para> |
| 54 | + This error led to crashes or, with carefully crafted input, disclosure |
| 55 | + of arbitrary backend memory. |
| 56 | + (CVE-2018-1052) |
| 57 | + </para> |
| 58 | + </listitem> |
| 59 | + |
| 60 | + <listitem> |
| 61 | +<!-- |
| 62 | +Author: Tom Lane < [email protected]> |
| 63 | +Branch: master [a926eb84e] 2018-02-05 10:58:27 -0500 |
| 64 | +Branch: REL_10_STABLE [6ba52aeb2] 2018-02-05 10:58:27 -0500 |
| 65 | +Branch: REL9_6_STABLE [1341e017d] 2018-02-05 10:58:27 -0500 |
| 66 | +Branch: REL9_5_STABLE [17aa02368] 2018-02-05 10:58:27 -0500 |
| 67 | +Branch: REL9_4_STABLE [c3456208d] 2018-02-05 10:58:27 -0500 |
| 68 | +Branch: REL9_3_STABLE [9c59e48a2] 2018-02-05 10:58:27 -0500 |
| 69 | +--> |
| 70 | + <para> |
| 71 | + Ensure that all temporary files made |
| 72 | + by <application>pg_upgrade</application> are non-world-readable |
| 73 | + (Tom Lane, Noah Misch) |
| 74 | + </para> |
| 75 | + |
| 76 | + <para> |
| 77 | + <application>pg_upgrade</application> normally restricts its |
| 78 | + temporary files to be readable and writable only by the calling user. |
| 79 | + But the temporary file containing <literal>pg_dumpall -g</literal> |
| 80 | + output would be group- or world-readable, or even writable, if the |
| 81 | + user's <literal>umask</literal> setting allows. In typical usage on |
| 82 | + multi-user machines, the <literal>umask</literal> and/or the working |
| 83 | + directory's permissions would be tight enough to prevent problems; |
| 84 | + but there may be people using <application>pg_upgrade</application> |
| 85 | + in scenarios where this oversight would permit disclosure of database |
| 86 | + passwords to unfriendly eyes. |
| 87 | + (CVE-2018-1053) |
| 88 | + </para> |
| 89 | + </listitem> |
| 90 | + |
| 91 | + <listitem> |
| 92 | +<!-- |
44 | 93 | Author: Andres Freund < [email protected]>
|
45 | 94 | Branch: master [9c2f0a6c3] 2017-12-14 18:20:47 -0800
|
46 | 95 | Branch: REL_10_STABLE [1224383e8] 2017-12-14 18:20:48 -0800
|
|
0 commit comments