Article 42GYA PostgreSQL 11.1, 10.6, 9.6.11, 9.5.15, 9.4.20, and 9.3.25 released

PostgreSQL 11.1, 10.6, 9.6.11, 9.5.15, 9.4.20, and 9.3.25 released

by
corbet
from LWN.net on (#42GYA)
There is a whole new set of PostgreSQL releases out there, the main purposeof which is to include an important security fix."Using a purpose-crafted trigger definition, an attacker can runarbitrary SQL statements with superuser privileges when a superuser runs`pg_upgrade` on the database or during a pg_dump dump/restore cycle.This attack requires a `CREATE` privilege on some non-temporary schemaor a `TRIGGER` privilege on a table. This is exploitable in the defaultPostgreSQL configuration, where all users have `CREATE` privilege on`public` schema." Note that this is the final update for the 9.3series; users on that version should be planning an upgrade in the nearfuture.
External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments