Updates for PostgreSQL 11.3, 10.8, 9.6.13, 9.5.17, and 9.4.22

Updates have been formed corrective updates for all supported branches of PostgreSQL: 11.3, 10.8, 9.6.13, 9.5.17 and 9.4.22, in which a portion of bug fixes is presented. Updates for branch 9.4 will continue until December 2019, 9.5 until January 2021, 9.6 — until September 2021, 10 — until October 2022, 11 — until November 2023.

In the new versions, over 60 bugs have been fixed and four vulnerabilities have been addressed:

  • Two vulnerabilities (CVE-2019-10127, CVE-2019-10128) are specific to the Windows platform and appear in installers from EnterpriseDB and BigSQL, which did not set proper access rights on the data directory, allowing any unprivileged Windows user to initiate code execution at the PostgreSQL service level.
  • The CVE-2019-10129 vulnerability appears in PostgreSQL 11 and allows a user to read arbitrary memory areas of the server process by sending a specially crafted INSERT request to a partitioned table.
  • The CVE-2019-10130 vulnerability allows reading the values of records for which access is restricted.

Among the fixed bugs is the corruption of the directory when performing "ALTER TABLE" on a partitioned table, server crashes when an error occurs while attempting to save a cursor between transaction commits, performance issues when rolling back transactions involving a large number of tables, lack of support for the expression "CREATE TABLE IF NOT EXISTS .. AS EXECUTE ..", and memory leaks.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster