mirror of https://github.com/postgres/postgres
Last-minute updates for release notes.
Security: CVE-2017-12172, CVE-2017-15098, CVE-2017-15099
This commit is contained in:
parent
eda780281c
commit
203b965f27
|
@ -40,6 +40,31 @@
|
|||
|
||||
<itemizedlist>
|
||||
|
||||
<listitem>
|
||||
<para>
|
||||
Fix sample server-start scripts to become <literal>$PGUSER</literal>
|
||||
before opening <literal>$PGLOG</literal> (Noah Misch)
|
||||
</para>
|
||||
|
||||
<para>
|
||||
Previously, the postmaster log file was opened while still running as
|
||||
root. The database owner could therefore mount an attack against
|
||||
another system user by making <literal>$PGLOG</literal> be a symbolic
|
||||
link to some other file, which would then become corrupted by appending
|
||||
log messages.
|
||||
</para>
|
||||
|
||||
<para>
|
||||
By default, these scripts are not installed anywhere. Users who have
|
||||
made use of them will need to manually recopy them, or apply the same
|
||||
changes to their modified versions. If the
|
||||
existing <literal>$PGLOG</literal> file is root-owned, it will need to
|
||||
be removed or renamed out of the way before restarting the server with
|
||||
the corrected script.
|
||||
(CVE-2017-12172)
|
||||
</para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para>
|
||||
Properly reject attempts to convert infinite float values to
|
||||
|
|
Loading…
Reference in New Issue