↑↓ 选择 ↵ 打开 ⌫ 改范围 完整检索页

pgsql.cc 提供对 postgresql.org 官网内容的中文翻译,由 Pigsty 团队维护。

百科 / 版本发布

PostgreSQL 11

已停止支持 · 记录构建 11.22 · 2023-11-09

此大版本已停止支持,相关记录用于查阅历史;没有更新的安全记录不代表仍可安全运行。

首次正式发布
2018-10-18
支持结束
2023-11-09
已收录发布版本
23
原始发布说明条目
1141

手册与来源

PostgreSQL 11 本站手册 · 已加载 1049 页。

手册加载时间:2026-09-27T00:10:45.258078。

发布说明快照:2026-09-26。安全证据快照:2026-09-26。PDF 链接按本地文件是否存在提供,历史版本的语言与 HTML 手册可能不同。生命周期参见官方版本政策。

升级注意事项

跨大版本升级需要导出/恢复或 pg_upgrade 等迁移方式,应阅读沿途大版本的发布说明与目标版本手册。小版本更新也可能要求额外操作,请核对对应发布的迁移说明。官方升级政策。

11.0 的兼容性变化 · 从首发到 11.22 的变化

11.0 的原始迁移说明

对于希望从任何先前版本迁移数据的用户,需要使用pg_dumpall进行导出/恢复,或使用pg_upgrade或逻辑复制。有关迁移到新主版本的一般信息,请参见第 18.6 节。

版本 11 包含许多可能影响与先前版本兼容性的变更。请注意以下不兼容性:

发布历史

每次发布的原始变更均独立保留。CVE 数量表示发布说明中的提及,可能包含后续纠正,不等于本次新修复漏洞数。

版本日期/快照截止时间全部变化BUG 修复迁移条目提及 CVE
11.22 2023-11-09 311003
11.21 2023-08-10 291101
11.20 2023-05-11 442202
11.19 2023-02-09 291200
11.18 2022-11-10 321500
11.17 2022-08-11 371402
11.16 2022-05-12 321601
11.15 2022-02-10 291300
11.14 2021-11-11 582702
11.13 2021-08-12 632003
11.12 2021-05-13 331703
11.11 2021-02-11 562601
11.10 2020-11-12 461703
11.9 2020-08-13 432203
11.8 2020-05-14 552300
11.7 2020-02-13 562902
11.6 2019-11-14 673100
11.5 2019-08-08 471803
11.4 2019-06-20 261601
11.3 2019-05-09 634003
11.2 2019-02-14 733700
11.1 2018-11-08 221201
11.0 2018-10-18 1701200

首次发布变化

11.0 的原始条目,包含功能和兼容性变化。类别用于浏览,不是上游原始分类。

匹配 170 / 170 条原始变更。

安全证据

共 38 条记录,来自官方安全矩阵及发布说明的提及。只有安全快照明确列出此分支时才显示修复版本;仅有提及不能确定漏洞适用性或新修复。

CVE-2023-5870 · Role "pg_signal_backend" can signal certain superuser processes · CVSS 2.2

Documentation says the pg_signal_backend role cannot signal "a backend owned by a superuser". On the contrary, it can signal background workers, including the logical replication launcher. It can signal autovacuum workers and the autovacuum launcher. Signaling autovacuum workers and those two launchers provides no meaningful exploit, so exploiting this vulnerability requires a non-core extension with a less-resilient background worker. For example, a non-core background worker that does not auto-restart would experience a denial of service with respect to that particular background worker. The PostgreSQL project thanks Hemanth Sandrana and Mahendrakar Srinivasarao for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.22。组件:core server。

官方受影响分支记录:11。

AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L

发布说明中的提及:

CVE-2023-5869 · Buffer overrun from integer overflow in array modification · CVSS 8.8

While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others. The PostgreSQL project thanks Pedro Gallegos for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.22。组件:core server。

官方受影响分支记录:11。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2023-5868 · Memory disclosure in aggregate function calls · CVSS 4.3

Certain aggregate function calls receiving "unknown"-type arguments could disclose bytes of server memory from the end of the "unknown"-type value to the next zero byte. One typically gets an "unknown"-type value via a string literal having no type designation. We have not confirmed or ruled out viability of attacks that arrange for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jingzhou Fu for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.22。组件:core server。

官方受影响分支记录:11。

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2023-39417 · Extension script @substitutions@ within quoting allow SQL injection · CVSS 7.5

An extension script is vulnerable if it uses @extowner@ , @extschema@ , or @extschema:...@ inside a quoting construct (dollar quoting, '' , or "" ). No bundled extension is vulnerable. Vulnerable uses do appear in a documentation example and in non-bundled extensions. Hence, the attack prerequisite is an administrator having installed files of a vulnerable, trusted, non-bundled extension. Subject to that prerequisite, this enables an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. PostgreSQL will block this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Micah Gates, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.21。组件:core server。

官方受影响分支记录:11。

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2023-2455 · Row security policies disregard user ID changes after inlining · CVSS 4.2

While CVE-2016-2193 fixed most interaction between row security and user ID changes, it missed a scenario involving function inlining. This leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLE s. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. The PostgreSQL project thanks Wolfgang Walther for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.20。组件:core server。

官方受影响分支记录:11。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

发布说明中的提及:

CVE-2023-2454 · CREATE SCHEMA ... schema_element defeats protective search_path changes · CVSS 7.2

This enabled an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. Database owners have that right by default, and explicit grants may extend it to other users. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.20。组件:core server。

官方受影响分支记录:11。

AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2022-2625 · Extension scripts replace objects not belonging to the extension · CVSS 7.1

Some extensions use CREATE OR REPLACE or CREATE IF NOT EXISTS commands. Some don't adhere to the documented rule to target only objects known to be extension members already. An attack requires permission to create non-temporary objects in at least one schema, ability to lure or wait for an administrator to create or update an affected extension in that schema, and ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS . Given all three prerequisites, the attacker can run arbitrary code as the victim role, which may be a superuser. Known-affected extensions include both PostgreSQL-bundled and non-bundled extensions. PostgreSQL is blocking this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Sven Klemm for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.17。组件:core server。

官方受影响分支记录:11。

AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2022-1552 · Autovacuum, REINDEX, and others omit "security restricted operation" sandbox · CVSS 8.8

Autovacuum, REINDEX , CREATE INDEX , REFRESH MATERIALIZED VIEW , CLUSTER , and pg_amcheck made incomplete efforts to operate safely when a privileged user is maintaining another user's objects. Those commands activated relevant protections too late or not at all. An attacker having permission to create non-temp objects in at least one schema could execute arbitrary SQL functions under a superuser identity. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum, not manually running the above commands, and not restoring from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.16。组件:core server。

官方受影响分支记录:11。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2021-3677 · Memory disclosure in certain queries · CVSS 6.5

A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0 , the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.

以上保留官方英文漏洞说明。

本分支修复于:11.13。组件:core server。

官方受影响分支记录:11。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

发布说明中的提及:

CVE-2021-3449 · CVE-2021-3449

尚未记录本分支的修复版本。

发布说明中的提及:

CVE-2021-3393 · Partition constraint violation errors leak values of denied columns · CVSS 3.1

A user having an UPDATE privilege on a partitioned table but lacking the SELECT privilege on some column may be able to acquire denied-column values from an error message. This is similar to CVE-2014-8161 , but the conditions to exploit are more rare. The PostgreSQL project thanks Heikki Linnakangas for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.11。组件:core server。

官方受影响分支记录:11。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2021-32029 · Memory disclosure in partitioned-table UPDATE ... RETURNING · CVSS 6.5

Using an UPDATE ... RETURNING on a purpose-crafted partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas typically cannot use this attack at will. The PostgreSQL project thanks Tom Lane for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.12。组件:core server。

官方受影响分支记录:11。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

发布说明中的提及:

CVE-2021-32028 · Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE · CVSS 6.5

Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas cannot use this attack at will. The PostgreSQL project thanks Andres Freund for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.12。组件:core server。

官方受影响分支记录:11。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

发布说明中的提及:

CVE-2021-32027 · Buffer overrun from integer overflow in array subscripting calculations · CVSS 6.5

While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The PostgreSQL project thanks Tom Lane for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.12。组件:core server。

官方受影响分支记录:11。

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

发布说明中的提及:

CVE-2021-23222 · libpq processes unencrypted bytes from man-in-the-middle · CVSS 3.7

A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property is a PostgreSQL configuration vulnerable to CVE-2021-23214 . As with any exploitation of CVE-2021-23214 , the server must be using trust authentication with a clientcert requirement or using cert authentication. To disclose a password, the client must be in possession of a password, which is atypical when using an authentication configuration vulnerable to CVE-2021-23214 . The attacker must have some other way to access the server to retrieve the exfiltrated data (a valid, unprivileged login account would be sufficient). The PostgreSQL project thanks Jacob Champion for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.14。组件:client。

官方受影响分支记录:11。

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2021-23214 · Server processes unencrypted bytes from man-in-the-middle · CVSS 8.1

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product). The PostgreSQL project thanks Jacob Champion for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.14。组件:core server。

官方受影响分支记录:11。

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2020-25696 · psql's \gset allows overwriting specially treated variables · CVSS 7.5

The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.10。组件:client。

官方受影响分支记录:11。

AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2020-25695 · Multiple features escape "security restricted operation" sandbox · CVSS 8.8

An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.10。组件:core server。

官方受影响分支记录:11。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2020-25694 · Reconnection can downgrade connection security settings · CVSS 8.1

Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.10。组件:client。

官方受影响分支记录:11。

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2020-1720 · ALTER ... DEPENDS ON EXTENSION is missing authorization checks. · CVSS 3.1

The ALTER ... DEPENDS ON EXTENSION sub-commands do not perform authorization checks, which can allow an unprivileged user to drop any function, procedure, materialized view, index, or trigger under certain conditions. This attack is possible if an administrator has installed an extension and an unprivileged user can CREATE , or an extension owner either executes DROP EXTENSION predictably or can be convinced to execute DROP EXTENSION . The PostgreSQL project thanks Tom Lane for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.7。组件:core server。

官方受影响分支记录:11。

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

发布说明中的提及:

CVE-2020-14350 · Uncontrolled search path element in CREATE EXTENSION · CVSS 7.1

When a superuser runs certain CREATE EXTENSION statements, users may be able to execute arbitrary SQL functions under the identity of that superuser. The attacker must have permission to create objects in the new extension's schema or a schema of a prerequisite extension. Not all extensions are vulnerable. In addition to correcting the extensions provided with PostgreSQL, the PostgreSQL Global Development Group is issuing guidance for third-party extension authors to secure their own work. The PostgreSQL project thanks Andres Freund for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.9。组件:core server。

官方受影响分支记录:11。

AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2020-14349 · Uncontrolled search path element in logical replication · CVSS 7.5

The PostgreSQL search_path setting determines schemas searched for tables, functions, operators, etc. The CVE-2018-1058 fix caused most PostgreSQL-provided client applications to sanitize search_path , but logical replication continued to leave search_path unchanged. Users of a replication publisher or subscriber database can create objects in the public schema and harness them to execute arbitrary SQL functions under the identity running replication, often a superuser. Installations having adopted a documented secure schema usage pattern are not vulnerable. The PostgreSQL project thanks Noah Misch for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.9。组件:core server。

官方受影响分支记录:11。

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2020-10733 · Windows installer runs executables from uncontrolled directories · CVSS 6.7

The Windows installer for PostgreSQL invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. The PostgreSQL project thanks Hou JingYi (@hjy79425575) for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.8。组件:packaging。

官方受影响分支记录:11。

AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVE-2019-3466 · pg_ctlcluster script in postgresql-common does not drop privileges when creating socket/statistics temporary directories · CVSS 8.4

A PostgreSQL superuser could escalate to root using a deficiency in the pg_ctlcluster command. pg_ctlcluster is a utility provided by the "postgresql-common" package that is installed with PostgreSQL on Debian and Ubuntu platforms.

以上保留官方英文漏洞说明。

本分支修复于:11.6。组件:packaging。

官方受影响分支记录:11。

AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

CVE-2019-10211 · Windows installer bundled OpenSSL executes code from unprotected directory · CVSS 7.8

When the database server or libpq client library initializes SSL, libeay32.dll attempts to read configuration from a hard-coded directory. Typically, the directory does not exist, but any local user could create it and inject configuration. This configuration can direct OpenSSL to load and execute arbitrary code as the user running a PostgreSQL server or client. Most PostgreSQL client tools and libraries use libpq , and one can encounter this vulnerability by using any of them. This vulnerability is much like CVE-2019-5443 , but it originated independently. One can work around the vulnerability by setting environment variable OPENSSL_CONF to "NUL:/openssl.cnf" or any other name that cannot exist as a file. The PostgreSQL project thanks Daniel Gustafsson of the curl security team for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.5。组件:packaging。

官方受影响分支记录:11。

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2019-10210 · Windows installer writes superuser password to unprotected temporary file · CVSS 6.7

The EnterpriseDB Windows installer writes a password to a temporary file in its installation directory, creates initial databases, and deletes the file. During those seconds while the file exists, a local attacker can read the PostgreSQL superuser password from the file. The PostgreSQL project thanks Noah Misch for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.5。组件:packaging。

官方受影响分支记录:11。

AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVE-2019-10209 · Memory disclosure in cross-type comparison for hashed subplan · CVSS 3.1

In a database containing hypothetical, user-defined hash equality operators, an attacker could read arbitrary bytes of server memory. For an attack to become possible, a superuser would need to create unusual operators. It is possible for operators not purpose-crafted for attack to have the properties that enable an attack, but we are not aware of specific examples. The PostgreSQL project thanks Andreas Seltenreich for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.5。组件:core server。

官方受影响分支记录:11。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2019-10208 · TYPE in pg_temp executes arbitrary SQL during SECURITY DEFINER execution · CVSS 7.5

Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function call having inexact argument type match. For example, length('foo'::varchar) and length('foo') are inexact, while length('foo'::text) is exact. As part of exploiting this vulnerability, the attacker uses CREATE DOMAIN to create a type in a pg_temp schema. The attack pattern and fix are similar to that for CVE-2007-2138 . Writing SECURITY DEFINER functions continues to require following the considerations noted in the documentation: https://www.postgresql.org/docs/current/sql-createfunction.html#SQL-CREATEFUNCTION-SECURITY The PostgreSQL project thanks Tom Lane for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.5。组件:core server。

官方受影响分支记录:11。

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2019-10164 · Stack-based buffer overflow via setting a password · CVSS 7.5

An authenticated user could create a stack-based buffer overflow by changing their own password to a purpose-crafted value. In addition to the ability to crash the PostgreSQL server, this could be further exploited to execute arbitrary code as the PostgreSQL operating system account. Additionally, a rogue server could send a specifically crafted message during the SCRAM authentication process and cause a libpq-enabled client to either crash or execute arbitrary code as the client's operating system account. This issue is fixed by upgrading and restarting your PostgreSQL server as well as your libpq installations. The PostgreSQL Project thanks Alexander Lakhin for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.4。组件:core server。

官方受影响分支记录:11。

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2019-10130 · Selectivity estimators bypass row security policies · CVSS 3.1

PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user able to execute SQL queries with permissions to read a given column could craft a leaky operator that could read whatever data had been sampled from that column. If this happened to include values from rows that the user is forbidden to see by a row security policy, the user could effectively bypass the policy. This is fixed by only allowing a non-leakproof operator to use this data if there are no relevant row security policies for the table. The PostgreSQL project thanks Dean Rasheed for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.3。组件:core server。

官方受影响分支记录:11。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2019-10129 · Memory disclosure in partition routing · CVSS 6.5

Prior to this release, a user running PostgreSQL 11 can read arbitrary bytes of server memory by executing a purpose-crafted INSERT statement to a partitioned table.

以上保留官方英文漏洞说明。

本分支修复于:11.3。组件:core server。

官方受影响分支记录:11。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

发布说明中的提及:

CVE-2019-10128 · EnterpriseDB Windows installer does not clear permissive ACL entries · CVSS 7.0

Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.3。组件:packaging。

官方受影响分支记录:11。

AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2019-10127 · BigSQL Windows installer does not clear permissive ACL entries. · CVSS 7.0

Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:11.3。组件:packaging。

官方受影响分支记录:11。

AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2018-16850 · SQL injection in pg_upgrade and pg_dump, via CREATE TRIGGER ... REFERENCING. · CVSS 8.8

本分支修复于:11.1。组件:core server。

官方受影响分支记录:11。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2018-1058 · Uncontrolled search path element in pg_dump and other client applications · CVSS 8.8

尚未记录本分支的修复版本。组件:client。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks · CVSS 4.3
CVE-2007-2138 · A vulnerability involving insecure search_path settings allows unprivileged users to gain the SQL privileges of the owner of any SECURITY DEFINER function they are allowed to call. Securing such a function requires both a software update and changes to the function definition.

尚未记录本分支的修复版本。

发布说明中的提及:

CVE-2006-2313 · An attacker able to submit crafted strings to an application that will embed those strings in SQL commands can use invalidly-encoded multibyte characters to bypass standard string-escaping methods, resulting in possible SQL injection.

导出此分支 JSON · 比较已收录的发布版本