↑↓ 选择 ↵ 打开 ⌫ 改范围 完整检索页

pgsql.cc 提供对 postgresql.org 官网内容的中文翻译,由 Pigsty 团队维护。

百科 / 版本发布

PostgreSQL 9.1

已停止支持 · 记录构建 9.1.24 · 2016-10-27

此大版本已停止支持,相关记录用于查阅历史;没有更新的安全记录不代表仍可安全运行。

首次正式发布
2011-09-12
支持结束
2016-10-27
已收录发布版本
25
原始发布说明条目
895

手册与来源

PostgreSQL 9.1 本站手册 · 已加载 1102 页。

手册加载时间:2026-09-27T00:10:45.258078。

发布说明快照:2026-09-26。安全证据快照:2026-09-26。PDF 链接按本地文件是否存在提供,历史版本的语言与 HTML 手册可能不同。生命周期参见官方版本政策。

升级注意事项

跨大版本升级需要导出/恢复或 pg_upgrade 等迁移方式,应阅读沿途大版本的发布说明与目标版本手册。小版本更新也可能要求额外操作,请核对对应发布的迁移说明。官方升级政策。

9.1.0 的兼容性变化 · 从首发到 9.1.24 的变化

9.1.0 的原始迁移说明

对于希望从任何早期版本迁移数据的用户,需要使用 pg_dump 进行转储/恢复,或者使用 pg_upgrade。

版本 9.1 包含许多可能影响与以前版本兼容性的变更。请注意以下不兼容之处:

发布历史

每次发布的原始变更均独立保留。CVE 数量表示发布说明中的提及,可能包含后续纠正,不等于本次新修复漏洞数。

版本日期/快照截止时间全部变化BUG 修复迁移条目提及 CVE
9.1.24 2016-10-27 13700
9.1.23 2016-08-11 22802
9.1.22 2016-05-12 11500
9.1.21 2016-03-31 17900
9.1.20 2016-02-11 451704
9.1.19 2015-10-08 543001
9.1.18 2015-06-12 2200
9.1.17 2015-06-04 3100
9.1.16 2015-05-22 411503
9.1.15 2015-02-05 602606
9.1.14 2014-07-24 321701
9.1.13 2014-03-20 12300
9.1.12 2014-02-20 432008
9.1.11 2013-12-05 181100
9.1.10 2013-10-10 341700
9.1.9 2013-04-04 251603
9.1.8 2013-02-07 301401
9.1.7 2012-12-06 402500
9.1.6 2012-09-24 17800
9.1.5 2012-08-17 301602
9.1.4 2012-06-04 423002
9.1.3 2012-02-27 462403
9.1.2 2011-12-05 522200
9.1.1 2011-09-26 3200
9.1.0 2011-09-12 2039170

首次发布变化

9.1.0 的原始条目,包含功能和兼容性变化。类别用于浏览,不是上游原始分类。

匹配 203 / 203 条原始变更。

安全证据

共 35 条记录,来自官方安全矩阵及发布说明的提及。只有安全快照明确列出此分支时才显示修复版本;仅有提及不能确定漏洞适用性或新修复。

CVE-2016-7048 · Interactive installer downloads software over plain HTTP, then executes it · CVSS 7.5

本分支修复于:9.1.24。组件:packaging。

官方受影响分支记录:9.1。

AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2016-5424 · Exceptional database and role names could enable escalation to superuser · CVSS 8.5

本分支修复于:9.1.23。组件:client。

官方受影响分支记录:9.1。

AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

发布说明中的提及:

CVE-2016-5423 · Certain nested CASE/WHEN expressions can crash server · CVSS 4.3

本分支修复于:9.1.23。组件:core server。

官方受影响分支记录:9.1。

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2016-0773 · Unchecked regex can crash the server · CVSS 6.5

本分支修复于:9.1.20。组件:core server。

官方受影响分支记录:9.1。

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

发布说明中的提及:

CVE-2016-0766 · CVE-2016-0766

尚未记录本分支的修复版本。

发布说明中的提及:

CVE-2015-7499 · CVE-2015-7499

尚未记录本分支的修复版本。

发布说明中的提及:

CVE-2015-5288 · Memory leak in crypt() function. · CVSS 3.1

本分支修复于:9.1.19。组件:contrib module。

官方受影响分支记录:9.1。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2015-3167 · pgcrypto has multiple error messages for decryption with an incorrect key. · CVSS 3.7

本分支修复于:9.1.16。组件:contrib module。

官方受影响分支记录:9.1。

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2015-3166 · Unanticipated errors from the standard library. · CVSS 5.6

本分支修复于:9.1.16。组件:core server。

官方受影响分支记录:9.1。

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

发布说明中的提及:

CVE-2015-3165 · Double "free" after authentication timeout · CVSS 7.5

本分支修复于:9.1.16。组件:core server。

官方受影响分支记录:9.1。

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

发布说明中的提及:

CVE-2015-0244 · An error in extended protocol message reading. · CVSS 8.1

本分支修复于:9.1.15。组件:core server。

官方受影响分支记录:9.1。

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2015-0243 · Memory errors in functions in the pgcrypto extension. · CVSS 6.5

本分支修复于:9.1.15。组件:contrib module。

官方受影响分支记录:9.1。

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

发布说明中的提及:

CVE-2015-0242 · Buffer overrun in replacement printf family of functions. · CVSS 4.2

本分支修复于:9.1.15。组件:core server。

官方受影响分支记录:9.1。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

发布说明中的提及:

CVE-2015-0241 · Buffer overruns in "to_char" functions. · CVSS 4.2

本分支修复于:9.1.15。组件:core server。

官方受影响分支记录:9.1。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

发布说明中的提及:

CVE-2014-8161 · Constraint violation errors can cause display of values in columns which the user would not normally have rights to see. · CVSS 3.1

本分支修复于:9.1.15。组件:core server。

官方受影响分支记录:9.1。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2014-0067 · Unauthenticated users may gain access to the database server during "make check".. · CVSS 7.0

本分支修复于:9.1.15。组件:other。

官方受影响分支记录:9.1。

AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2014-0066 · Potential null pointer dereference crash when crypt(3) returns NULL. · CVSS 0.0

本分支修复于:9.1.12。组件:contrib module。

官方受影响分支记录:9.1。

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N

发布说明中的提及:

CVE-2014-0065 · Potential buffer overruns of fixed-size buffers. · CVSS 0.0

本分支修复于:9.1.12。组件:core server。

官方受影响分支记录:9.1。

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N

发布说明中的提及:

CVE-2014-0064 · Potential buffer overruns due to integer overflow in size calculations. · CVSS 6.5

本分支修复于:9.1.12。组件:core server。

官方受影响分支记录:9.1。

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

发布说明中的提及:

CVE-2014-0063 · Potential buffer overruns in datetime input/output. · CVSS 4.3

本分支修复于:9.1.12。组件:core server。

官方受影响分支记录:9.1。

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

发布说明中的提及:

CVE-2014-0062 · Race condition in CREATE INDEX allows for privilege escalation. · CVSS 8.8

本分支修复于:9.1.12。组件:core server。

官方受影响分支记录:9.1。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2014-0061 · Privilege escalation via calls to validator functions. · CVSS 7.5

本分支修复于:9.1.12。组件:core server。

官方受影响分支记录:9.1。

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2014-0060 · SET ROLE bypasses lack of ADMIN OPTION. · CVSS 3.1

本分支修复于:9.1.12。组件:core server。

官方受影响分支记录:9.1。

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

发布说明中的提及:

CVE-2013-1901 · An unprivileged user can run commands that could interfere with in-progress backups.

本分支修复于:9.1.9。

官方受影响分支记录:9.1。

发布说明中的提及:

CVE-2013-1900 · Random numbers generated by contrib/pgcrypto functions may be easy for another database user to guess

本分支修复于:9.1.9。

官方受影响分支记录:9.1。

发布说明中的提及:

CVE-2013-1899 · A connection request containing a database name that begins with "-" may be crafted to damage or destroy files within a server's data directory

本分支修复于:9.1.9。

官方受影响分支记录:9.1。

发布说明中的提及:

CVE-2013-0255 · executing enum_recv() with wrong parameters crashes server

本分支修复于:9.1.8。

官方受影响分支记录:9.1。

发布说明中的提及:

CVE-2012-3489 · xml_parse() DTD validation can be used to read arbitrary files
CVE-2012-3488 · contrib/xml2's xslt_process() can be used to read and write arbitrary files

本分支修复于:9.1.5。

官方受影响分支记录:9.1。

发布说明中的提及:

CVE-2012-2655 · SECURITY DEFINER and SET attributes on procedural call handlers are not ignored and can be used to crash the server

本分支修复于:9.1.4。

官方受影响分支记录:9.1。

发布说明中的提及:

CVE-2012-2143 · Passwords containing the byte 0x80 passed to the crypt() function in pgcrypto are incorrectly truncated if DES encryption was used

本分支修复于:9.1.4。

官方受影响分支记录:9.1。

发布说明中的提及:

CVE-2012-0868 · Line breaks in object names can be exploited to execute arbitrary SQL when reloading a pg_dump file.

本分支修复于:9.1.3。

官方受影响分支记录:9.1。

发布说明中的提及:

CVE-2012-0867 · SSL certificate name checks are truncated to 32 characters, allowing connection spoofing under some circumstances when using third party certificate authorities.

本分支修复于:9.1.3。

官方受影响分支记录:9.1。

发布说明中的提及:

CVE-2012-0866 · Permissions on a function called by a trigger are not properly checked.

本分支修复于:9.1.3。

官方受影响分支记录:9.1。

发布说明中的提及:

CVE-2007-4772 · CVE-2007-4772

尚未记录本分支的修复版本。

发布说明中的提及:

导出此分支 JSON · 比较已收录的发布版本