PostgreSQL 12
已停止支持 · 记录构建 12.22 · 2024-11-21
此大版本已停止支持,相关记录用于查阅历史;没有更新的安全记录不代表仍可安全运行。
- 首次正式发布
- 2019-10-03
- 支持结束
- 2024-11-21
- 已收录发布版本
- 23
- 原始发布说明条目
- 1181
手册与来源
PostgreSQL 12 本站手册 · 已加载 1058 页。
手册加载时间:2026-09-27T00:10:45.258078。
发布说明快照:2026-09-26。安全证据快照:2026-09-26。PDF 链接按本地文件是否存在提供,历史版本的语言与 HTML 手册可能不同。生命周期参见官方版本政策。
升级注意事项
跨大版本升级需要导出/恢复或 pg_upgrade 等迁移方式,应阅读沿途大版本的发布说明与目标版本手册。小版本更新也可能要求额外操作,请核对对应发布的迁移说明。官方升级政策。
12.0 的原始迁移说明
对于希望从任何先前版本迁移数据的用户,需要使用pg_dumpall进行导出/恢复,或使用pg_upgrade或逻辑复制。有关迁移到新主版本的一般信息,请参见第 18.6 节。
版本 12 包含许多可能影响与先前版本兼容性的变更。请注意以下不兼容性:
发布历史
每次发布的原始变更均独立保留。CVE 数量表示发布说明中的提及,可能包含后续纠正,不等于本次新修复漏洞数。
| 版本 | 日期/快照截止时间 | 全部变化 | BUG 修复 | 迁移条目 | 提及 CVE |
|---|---|---|---|---|---|
| 12.22 | 2024-11-21 | 1 | 0 | 0 | 1 |
| 12.21 | 2024-11-14 | 34 | 11 | 0 | 4 |
| 12.20 | 2024-08-08 | 34 | 16 | 0 | 2 |
| 12.19 | 2024-05-09 | 35 | 15 | 0 | 0 |
| 12.18 | 2024-02-08 | 39 | 14 | 0 | 1 |
| 12.17 | 2023-11-09 | 43 | 15 | 0 | 3 |
| 12.16 | 2023-08-10 | 32 | 14 | 0 | 1 |
| 12.15 | 2023-05-11 | 50 | 26 | 0 | 2 |
| 12.14 | 2023-02-09 | 36 | 15 | 0 | 1 |
| 12.13 | 2022-11-10 | 38 | 19 | 0 | 0 |
| 12.12 | 2022-08-11 | 39 | 15 | 0 | 2 |
| 12.11 | 2022-05-12 | 36 | 18 | 0 | 1 |
| 12.10 | 2022-02-10 | 33 | 16 | 0 | 0 |
| 12.9 | 2021-11-11 | 63 | 30 | 0 | 2 |
| 12.8 | 2021-08-12 | 68 | 23 | 0 | 3 |
| 12.7 | 2021-05-13 | 41 | 23 | 0 | 3 |
| 12.6 | 2021-02-11 | 67 | 33 | 0 | 1 |
| 12.5 | 2020-11-12 | 58 | 24 | 0 | 3 |
| 12.4 | 2020-08-13 | 52 | 27 | 0 | 3 |
| 12.3 | 2020-05-14 | 76 | 31 | 0 | 0 |
| 12.2 | 2020-02-13 | 75 | 44 | 0 | 2 |
| 12.1 | 2019-11-14 | 51 | 24 | 0 | 0 |
| 12.0 | 2019-10-03 | 180 | 4 | 23 | 0 |
首次发布变化
12.0 的原始条目,包含功能和兼容性变化。类别用于浏览,不是上游原始分类。
匹配 180 / 180 条原始变更。
将 recovery.conf 设置移入 postgresql.conf · 兼容性变化 · 迁移说明
将
recovery.conf设置移入postgresql.conf(Masao Fujii,Simon Riggs,Abhijit Menon-Sen,Sergei Kornilov)§不再使用
recovery.conf,如果该文件存在,服务器将无法启动。现在通过 recovery.signal 和standby.signal文件切换到非主库模式。trigger_file设置已重命名为promote_trigger_file。standby_mode设置已被移除。原始发布条目 ·
12.0/migration/004不再允许指定多个相互冲突的 recovery_target* 设置 · 兼容性变化 · 迁移说明
不再允许指定多个相互冲突的
recovery_target* 设置(Peter Eisentraut)§具体而言,recovery_target、recovery_target_lsn、recovery_target_name、recovery_target_time和recovery_target_xid中只允许指定一个。以前可以指定这些参数中的多个不同参数,并采用最后一个。现在只能指定其中一个,但同一个参数可以重复指定,并采用最后一次指定的值。
原始发布条目 ·
12.0/migration/005使恢复默认推进到最新时间线 · 兼容性变化 · 迁移说明
使恢复默认推进到最新时间线(Peter Eisentraut)§
具体而言,recovery_target_timeline现在默认为
latest,而以前默认为current。原始发布条目 ·
12.0/migration/006采用新算法输出 real 和 double precision 值,以提高性能 · 兼容性变化 · 迁移说明
采用新算法输出
real和double precision值,以提高性能(Andrew Gierth)§ §以前,显示的浮点值默认舍入到 6 位(
real)或 15 位(double precision),并根据extra_float_digits的值进行调整。现在,只要extra_float_digits大于零(这也是现在的默认值),就只输出保留精确二进制值所需的最少位数。当extra_float_digits设置为零或更小时,行为与以前相同。此外,浮点指数的格式现在在各平台上一致:除非必须使用三位数字,否则使用两位。在以前的版本中,Windows 构建始终输出三位数字。
原始发布条目 ·
12.0/migration/008更改 SQL 风格的 substring(),使其具有符合标准的贪婪匹配行为 · 兼容性变化 · 迁移说明
更改 SQL 风格的
substring(),使其具有符合标准的贪婪匹配行为(Tom Lane)§当模式可以以多种方式匹配时,起始子模式现在会匹配尽可能少的文本,而非尽可能多的文本。例如,
%#"aa*#"%这样的模式现在会从输入中选择第一组a,而非最后一组。原始发布条目 ·
12.0/migration/010将命令行工具 pg_verify_checksums 重命名为pg_checksums · 兼容性变化 · 迁移说明
将命令行工具 pg_verify_checksums 重命名为pg_checksums(Michaël Paquier)§
原始发布条目 ·
12.0/migration/012在pg_restore中,要求指定 -f - 才能将转储内容发送到标准输出 · 兼容性变化 · 迁移说明
在pg_restore中,要求指定
-f -才能将转储内容发送到标准输出(Euler Taveira)§以前,如果未指定目标位置,默认会这样做,但这种行为被认为不够友好。
原始发布条目 ·
12.0/migration/013如果没有提供参数列表且存在多个匹配对象,则使 DROP IF EXISTS FUNCTION/PROCEDURE/AGGREGATE/ROUTINE 报错 · 兼容性变化 · 迁移说明
如果没有提供参数列表且存在多个匹配对象,则使
DROP IF EXISTS FUNCTION/PROCEDURE/AGGREGATE/ROUTINE报错(David Rowley)§同时改进此类情况下的错误消息。
原始发布条目 ·
12.0/migration/016将 pg_statistic_ext 目录拆分为两个目录,并添加相应的 pg_stats_ext 视图 · 兼容性变化 · 迁移说明
将
pg_statistic_ext目录拆分为两个目录,并添加相应的pg_stats_ext视图(Dean Rasheed,Tomas Vondra)§ §此更改支持向无特权用户隐藏可能敏感的统计数据。
原始发布条目 ·
12.0/migration/017移除过时的 pg_constraint.consrc 列 · 兼容性变化 · 迁移说明
移除过时的
pg_constraint.consrc列(Peter Eisentraut)§此列早已弃用,因为它不会随其他目录变更(如列重命名)而更新。从
pg_constraint获取检查约束表达式文本形式的推荐方法是pg_get_expr(conbin, conrelid)。pg_get_constraintdef()也是一种有用的替代方法。原始发布条目 ·
12.0/migration/018移除过时的 pg_attrdef.adsrc 列 · 兼容性变化 · 迁移说明
移除过时的
pg_attrdef.adsrc列(Peter Eisentraut)§此列早已弃用,因为它不会随其他目录变更(如列重命名)而更新。从
pg_attrdef获取默认值表达式文本形式的推荐方法是pg_get_expr(adbin, adrelid)。原始发布条目 ·
12.0/migration/019将 name 类型的表列标记为默认使用 “C” 排序规则 · 兼容性变化 · 迁移说明
将 name 类型的表列标记为默认使用 “C” 排序规则(Tom Lane,Daniel Vérité)§ §
数据类型
name的比较操作符现在可以使用任何排序规则,而不再总是使用 “C” 排序规则。为保留查询以前的语义,现在将name类型的列显式标记为使用 “C” 排序规则。这一改动的副作用是,name列上的正则表达式操作符现在默认使用 “C” 排序规则,而非数据库的排序规则,来确定依赖区域设置的正则表达式模式(例如\w)的行为。如果希望name列上的正则表达式具有非 C 行为,请附加一个显式的COLLATE子句。(对于用户定义的name列,另一种方法是在建表时指定不同的排序规则;但这只是将向后不兼容性转移到了比较操作符上。)原始发布条目 ·
12.0/migration/020将 information_schema 视图中的对象名列视为 name 类型,而非 varchar 类型 · 兼容性变化 · 迁移说明
将
information_schema视图中的对象名列视为name类型,而非varchar类型(Tom Lane)§ § §按照 SQL 标准,
information_schema视图中的对象名列被声明为域类型sql_identifier。在 PostgreSQL 中,底层目录列实际为name类型。此更改使sql_identifier成为基于name的域,而非原来的varchar。这消除了比较和排序行为中的语义不一致,可显著提高对information_schema视图中的对象名列施加限制的查询性能。不过请注意,不等式限制,例如SELECT ... FROM information_schema.tables WHERE table_name < 'foo';
现在默认使用 “C” 区域设置的比较语义,而非像以前那样使用数据库的默认排序规则。对这些列进行排序也将遵循 “C” 排序规则。通过添加
COLLATE "default"子句,可以强制使用以前的行为(及其低效率)。原始发布条目 ·
12.0/migration/021移除禁用动态共享内存的功能 · 兼容性变化 · 迁移说明
移除禁用动态共享内存的功能(Kyotaro Horiguchi)§
具体而言,dynamic_shared_memory_type不再能够设置为
none。原始发布条目 ·
12.0/migration/022降低执行 ALTER TABLE ATTACH PARTITION 的锁定要求 · 新功能
降低执行
ALTER TABLE ATTACH PARTITION的锁定要求(Robert Haas)§原始发布条目 ·
12.0/changes/007添加分区自省函数 · 新功能
添加分区自省函数(Michaël Paquier,Álvaro Herrera,Amit Langote)§ § §
新函数
pg_partition_root()返回分区树的最顶层父表,pg_partition_ancestors()报告分区的所有祖先,pg_partition_tree()显示分区信息。原始发布条目 ·
12.0/changes/008允许多列 B-树索引占用更少空间 · 新功能
允许多列 B-树索引占用更少空间(Peter Geoghegan,Heikki Linnakangas)
内部页面和叶子页面的最小/最大值指示项现在只存储到发生差异的键为止的索引键,而非全部索引键。这也提高了索引访问的局部性。
通过 pg_upgrade 从以前版本升级而来的索引无法获得这些好处。
原始发布条目 ·
12.0/changes/014允许CREATE STATISTICS创建多列最常见值统计信息 · 新功能
允许CREATE STATISTICS创建多列最常见值统计信息(Tomas Vondra)§ §
这改进了对多个列进行测试、需要估算多个
WHERE子句综合效果的查询的优化。如果这些列彼此相关且分布不均匀,多列统计信息将使估算显著改善。原始发布条目 ·
12.0/changes/023允许控制何时为预备语句使用通用计划 · 新功能
允许控制何时为预备语句使用通用计划(Pavel Stehule)§
这由服务器参数plan_cache_mode控制。
原始发布条目 ·
12.0/changes/025允许 ALTER TABLE ... SET NOT NULL 避免不必要的表扫描 · 性能改进
允许
ALTER TABLE ... SET NOT NULL避免不必要的表扫描(Sergei Kornilov)§当可以识别出表的列约束不允许空值时,就能进行此项优化。
原始发布条目 ·
12.0/changes/038允许在 SERIALIZABLE 隔离模式下使用并行查询 · 性能改进
允许在
SERIALIZABLE隔离模式下使用并行查询(Thomas Munro)§以前,在此模式下会禁用并行执行。
原始发布条目 ·
12.0/changes/041允许仅记录一定比例事务中的语句 · 新功能
允许仅记录一定比例事务中的语句(Adrien Nayrat)§
这由参数log_transaction_sample_rate控制。
原始发布条目 ·
12.0/changes/044为 CREATE INDEX 和 REINDEX 操作添加进度报告 · 新功能
为
CREATE INDEX和REINDEX操作添加进度报告(Álvaro Herrera,Peter Eisentraut)§ §进度通过
pg_stat_progress_create_index系统视图报告。原始发布条目 ·
12.0/changes/045为 CLUSTER 和 VACUUM FULL 添加进度报告 · 新功能
为
CLUSTER和VACUUM FULL添加进度报告(Tatsuro Yamada)§进度通过
pg_stat_progress_cluster系统视图报告。原始发布条目 ·
12.0/changes/046为pg_checksums添加进度报告 · 新功能
为pg_checksums添加进度报告(Michael Banck,Bernd Helmle)§
可通过
--progress选项启用此功能。原始发布条目 ·
12.0/changes/047在系统视图 pg_stat_database 中添加对全局对象的跟踪 · 新功能
在系统视图
pg_stat_database中添加对全局对象的跟踪(Julien Rouhaud)§全局对象对应的
pg_stat_database.datid值显示为零。原始发布条目 ·
12.0/changes/049添加列出归档目录内容的功能 · 新功能
添加列出归档目录内容的功能(Christoph Moench-Tegeder)§
相应函数为
pg_ls_archive_statusdir()。原始发布条目 ·
12.0/changes/050添加列出临时目录内容的功能 · 新功能
添加列出临时目录内容的功能(Nathan Bossart)§
相应函数
pg_ls_tmpdir()允许选择性地指定表空间。原始发布条目 ·
12.0/changes/051在系统视图 pg_stat_ssl 中添加客户端证书信息 · 新功能
在系统视图
pg_stat_ssl中添加客户端证书信息(Peter Eisentraut)§新增列为
client_serial和issuer_dn。为使含义更清楚,将clientdn列重命名为client_dn。原始发布条目 ·
12.0/changes/052如果设置了application_name,则在log_connections日志消息中包含它 · 新功能
如果设置了application_name,则在log_connections日志消息中包含它(Don Seiler)§
原始发布条目 ·
12.0/changes/056在 pg_stat_replication 中添加最后收到的备库消息的时间戳 · 新功能
在
pg_stat_replication中添加最后收到的备库消息的时间戳(Lim Myungkyu)§原始发布条目 ·
12.0/changes/058添加 GSSAPI 加密支持 · 新功能
添加 GSSAPI 加密支持(Robbie Harwood,Stephen Frost)§
此特性允许在使用 GSSAPI 认证时加密 TCP/IP 连接,无需另外配置 SSL 等加密设施。为支持此功能,在
pg_hba.conf中增加了hostgssenc和hostnogssenc记录类型,用于选择使用或不使用 GSSAPI 加密的连接,分别对应现有的hostssl和hostnossl记录类型。另外,还增加了 libpq 选项gssencmode和系统视图pg_stat_gssapi。原始发布条目 ·
12.0/changes/060允许 pg_hba.conf 的 clientcert 选项检查数据库用户名是否与客户端证书的通用名匹配 · 新功能
允许
pg_hba.conf的clientcert选项检查数据库用户名是否与客户端证书的通用名匹配(Julian Markwort,Marius Timmer)§此项新检查通过
clientcert=verify-full启用。原始发布条目 ·
12.0/changes/061添加使用pg_checksums启用/禁用集群校验和的功能 · 新功能
添加使用pg_checksums启用/禁用集群校验和的功能(Michael Banck,Michaël Paquier)§
执行这些操作时必须关闭集群。
原始发布条目 ·
12.0/changes/063将autovacuum_vacuum_cost_delay的默认值降低到 2ms · 新功能
将autovacuum_vacuum_cost_delay的默认值降低到 2ms(Tom Lane)§
这使自动清理操作默认能够更快地执行。
原始发布条目 ·
12.0/changes/064允许vacuum_cost_delay接受小数值,以指定亚毫秒级延迟 · 新功能
允许vacuum_cost_delay接受小数值,以指定亚毫秒级延迟(Tom Lane)§
原始发布条目 ·
12.0/changes/065添加服务器参数wal_recycle和wal_init_zero,以控制 WAL 文件的循环利用 · 新功能
添加服务器参数wal_recycle和wal_init_zero,以控制 WAL 文件的循环利用(Jerry Jelinek)§
在 ZFS 等写时复制文件系统上,避免文件循环利用可能有益。
原始发布条目 ·
12.0/changes/069添加服务器参数tcp_user_timeout,以控制服务器的 TCP 超时 · 新功能
添加服务器参数tcp_user_timeout,以控制服务器的 TCP 超时(Ryohei Nagaura)§
原始发布条目 ·
12.0/changes/070添加服务器参数ssl_library,以报告服务器使用的 SSL 库版本 · 新功能
添加服务器参数ssl_library,以报告服务器使用的 SSL 库版本(Peter Eisentraut)§
原始发布条目 ·
12.0/changes/072添加服务器参数shared_memory_type,以控制所使用的共享内存类型 · 新功能
添加服务器参数shared_memory_type,以控制所使用的共享内存类型(Andres Freund)§
这允许在需要时选择 System V 共享内存。
原始发布条目 ·
12.0/changes/073允许通过重新加载配置更改部分恢复参数 · 新功能
允许通过重新加载配置更改部分恢复参数(Peter Eisentraut)§
这些参数是archive_cleanup_command、promote_trigger_file、recovery_end_command和recovery_min_apply_delay。
原始发布条目 ·
12.0/changes/074允许按连接设置流复制超时(wal_sender_timeout) · 新功能
允许按连接设置流复制超时(wal_sender_timeout)(Takayuki Tsunakawa)§
以前,只能在整个集群范围内设置此参数。
原始发布条目 ·
12.0/changes/075添加函数 pg_promote(),用于将备库提升为主库 · 新功能
添加函数
pg_promote(),用于将备库提升为主库(Laurenz Albe,Michaël Paquier)§ §以前,只能使用pg_ctl或创建触发文件来执行此操作。
原始发布条目 ·
12.0/changes/076允许复制复制槽 · 新功能
允许复制复制槽(Masahiko Sawada)§
相应函数为
pg_copy_physical_replication_slot()和pg_copy_logical_replication_slot()。原始发布条目 ·
12.0/changes/077不再将max_wal_senders计入max_connections · 新功能
不再将max_wal_senders计入max_connections(Alexander Kukushkin)§
原始发布条目 ·
12.0/changes/078为recovery_target_timeline添加显式值 current · 新功能
为recovery_target_timeline添加显式值
current(Peter Eisentraut)§原始发布条目 ·
12.0/changes/079允许更灵活地添加枚举值 · 新功能
允许更灵活地添加枚举值(Andrew Dunstan,Tom Lane,Thomas Munro)§
以前,不能在事务块中调用
ALTER TYPE ... ADD VALUE,除非它与创建该枚举类型的操作处于同一事务。现在可以在后续事务中调用,只要在提交之后才引用新的枚举值即可。原始发布条目 ·
12.0/changes/084添加结束当前事务并开始新事务的命令 · 新功能
添加结束当前事务并开始新事务的命令(Peter Eisentraut)§
这些命令为
COMMIT AND CHAIN和ROLLBACK AND CHAIN。原始发布条目 ·
12.0/changes/085为EXPLAIN添加 SETTINGS 选项,以输出非默认的优化器设置 · 新功能
为EXPLAIN添加
SETTINGS选项,以输出非默认的优化器设置(Tomas Vondra)§使用auto_explain时,也可通过设置
auto_explain.log_settings获取这些输出。原始发布条目 ·
12.0/changes/091为CREATE AGGREGATE添加 OR REPLACE 选项 · 新功能
为CREATE AGGREGATE添加
OR REPLACE选项(Andrew Gierth)§原始发布条目 ·
12.0/changes/092允许使用ALTER TABLE修改系统目录的选项 · 新功能
允许使用ALTER TABLE修改系统目录的选项(Peter Eisentraut)§
现在支持修改目录的
reloptions和自动清理设置。(仍然需要设置allow_system_table_mods。)原始发布条目 ·
12.0/changes/093采用更精确的算法,提高 variance() 等统计聚合的精度 · 新功能
采用更精确的算法,提高
variance()等统计聚合的精度(Dean Rasheed)§原始发布条目 ·
12.0/changes/102允许 date_trunc() 接受额外参数来控制时区 · 新功能
允许
date_trunc()接受额外参数来控制时区(Vik Fearing,Tom Lane)§这比使用
AT TIME ZONE子句更快、更简单。原始发布条目 ·
12.0/changes/103调整 to_timestamp()/to_date() 函数,使其对模板不匹配更加宽容 · 新功能
调整
to_timestamp()/to_date()函数,使其对模板不匹配更加宽容(Artur Zakirov,Alexander Korotkov,Liudmila Mantrova)§这种新行为更接近 Oracle 的同名函数。
原始发布条目 ·
12.0/changes/104防止并行工作进程运行 current_schema() 和 current_schemas(),因为它们并非并行安全 · 新功能
防止并行工作进程运行
current_schema()和current_schemas(),因为它们并非并行安全(Michaël Paquier)§原始发布条目 ·
12.0/changes/107添加连接参数tcp_user_timeout,以控制 libpq 的 TCP 超时 · 新功能
添加连接参数tcp_user_timeout,以控制 libpq 的 TCP 超时(Ryohei Nagaura)§
原始发布条目 ·
12.0/changes/111添加 libpq 函数 PQresultMemorySize(),以报告查询结果使用的内存 · 新功能
添加 libpq 函数
PQresultMemorySize(),以报告查询结果使用的内存(Lars Kanis,Tom Lane)§原始发布条目 ·
12.0/changes/113改进 CREATE TABLE、CREATE TRIGGER、CREATE EVENT TRIGGER、ANALYZE、EXPLAIN、VACUUM、ALTER TABLE、ALTER INDEX、ALTER DATABASE 和 ALTER INDEX ALTER COLUMN 的 Tab 补全 · 新功能
改进
CREATE TABLE、CREATE TRIGGER、CREATE EVENT TRIGGER、ANALYZE、EXPLAIN、VACUUM、ALTER TABLE、ALTER INDEX、ALTER DATABASE和ALTER INDEX ALTER COLUMN的 Tab 补全(Dagfinn Ilmari Mannsåker,Tatsuro Yamada,Michaël Paquier,Tom Lane,Justin Pryzby)§ § § § § § § § §原始发布条目 ·
12.0/changes/123如果文件系统具有克隆功能,则允许pg_upgrade使用它 · 新功能
如果文件系统具有克隆功能,则允许pg_upgrade使用它(Peter Eisentraut)§
--clone选项具有--link的优点,同时可以防止新集群启动后旧集群被改动。原始发布条目 ·
12.0/changes/129允许pg_checksums禁用 fsync 操作 · 新功能
允许pg_checksums禁用 fsync 操作(Michaël Paquier)§
这通过
--no-sync选项控制。原始发布条目 ·
12.0/changes/131修复pg_test_fsync,使其在 Windows 上报告准确的 open_datasync 耗时 · BUG 修复
修复pg_test_fsync,使其在 Windows 上报告准确的
open_datasync耗时(Laurenz Albe)§ §原始发布条目 ·
12.0/changes/133允许为 pg_dump 和 pg_dumpall 指定extra_float_digits设置 · 新功能
允许为 pg_dump 和 pg_dumpall 指定extra_float_digits设置(Andrew Dunstan)§
这主要用于生成能够在不同源服务器版本之间精确比较的转储。不建议在常规使用中这样做,因为恢复转储时可能丢失精度。
原始发布条目 ·
12.0/changes/137简化手动分配的 OID 的重新编号,并为此类 OID 的管理制定新的项目政策 · 新功能
简化手动分配的 OID 的重新编号,并为此类 OID 的管理制定新的项目政策(John Naylor,Tom Lane)§ §
为新的内置对象(如新函数)手动分配 OID 的补丁,现在应在 8000—9999 范围内随机选择 OID。在开发周期结束时,已提交补丁使用的 OID 将通过新的
renumber_oids.pl脚本重新编号为较小的数字,目前大约位于 4xxx范围内。这种做法应能大幅降低不同开发中补丁之间发生 OID 冲突的概率。虽然没有专门为外部使用预留 OID 的政策,但建议分支项目及其他需要私有手动分配 OID 的项目,使用 7
xxx范围高端的编号。这将避免与最近合入的补丁冲突,而且核心项目应该要很久才会用到该范围。原始发布条目 ·
12.0/changes/141允许在更多情况下将 ORDER BY 排序和 LIMIT 子句下推到postgres_fdw外部服务器 · 新功能
允许在更多情况下将
ORDER BY排序和LIMIT子句下推到postgres_fdw外部服务器(Etsuro Fujita)§ §原始发布条目 ·
12.0/changes/148允许 pg_stat_statements_reset() 提供更细的控制粒度 · 新功能
允许
pg_stat_statements_reset()提供更细的控制粒度(Haribabu Kommi,Amit Kapila)§此函数现在允许重置特定数据库、用户和查询的统计信息。
原始发布条目 ·
12.0/changes/151允许控制auto_explain的日志级别 · 新功能
允许控制auto_explain的日志级别(Tom Dunstan,Andrew Dunstan)§
默认值为
LOG。原始发布条目 ·
12.0/changes/152
安全证据
共 34 条记录,来自官方安全矩阵及发布说明的提及。只有安全快照明确列出此分支时才显示修复版本;仅有提及不能确定漏洞适用性或新修复。
CVE-2024-7348 · PostgreSQL relation replacement during pg_dump executes arbitrary SQL · CVSS 8.8
Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected. The PostgreSQL project thanks Noah Misch for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.20。组件:core server。
官方受影响分支记录:12。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2024-10979 · PostgreSQL PL/Perl environment variable changes execute arbitrary code · CVSS 8.8
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH ). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Coby Abrams for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.21。组件:core server。
官方受影响分支记录:12。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2024-10978 · PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID · CVSS 4.2
Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE , SET SESSION AUTHORIZATION , or an equivalent feature. The problem arises when an application query uses parameters from the attacker or conveys query results to the attacker. If that query reacts to current_setting('role') or the current user ID, it may modify or return data as though the session had not used SET ROLE or SET SESSION AUTHORIZATION . The attacker does not control which incorrect user ID applies. Query text from less-privileged sources is not a concern here, because SET ROLE and SET SESSION AUTHORIZATION are not sandboxes for unvetted queries. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Tom Lane for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.21。组件:core server。
官方受影响分支记录:12。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2024-10977 · PostgreSQL libpq retains an error message from man-in-the-middle · CVSS 3.1
Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper user of psql mistakes for valid query results. This is probably not a concern for clients where the user interface unambiguously indicates the boundary between one error message and other text. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Jacob Champion for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.21。组件:client。
官方受影响分支记录:12。
AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
发布说明中的提及:
CVE-2024-10976 · PostgreSQL row security below e.g. subqueries disregards user ID changes · CVSS 4.2
Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.
以上保留官方英文漏洞说明。
本分支修复于:12.21。组件:core server。
官方受影响分支记录:12。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2024-0985 · PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL · CVSS 8.0
UPDATE (June 19, 2024) : Added v16 as impacted. Updated description to clarify the attack vector. Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view.
以上保留官方英文漏洞说明。
本分支修复于:12.18。组件:core server。
官方受影响分支记录:12。
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2023-5870 · Role "pg_signal_backend" can signal certain superuser processes · CVSS 2.2
Documentation says the pg_signal_backend role cannot signal "a backend owned by a superuser". On the contrary, it can signal background workers, including the logical replication launcher. It can signal autovacuum workers and the autovacuum launcher. Signaling autovacuum workers and those two launchers provides no meaningful exploit, so exploiting this vulnerability requires a non-core extension with a less-resilient background worker. For example, a non-core background worker that does not auto-restart would experience a denial of service with respect to that particular background worker. The PostgreSQL project thanks Hemanth Sandrana and Mahendrakar Srinivasarao for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.17。组件:core server。
官方受影响分支记录:12。
AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
发布说明中的提及:
CVE-2023-5869 · Buffer overrun from integer overflow in array modification · CVSS 8.8
While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others. The PostgreSQL project thanks Pedro Gallegos for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.17。组件:core server。
官方受影响分支记录:12。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2023-5868 · Memory disclosure in aggregate function calls · CVSS 4.3
Certain aggregate function calls receiving "unknown"-type arguments could disclose bytes of server memory from the end of the "unknown"-type value to the next zero byte. One typically gets an "unknown"-type value via a string literal having no type designation. We have not confirmed or ruled out viability of attacks that arrange for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jingzhou Fu for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.17。组件:core server。
官方受影响分支记录:12。
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2023-39417 · Extension script @substitutions@ within quoting allow SQL injection · CVSS 7.5
An extension script is vulnerable if it uses @extowner@ , @extschema@ , or @extschema:...@ inside a quoting construct (dollar quoting, '' , or "" ). No bundled extension is vulnerable. Vulnerable uses do appear in a documentation example and in non-bundled extensions. Hence, the attack prerequisite is an administrator having installed files of a vulnerable, trusted, non-bundled extension. Subject to that prerequisite, this enables an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. PostgreSQL will block this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Micah Gates, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.16。组件:core server。
官方受影响分支记录:12。
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2023-2455 · Row security policies disregard user ID changes after inlining · CVSS 4.2
While CVE-2016-2193 fixed most interaction between row security and user ID changes, it missed a scenario involving function inlining. This leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLE s. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. The PostgreSQL project thanks Wolfgang Walther for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.15。组件:core server。
官方受影响分支记录:12。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2023-2454 · CREATE SCHEMA ... schema_element defeats protective search_path changes · CVSS 7.2
This enabled an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. Database owners have that right by default, and explicit grants may extend it to other users. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.15。组件:core server。
官方受影响分支记录:12。
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2022-41862 · Client memory disclosure when connecting, with Kerberos, to modified server · CVSS 3.7
A modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. When a libpq client application has a Kerberos credential cache and doesn't explicitly disable option gssencmode , a server can cause libpq to over-read and report an error message containing uninitialized bytes from and following its receive buffer. If libpq's caller somehow makes that message accessible to the attacker, this achieves a disclosure of the over-read bytes. We have not confirmed or ruled out viability of attacks that arrange for a crash or for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jacob Champion for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.14。组件:client。
官方受影响分支记录:12。
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2022-2625 · Extension scripts replace objects not belonging to the extension · CVSS 7.1
Some extensions use CREATE OR REPLACE or CREATE IF NOT EXISTS commands. Some don't adhere to the documented rule to target only objects known to be extension members already. An attack requires permission to create non-temporary objects in at least one schema, ability to lure or wait for an administrator to create or update an affected extension in that schema, and ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS . Given all three prerequisites, the attacker can run arbitrary code as the victim role, which may be a superuser. Known-affected extensions include both PostgreSQL-bundled and non-bundled extensions. PostgreSQL is blocking this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Sven Klemm for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.12。组件:core server。
官方受影响分支记录:12。
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2022-1552 · Autovacuum, REINDEX, and others omit "security restricted operation" sandbox · CVSS 8.8
Autovacuum, REINDEX , CREATE INDEX , REFRESH MATERIALIZED VIEW , CLUSTER , and pg_amcheck made incomplete efforts to operate safely when a privileged user is maintaining another user's objects. Those commands activated relevant protections too late or not at all. An attacker having permission to create non-temp objects in at least one schema could execute arbitrary SQL functions under a superuser identity. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum, not manually running the above commands, and not restoring from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.11。组件:core server。
官方受影响分支记录:12。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2021-3677 · Memory disclosure in certain queries · CVSS 6.5
A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0 , the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.
以上保留官方英文漏洞说明。
本分支修复于:12.8。组件:core server。
官方受影响分支记录:12。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
发布说明中的提及:
CVE-2021-3449 · CVE-2021-3449
CVE-2021-3393 · Partition constraint violation errors leak values of denied columns · CVSS 3.1
A user having an UPDATE privilege on a partitioned table but lacking the SELECT privilege on some column may be able to acquire denied-column values from an error message. This is similar to CVE-2014-8161 , but the conditions to exploit are more rare. The PostgreSQL project thanks Heikki Linnakangas for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.6。组件:core server。
官方受影响分支记录:12。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2021-32029 · Memory disclosure in partitioned-table UPDATE ... RETURNING · CVSS 6.5
Using an UPDATE ... RETURNING on a purpose-crafted partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas typically cannot use this attack at will. The PostgreSQL project thanks Tom Lane for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.7。组件:core server。
官方受影响分支记录:12。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
发布说明中的提及:
CVE-2021-32028 · Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE · CVSS 6.5
Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas cannot use this attack at will. The PostgreSQL project thanks Andres Freund for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.7。组件:core server。
官方受影响分支记录:12。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
发布说明中的提及:
CVE-2021-32027 · Buffer overrun from integer overflow in array subscripting calculations · CVSS 6.5
While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The PostgreSQL project thanks Tom Lane for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.7。组件:core server。
官方受影响分支记录:12。
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
发布说明中的提及:
CVE-2021-23222 · libpq processes unencrypted bytes from man-in-the-middle · CVSS 3.7
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property is a PostgreSQL configuration vulnerable to CVE-2021-23214 . As with any exploitation of CVE-2021-23214 , the server must be using trust authentication with a clientcert requirement or using cert authentication. To disclose a password, the client must be in possession of a password, which is atypical when using an authentication configuration vulnerable to CVE-2021-23214 . The attacker must have some other way to access the server to retrieve the exfiltrated data (a valid, unprivileged login account would be sufficient). The PostgreSQL project thanks Jacob Champion for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.9。组件:client。
官方受影响分支记录:12。
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2021-23214 · Server processes unencrypted bytes from man-in-the-middle · CVSS 8.1
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product). The PostgreSQL project thanks Jacob Champion for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.9。组件:core server。
官方受影响分支记录:12。
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2020-25696 · psql's \gset allows overwriting specially treated variables · CVSS 7.5
The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.5。组件:client。
官方受影响分支记录:12。
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2020-25695 · Multiple features escape "security restricted operation" sandbox · CVSS 8.8
An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.5。组件:core server。
官方受影响分支记录:12。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2020-25694 · Reconnection can downgrade connection security settings · CVSS 8.1
Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.5。组件:client。
官方受影响分支记录:12。
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2020-1720 · ALTER ... DEPENDS ON EXTENSION is missing authorization checks. · CVSS 3.1
The ALTER ... DEPENDS ON EXTENSION sub-commands do not perform authorization checks, which can allow an unprivileged user to drop any function, procedure, materialized view, index, or trigger under certain conditions. This attack is possible if an administrator has installed an extension and an unprivileged user can CREATE , or an extension owner either executes DROP EXTENSION predictably or can be convinced to execute DROP EXTENSION . The PostgreSQL project thanks Tom Lane for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.2。组件:core server。
官方受影响分支记录:12。
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
发布说明中的提及:
CVE-2020-14350 · Uncontrolled search path element in CREATE EXTENSION · CVSS 7.1
When a superuser runs certain CREATE EXTENSION statements, users may be able to execute arbitrary SQL functions under the identity of that superuser. The attacker must have permission to create objects in the new extension's schema or a schema of a prerequisite extension. Not all extensions are vulnerable. In addition to correcting the extensions provided with PostgreSQL, the PostgreSQL Global Development Group is issuing guidance for third-party extension authors to secure their own work. The PostgreSQL project thanks Andres Freund for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.4。组件:core server。
官方受影响分支记录:12。
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2020-14349 · Uncontrolled search path element in logical replication · CVSS 7.5
The PostgreSQL search_path setting determines schemas searched for tables, functions, operators, etc. The CVE-2018-1058 fix caused most PostgreSQL-provided client applications to sanitize search_path , but logical replication continued to leave search_path unchanged. Users of a replication publisher or subscriber database can create objects in the public schema and harness them to execute arbitrary SQL functions under the identity running replication, often a superuser. Installations having adopted a documented secure schema usage pattern are not vulnerable. The PostgreSQL project thanks Noah Misch for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.4。组件:core server。
官方受影响分支记录:12。
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2020-10733 · Windows installer runs executables from uncontrolled directories · CVSS 6.7
The Windows installer for PostgreSQL invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. The PostgreSQL project thanks Hou JingYi (@hjy79425575) for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:12.3。组件:packaging。
官方受影响分支记录:12。
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVE-2019-3466 · pg_ctlcluster script in postgresql-common does not drop privileges when creating socket/statistics temporary directories · CVSS 8.4
A PostgreSQL superuser could escalate to root using a deficiency in the pg_ctlcluster command. pg_ctlcluster is a utility provided by the "postgresql-common" package that is installed with PostgreSQL on Debian and Ubuntu platforms.
以上保留官方英文漏洞说明。
本分支修复于:12.1。组件:packaging。
官方受影响分支记录:12。
AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CVE-2018-1058 · Uncontrolled search path element in pg_dump and other client applications · CVSS 8.8
尚未记录本分支的修复版本。组件:client。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks · CVSS 4.3
尚未记录本分支的修复版本。组件:core server。
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及: