↑↓ 选择 ↵ 打开 ⌫ 改范围 完整检索页

pgsql.cc 提供对 postgresql.org 官网内容的中文翻译,由 Pigsty 团队维护。

百科 / 版本发布

PostgreSQL 9.0

已停止支持 · 记录构建 9.0.23 · 2015-10-08

此大版本已停止支持,相关记录用于查阅历史;没有更新的安全记录不代表仍可安全运行。

首次正式发布
2010-09-20
支持结束
2015-10-08
已收录发布版本
24
原始发布说明条目
850

手册与来源

PostgreSQL 9.0 本站手册 · 已加载 1024 页。

手册加载时间:2026-09-27T00:10:45.258078。

发布说明快照:2026-09-26。安全证据快照:2026-09-26。PDF 链接按本地文件是否存在提供,历史版本的语言与 HTML 手册可能不同。生命周期参见官方版本政策。

升级注意事项

跨大版本升级需要导出/恢复或 pg_upgrade 等迁移方式,应阅读沿途大版本的发布说明与目标版本手册。小版本更新也可能要求额外操作,请核对对应发布的迁移说明。官方升级政策。

9.0.0 的兼容性变化 · 从首发到 9.0.23 的变化

9.0.0 的原始迁移说明

对于希望从任何早期版本迁移数据的用户,需要使用 pg_dump 进行转储/恢复,或者使用 pg_upgrade。

版本 9.0 包含一些为支持新特性和代码质量改进而有选择地破坏向后兼容性的变更。特别是,大量使用 PL/pgSQL、时间点恢复(PITR)或温备的用户应测试其应用,因为这些领域有轻微的用户可见变化。请注意以下不兼容之处:

发布历史

每次发布的原始变更均独立保留。CVE 数量表示发布说明中的提及,可能包含后续纠正,不等于本次新修复漏洞数。

版本日期/快照截止时间全部变化BUG 修复迁移条目提及 CVE
9.0.23 2015-10-08 472501
9.0.22 2015-06-12 2200
9.0.21 2015-06-04 3100
9.0.20 2015-05-22 351303
9.0.19 2015-02-05 522206
9.0.18 2014-07-24 281401
9.0.17 2014-03-20 10100
9.0.16 2014-02-20 371608
9.0.15 2013-12-05 161000
9.0.14 2013-10-10 261300
9.0.13 2013-04-04 211502
9.0.12 2013-02-07 23901
9.0.11 2012-12-06 322000
9.0.10 2012-09-24 10500
9.0.9 2012-08-17 231102
9.0.8 2012-06-04 271902
9.0.7 2012-02-27 351803
9.0.6 2011-12-05 291300
9.0.5 2011-09-26 643901
9.0.4 2011-04-18 291800
9.0.3 2011-01-31 12701
9.0.2 2010-12-16 422600
9.0.1 2010-10-04 10501
9.0.0 2010-09-20 2375200

首次发布变化

9.0.0 的原始条目,包含功能和兼容性变化。类别用于浏览,不是上游原始分类。

匹配 237 / 237 条原始变更。

安全证据

共 30 条记录,来自官方安全矩阵及发布说明的提及。只有安全快照明确列出此分支时才显示修复版本;仅有提及不能确定漏洞适用性或新修复。

CVE-2015-5288 · Memory leak in crypt() function. · CVSS 3.1

本分支修复于:9.0.23。组件:contrib module。

官方受影响分支记录:9.0。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2015-3167 · pgcrypto has multiple error messages for decryption with an incorrect key. · CVSS 3.7

本分支修复于:9.0.20。组件:contrib module。

官方受影响分支记录:9.0。

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2015-3166 · Unanticipated errors from the standard library. · CVSS 5.6

本分支修复于:9.0.20。组件:core server。

官方受影响分支记录:9.0。

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

发布说明中的提及:

CVE-2015-3165 · Double "free" after authentication timeout · CVSS 7.5

本分支修复于:9.0.20。组件:core server。

官方受影响分支记录:9.0。

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

发布说明中的提及:

CVE-2015-0244 · An error in extended protocol message reading. · CVSS 8.1

本分支修复于:9.0.19。组件:core server。

官方受影响分支记录:9.0。

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2015-0243 · Memory errors in functions in the pgcrypto extension. · CVSS 6.5

本分支修复于:9.0.19。组件:contrib module。

官方受影响分支记录:9.0。

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

发布说明中的提及:

CVE-2015-0242 · Buffer overrun in replacement printf family of functions. · CVSS 4.2

本分支修复于:9.0.19。组件:core server。

官方受影响分支记录:9.0。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

发布说明中的提及:

CVE-2015-0241 · Buffer overruns in "to_char" functions. · CVSS 4.2

本分支修复于:9.0.19。组件:core server。

官方受影响分支记录:9.0。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

发布说明中的提及:

CVE-2014-8161 · Constraint violation errors can cause display of values in columns which the user would not normally have rights to see. · CVSS 3.1

本分支修复于:9.0.19。组件:core server。

官方受影响分支记录:9.0。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2014-0067 · Unauthenticated users may gain access to the database server during "make check".. · CVSS 7.0

本分支修复于:9.0.19。组件:other。

官方受影响分支记录:9.0。

AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2014-0066 · Potential null pointer dereference crash when crypt(3) returns NULL. · CVSS 0.0

本分支修复于:9.0.16。组件:contrib module。

官方受影响分支记录:9.0。

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N

发布说明中的提及:

CVE-2014-0065 · Potential buffer overruns of fixed-size buffers. · CVSS 0.0

本分支修复于:9.0.16。组件:core server。

官方受影响分支记录:9.0。

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N

发布说明中的提及:

CVE-2014-0064 · Potential buffer overruns due to integer overflow in size calculations. · CVSS 6.5

本分支修复于:9.0.16。组件:core server。

官方受影响分支记录:9.0。

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

发布说明中的提及:

CVE-2014-0063 · Potential buffer overruns in datetime input/output. · CVSS 4.3

本分支修复于:9.0.16。组件:core server。

官方受影响分支记录:9.0。

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

发布说明中的提及:

CVE-2014-0062 · Race condition in CREATE INDEX allows for privilege escalation. · CVSS 8.8

本分支修复于:9.0.16。组件:core server。

官方受影响分支记录:9.0。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2014-0061 · Privilege escalation via calls to validator functions. · CVSS 7.5

本分支修复于:9.0.16。组件:core server。

官方受影响分支记录:9.0。

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2014-0060 · SET ROLE bypasses lack of ADMIN OPTION. · CVSS 3.1

本分支修复于:9.0.16。组件:core server。

官方受影响分支记录:9.0。

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

发布说明中的提及:

CVE-2013-1900 · Random numbers generated by contrib/pgcrypto functions may be easy for another database user to guess

本分支修复于:9.0.13。

官方受影响分支记录:9.0。

发布说明中的提及:

CVE-2013-1899 · A connection request containing a database name that begins with "-" may be crafted to damage or destroy files within a server's data directory

本分支修复于:9.0.13。

官方受影响分支记录:9.0。

发布说明中的提及:

CVE-2013-0255 · executing enum_recv() with wrong parameters crashes server

本分支修复于:9.0.12。

官方受影响分支记录:9.0。

发布说明中的提及:

CVE-2012-3489 · xml_parse() DTD validation can be used to read arbitrary files
CVE-2012-3488 · contrib/xml2's xslt_process() can be used to read and write arbitrary files

本分支修复于:9.0.9。

官方受影响分支记录:9.0。

发布说明中的提及:

CVE-2012-2655 · SECURITY DEFINER and SET attributes on procedural call handlers are not ignored and can be used to crash the server

本分支修复于:9.0.8。

官方受影响分支记录:9.0。

发布说明中的提及:

CVE-2012-2143 · Passwords containing the byte 0x80 passed to the crypt() function in pgcrypto are incorrectly truncated if DES encryption was used

本分支修复于:9.0.8。

官方受影响分支记录:9.0。

发布说明中的提及:

CVE-2012-0868 · Line breaks in object names can be exploited to execute arbitrary SQL when reloading a pg_dump file.

本分支修复于:9.0.7。

官方受影响分支记录:9.0。

发布说明中的提及:

CVE-2012-0867 · SSL certificate name checks are truncated to 32 characters, allowing connection spoofing under some circumstances when using third party certificate authorities.

本分支修复于:9.0.7。

官方受影响分支记录:9.0。

发布说明中的提及:

CVE-2012-0866 · Permissions on a function called by a trigger are not properly checked.

本分支修复于:9.0.7。

官方受影响分支记录:9.0。

发布说明中的提及:

CVE-2011-2483 · CVE-2011-2483

尚未记录本分支的修复版本。

发布说明中的提及:

CVE-2010-4015 · An authenticated database user can cause a buffer overrun by calling functions from the intarray optional module with certain parameters.

本分支修复于:9.0.3。

官方受影响分支记录:9.0。

发布说明中的提及:

CVE-2010-3433 · An authenticated database user can manipulate modules and tied variables in some external procedural languages to execute code with enhanced privileges.Details

本分支修复于:9.0.1。

官方受影响分支记录:9.0。

发布说明中的提及:

导出此分支 JSON · 比较已收录的发布版本