↑↓ 选择 ↵ 打开 ⌫ 改范围 完整检索页

pgsql.cc 提供对 postgresql.org 官网内容的中文翻译,由 Pigsty 团队维护。

百科 / 版本发布

PostgreSQL 9.4

已停止支持 · 记录构建 9.4.26 · 2020-02-13

此大版本已停止支持,相关记录用于查阅历史;没有更新的安全记录不代表仍可安全运行。

首次正式发布
2014-12-18
支持结束
2020-02-13
已收录发布版本
27
原始发布说明条目
1007

手册与来源

PostgreSQL 9.4 本站手册 · 已加载 935 页。

手册加载时间:2026-09-27T00:10:45.258078。

发布说明快照:2026-09-26。安全证据快照:2026-09-26。PDF 链接按本地文件是否存在提供,历史版本的语言与 HTML 手册可能不同。生命周期参见官方版本政策。

升级注意事项

跨大版本升级需要导出/恢复或 pg_upgrade 等迁移方式,应阅读沿途大版本的发布说明与目标版本手册。小版本更新也可能要求额外操作,请核对对应发布的迁移说明。官方升级政策。

9.4.0 的兼容性变化 · 从首发到 9.4.26 的变化

9.4.0 的原始迁移说明

希望从任何之前的版本迁移数据的用户,需要使用pg_dumpall进行转储/恢复,或使用pg_upgrade。

版本 9.4 包含许多可能影响与以前版本兼容性的变更。请注意以下不兼容之处:

发布历史

每次发布的原始变更均独立保留。CVE 数量表示发布说明中的提及,可能包含后续纠正,不等于本次新修复漏洞数。

版本日期/快照截止时间全部变化BUG 修复迁移条目提及 CVE
9.4.26 2020-02-13 281500
9.4.25 2019-11-14 391700
9.4.24 2019-08-08 18702
9.4.23 2019-06-20 10500
9.4.22 2019-05-09 251500
9.4.21 2019-02-14 351900
9.4.20 2018-11-08 422000
9.4.19 2018-08-09 261301
9.4.18 2018-05-10 321600
9.4.17 2018-03-01 7401
9.4.16 2018-02-08 281601
9.4.15 2017-11-09 221002
9.4.14 2017-08-31 8200
9.4.13 2017-08-10 532704
9.4.12 2017-05-11 341904
9.4.11 2017-02-09 441900
9.4.10 2016-10-27 341800
9.4.9 2016-08-11 391402
9.4.8 2016-05-12 211200
9.4.7 2016-03-31 231300
9.4.6 2016-02-11 592604
9.4.5 2015-10-08 703702
9.4.4 2015-06-12 4300
9.4.3 2015-06-04 4300
9.4.2 2015-05-22 592403
9.4.1 2015-02-05 321206
9.4.0 2014-12-18 2116220

首次发布变化

9.4.0 的原始条目,包含功能和兼容性变化。类别用于浏览,不是上游原始分类。

匹配 211 / 211 条原始变更。

安全证据

共 36 条记录,来自官方安全矩阵及发布说明的提及。只有安全快照明确列出此分支时才显示修复版本;仅有提及不能确定漏洞适用性或新修复。

CVE-2019-3466 · pg_ctlcluster script in postgresql-common does not drop privileges when creating socket/statistics temporary directories · CVSS 8.4

A PostgreSQL superuser could escalate to root using a deficiency in the pg_ctlcluster command. pg_ctlcluster is a utility provided by the "postgresql-common" package that is installed with PostgreSQL on Debian and Ubuntu platforms.

以上保留官方英文漏洞说明。

本分支修复于:9.4.25。组件:packaging。

官方受影响分支记录:9.4。

AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

CVE-2019-10211 · Windows installer bundled OpenSSL executes code from unprotected directory · CVSS 7.8

When the database server or libpq client library initializes SSL, libeay32.dll attempts to read configuration from a hard-coded directory. Typically, the directory does not exist, but any local user could create it and inject configuration. This configuration can direct OpenSSL to load and execute arbitrary code as the user running a PostgreSQL server or client. Most PostgreSQL client tools and libraries use libpq , and one can encounter this vulnerability by using any of them. This vulnerability is much like CVE-2019-5443 , but it originated independently. One can work around the vulnerability by setting environment variable OPENSSL_CONF to "NUL:/openssl.cnf" or any other name that cannot exist as a file. The PostgreSQL project thanks Daniel Gustafsson of the curl security team for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.4.24。组件:packaging。

官方受影响分支记录:9.4。

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2019-10210 · Windows installer writes superuser password to unprotected temporary file · CVSS 6.7

The EnterpriseDB Windows installer writes a password to a temporary file in its installation directory, creates initial databases, and deletes the file. During those seconds while the file exists, a local attacker can read the PostgreSQL superuser password from the file. The PostgreSQL project thanks Noah Misch for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.4.24。组件:packaging。

官方受影响分支记录:9.4。

AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVE-2019-10208 · TYPE in pg_temp executes arbitrary SQL during SECURITY DEFINER execution · CVSS 7.5

Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function call having inexact argument type match. For example, length('foo'::varchar) and length('foo') are inexact, while length('foo'::text) is exact. As part of exploiting this vulnerability, the attacker uses CREATE DOMAIN to create a type in a pg_temp schema. The attack pattern and fix are similar to that for CVE-2007-2138 . Writing SECURITY DEFINER functions continues to require following the considerations noted in the documentation: https://www.postgresql.org/docs/current/sql-createfunction.html#SQL-CREATEFUNCTION-SECURITY The PostgreSQL project thanks Tom Lane for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.4.24。组件:core server。

官方受影响分支记录:9.4。

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2019-10128 · EnterpriseDB Windows installer does not clear permissive ACL entries · CVSS 7.0

Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.4.22。组件:packaging。

官方受影响分支记录:9.4。

AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2019-10127 · BigSQL Windows installer does not clear permissive ACL entries. · CVSS 7.0

Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.4.22。组件:packaging。

官方受影响分支记录:9.4。

AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2018-10915 · Certain host connection parameters defeat client-side security defenses · CVSS 8.5

本分支修复于:9.4.19。组件:client。

官方受影响分支记录:9.4。

AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

发布说明中的提及:

CVE-2018-1058 · Uncontrolled search path element in pg_dump and other client applications · CVSS 8.8

本分支修复于:9.4.17。组件:client。

官方受影响分支记录:9.4。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2018-1053 · pg_upgrade creates file of sensitive metadata under prevailing umask · CVSS 6.7

本分支修复于:9.4.16。组件:client。

官方受影响分支记录:9.4。

AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2017-7548 · lo_put() function ignores ACLs · CVSS 3.1

本分支修复于:9.4.13。组件:core server。

官方受影响分支记录:9.4。

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

发布说明中的提及:

CVE-2017-7547 · pg_user_mappings view discloses passwords to users lacking server privileges · CVSS 8.5
CVE-2017-7546 · empty password accepted in some authentication methods · CVSS 8.1

本分支修复于:9.4.13。组件:core server。

官方受影响分支记录:9.4。

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2017-7486 · pg_user_mappings view discloses foreign server passwords · CVSS 8.5
CVE-2017-7485 · libpq ignores PGREQUIRESSL environment variable · CVSS 8.1

本分支修复于:9.4.12。组件:client。

官方受影响分支记录:9.4。

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks · CVSS 4.3

本分支修复于:9.4.12。组件:core server。

官方受影响分支记录:9.4。

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2017-15098 · Memory disclosure in JSON functions · CVSS 4.3

本分支修复于:9.4.15。组件:core server。

官方受影响分支记录:9.4。

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2017-12172 · Start scripts permit database administrator to modify root-owned files · CVSS 8.4

本分支修复于:9.4.15。组件:contrib module。

官方受影响分支记录:9.4。

AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

发布说明中的提及:

CVE-2016-7048 · Interactive installer downloads software over plain HTTP, then executes it · CVSS 7.5

本分支修复于:9.4.10。组件:packaging。

官方受影响分支记录:9.4。

AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2016-5424 · Exceptional database and role names could enable escalation to superuser · CVSS 8.5

本分支修复于:9.4.9。组件:client。

官方受影响分支记录:9.4。

AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

发布说明中的提及:

CVE-2016-5423 · Certain nested CASE/WHEN expressions can crash server · CVSS 4.3

本分支修复于:9.4.9。组件:core server。

官方受影响分支记录:9.4。

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2016-0773 · Unchecked regex can crash the server · CVSS 6.5

本分支修复于:9.4.6。组件:core server。

官方受影响分支记录:9.4。

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

发布说明中的提及:

CVE-2016-0766 · CVE-2016-0766

尚未记录本分支的修复版本。

发布说明中的提及:

CVE-2015-7499 · CVE-2015-7499

尚未记录本分支的修复版本。

发布说明中的提及:

CVE-2015-5289 · Unchecked JSON input can crash the server · CVSS 5.9

本分支修复于:9.4.5。组件:core server。

官方受影响分支记录:9.4。

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

发布说明中的提及:

CVE-2015-5288 · Memory leak in crypt() function. · CVSS 3.1

本分支修复于:9.4.5。组件:contrib module。

官方受影响分支记录:9.4。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2015-3167 · pgcrypto has multiple error messages for decryption with an incorrect key. · CVSS 3.7

本分支修复于:9.4.2。组件:contrib module。

官方受影响分支记录:9.4。

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2015-3166 · Unanticipated errors from the standard library. · CVSS 5.6

本分支修复于:9.4.2。组件:core server。

官方受影响分支记录:9.4。

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

发布说明中的提及:

CVE-2015-3165 · Double "free" after authentication timeout · CVSS 7.5

本分支修复于:9.4.2。组件:core server。

官方受影响分支记录:9.4。

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

发布说明中的提及:

CVE-2015-0244 · An error in extended protocol message reading. · CVSS 8.1

本分支修复于:9.4.1。组件:core server。

官方受影响分支记录:9.4。

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2015-0243 · Memory errors in functions in the pgcrypto extension. · CVSS 6.5

本分支修复于:9.4.1。组件:contrib module。

官方受影响分支记录:9.4。

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

发布说明中的提及:

CVE-2015-0242 · Buffer overrun in replacement printf family of functions. · CVSS 4.2

本分支修复于:9.4.1。组件:core server。

官方受影响分支记录:9.4。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

发布说明中的提及:

CVE-2015-0241 · Buffer overruns in "to_char" functions. · CVSS 4.2

本分支修复于:9.4.1。组件:core server。

官方受影响分支记录:9.4。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

发布说明中的提及:

CVE-2014-8161 · Constraint violation errors can cause display of values in columns which the user would not normally have rights to see. · CVSS 3.1

本分支修复于:9.4.1。组件:core server。

官方受影响分支记录:9.4。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2014-0067 · Unauthenticated users may gain access to the database server during "make check".. · CVSS 7.0

本分支修复于:9.4.1。组件:other。

官方受影响分支记录:9.4。

AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2007-4772 · CVE-2007-4772

尚未记录本分支的修复版本。

发布说明中的提及:

CVE-2007-2138 · A vulnerability involving insecure search_path settings allows unprivileged users to gain the SQL privileges of the owner of any SECURITY DEFINER function they are allowed to call. Securing such a function requires both a software update and changes to the function definition.

尚未记录本分支的修复版本。

发布说明中的提及:

导出此分支 JSON · 比较已收录的发布版本