diff options
| author | Tom Lane <tgl@sss.pgh.pa.us> | 2018-08-06 13:13:41 -0400 | 
|---|---|---|
| committer | Tom Lane <tgl@sss.pgh.pa.us> | 2018-08-06 13:13:41 -0400 | 
| commit | ebeb8d53710ea140dd00eb6506cbe50db4e11dce (patch) | |
| tree | 69b5778fd89c9a6de10e8ece10e5afcc236f5166 | |
| parent | 243de06be96d6001d01f2ec7c4573aad8b657195 (diff) | |
Last-minute updates for release notes.
Security: CVE-2018-10915, CVE-2018-10925
| -rw-r--r-- | doc/src/sgml/release-9.3.sgml | 28 | 
1 files changed, 28 insertions, 0 deletions
| diff --git a/doc/src/sgml/release-9.3.sgml b/doc/src/sgml/release-9.3.sgml index a2078eac9ec..b0b46b4b394 100644 --- a/doc/src/sgml/release-9.3.sgml +++ b/doc/src/sgml/release-9.3.sgml @@ -41,6 +41,34 @@      <listitem>       <para> +      Fix failure to reset <application>libpq</application>'s state fully +      between connection attempts (Tom Lane) +     </para> + +     <para> +      An unprivileged user of <filename>dblink</filename> +      or <filename>postgres_fdw</filename> could bypass the checks intended +      to prevent use of server-side credentials, such as +      a <filename>~/.pgpass</filename> file owned by the operating-system +      user running the server.  Servers allowing peer authentication on +      local connections are particularly vulnerable.  Other attacks such +      as SQL injection into a <filename>postgres_fdw</filename> session +      are also possible. +      Attacking <filename>postgres_fdw</filename> in this way requires the +      ability to create a foreign server object with selected connection +      parameters, but any user with access to <filename>dblink</filename> +      could exploit the problem. +      In general, an attacker with the ability to select the connection +      parameters for a <application>libpq</application>-using application +      could cause mischief, though other plausible attack scenarios are +      harder to think of. +      Our thanks to Andrew Krasichkov for reporting this issue. +      (CVE-2018-10915) +     </para> +    </listitem> + +    <listitem> +     <para>        Ensure that updates to the <structfield>relfrozenxid</structfield>        and <structfield>relminmxid</structfield> values        for <quote>nailed</quote> system catalogs are processed in a timely | 
