PostgreSQL 9.5
已停止支持 · 记录构建 9.5.25 · 2021-02-11
此大版本已停止支持,相关记录用于查阅历史;没有更新的安全记录不代表仍可安全运行。
- 首次正式发布
- 2016-01-07
- 支持结束
- 2021-02-11
- 已收录发布版本
- 26
- 原始发布说明条目
- 1026
手册与来源
PostgreSQL 9.5 本站手册 · 已加载 959 页。
手册加载时间:2026-09-27T00:10:45.258078。
发布说明快照:2026-09-26。安全证据快照:2026-09-26。PDF 链接按本地文件是否存在提供,历史版本的语言与 HTML 手册可能不同。生命周期参见官方版本政策。
升级注意事项
跨大版本升级需要导出/恢复或 pg_upgrade 等迁移方式,应阅读沿途大版本的发布说明与目标版本手册。小版本更新也可能要求额外操作,请核对对应发布的迁移说明。官方升级政策。
9.5.0 的兼容性变化 · 从首发到 9.5.25 的变化
9.5.0 的原始迁移说明
发布历史
每次发布的原始变更均独立保留。CVE 数量表示发布说明中的提及,可能包含后续纠正,不等于本次新修复漏洞数。
| 版本 | 日期/快照截止时间 | 全部变化 | BUG 修复 | 迁移条目 | 提及 CVE |
|---|---|---|---|---|---|
| 9.5.25 | 2021-02-11 | 32 | 15 | 0 | 0 |
| 9.5.24 | 2020-11-12 | 34 | 10 | 0 | 3 |
| 9.5.23 | 2020-08-13 | 25 | 11 | 0 | 2 |
| 9.5.22 | 2020-05-14 | 33 | 14 | 0 | 0 |
| 9.5.21 | 2020-02-13 | 29 | 16 | 0 | 0 |
| 9.5.20 | 2019-11-14 | 50 | 19 | 0 | 0 |
| 9.5.19 | 2019-08-08 | 20 | 7 | 0 | 2 |
| 9.5.18 | 2019-06-20 | 14 | 8 | 0 | 0 |
| 9.5.17 | 2019-05-09 | 31 | 18 | 0 | 2 |
| 9.5.16 | 2019-02-14 | 39 | 22 | 0 | 0 |
| 9.5.15 | 2018-11-08 | 52 | 25 | 0 | 0 |
| 9.5.14 | 2018-08-09 | 30 | 14 | 0 | 2 |
| 9.5.13 | 2018-05-10 | 38 | 20 | 0 | 0 |
| 9.5.12 | 2018-03-01 | 7 | 4 | 0 | 1 |
| 9.5.11 | 2018-02-08 | 32 | 18 | 0 | 1 |
| 9.5.10 | 2017-11-09 | 28 | 14 | 0 | 3 |
| 9.5.9 | 2017-08-31 | 8 | 2 | 0 | 0 |
| 9.5.8 | 2017-08-10 | 56 | 30 | 0 | 4 |
| 9.5.7 | 2017-05-11 | 40 | 23 | 0 | 4 |
| 9.5.6 | 2017-02-09 | 56 | 29 | 0 | 0 |
| 9.5.5 | 2016-10-27 | 47 | 22 | 0 | 0 |
| 9.5.4 | 2016-08-11 | 51 | 23 | 0 | 2 |
| 9.5.3 | 2016-05-12 | 25 | 14 | 0 | 0 |
| 9.5.2 | 2016-03-31 | 33 | 20 | 0 | 2 |
| 9.5.1 | 2016-02-11 | 23 | 12 | 0 | 2 |
| 9.5.0 | 2016-01-07 | 193 | 1 | 12 | 0 |
首次发布变化
9.5.0 的原始条目,包含功能和兼容性变化。类别用于浏览,不是上游原始分类。
匹配 193 / 193 条原始变更。
调整操作符优先级以符合 SQL 标准 · 兼容性变化 · 迁移说明
调整操作符优先级以符合 SQL 标准(Tom Lane)
<=、>=和<>的优先级已降低到与<、>和=相同。IS测试(例如xIS NULL)的优先级已降低到恰好位于这六个比较操作符之下。此外,以NOT开头的多关键字操作符现在具有其基础操作符的优先级(例如NOT BETWEEN现在与BETWEEN优先级相同),而以前它们的优先级并不一致:对左操作数表现得像NOT,对右操作数表现得像其基础操作符。新的配置参数operator_precedence_warning可以启用,以就在这些优先级变更导致不同解析选择的查询发出警告。原始发布条目 ·
9.5.0/migration/001在 PL/pgSQL 赋值中使用赋值转换行为进行数据类型转换,而不是经由文本往返转换 · 兼容性变化 · 迁移说明
在 PL/pgSQL 赋值中使用赋值转换行为进行数据类型转换,而不是经由文本往返转换(Tom Lane)
此变更使布尔值到字符串的转换产生
true或false,而不是t或f。其他类型转换可能在比以前更多的情况下成功;例如,把数值3.9赋给整数变量现在会赋值 4,而不是失败。如果没有为特定的源类型和目标类型定义赋值级转换,PL/pgSQL 将回退到旧的 I/O 转换行为。原始发布条目 ·
9.5.0/migration/003把 GSSAPI 的 include_realm 参数默认值改为 1,因此默认情况下不会从 GSS 或 SSPI 主体名中移除领域(realm) · 兼容性变化 · 迁移说明
把 GSSAPI 的
include_realm参数默认值改为 1,因此默认情况下不会从 GSS 或 SSPI 主体名中移除领域(realm)(Stephen Frost)原始发布条目 ·
9.5.0/migration/005用min_wal_size和max_wal_size替换配置参数 checkpoint_segments · 兼容性变化 · 迁移说明
用min_wal_size和max_wal_size替换配置参数
checkpoint_segments(Heikki Linnakangas)如果你以前调整过
checkpoint_segments,以下公式可给出近似等效的设置:max_wal_size = (3 * checkpoint_segments) * 16MB
注意,
max_wal_size的默认设置比过去checkpoint_segments的默认值高得多,因此可能不再需要调整它。原始发布条目 ·
9.5.0/migration/006通过新的环境变量 PG_OOM_ADJUST_FILE 和 PG_OOM_ADJUST_VALUE 控制 Linux 的 OOM killer,而不是编译时选项 LINUX_OOM_SCORE_ADJ 和 LINUX_OOM_ADJ · 兼容性变化 · 迁移说明
通过新的环境变量
PG_OOM_ADJUST_FILE和PG_OOM_ADJUST_VALUE控制 Linux 的 OOM killer,而不是编译时选项LINUX_OOM_SCORE_ADJ和LINUX_OOM_ADJ(Gurjeet Singh)原始发布条目 ·
9.5.0/migration/007停用服务器配置参数 ssl_renegotiation_limit,它在以前的版本中已被弃用 · 兼容性变化 · 迁移说明
停用服务器配置参数
ssl_renegotiation_limit,它在以前的版本中已被弃用(Andres Freund)虽然 SSL 重协商在理论上是个好主意,但它引发的 bug 之多,使它在实践中被认为弊大于利,而且相关标准的未来版本将移除它。因此我们已从 PostgreSQL 中移除了对它的支持。
ssl_renegotiation_limit参数仍然存在,但只能设置为零(禁用)。它也不再被写入文档。原始发布条目 ·
9.5.0/migration/008移除服务器配置参数 autocommit,它此前已被弃用且不起作用 · 兼容性变化 · 迁移说明
移除服务器配置参数
autocommit,它此前已被弃用且不起作用(Tom Lane)原始发布条目 ·
9.5.0/migration/009当没有有效值时,pg_stat_replication 系统视图的 sent 字段现在为 NULL 而不是零 · 兼容性变化 · 迁移说明
当没有有效值时,
pg_stat_replication系统视图的sent字段现在为 NULL 而不是零(Magnus Hagander)原始发布条目 ·
9.5.0/migration/011允许 json 和 jsonb 数组提取操作符接受负数下标,它们从 JSON 数组末尾开始计数 · 兼容性变化 · 迁移说明
允许
json和jsonb数组提取操作符接受负数下标,它们从 JSON 数组末尾开始计数(Peter Geoghegan、Andrew Dunstan)以前,这些操作符对负数下标返回
NULL。原始发布条目 ·
9.5.0/migration/012添加配置参数gin_pending_list_limit来控制 GIN 待处理列表的大小 · 新功能
添加配置参数gin_pending_list_limit来控制 GIN 待处理列表的大小(Fujii Masao)
该值也可以按索引设置为索引存储参数。以前,待处理列表的大小由work_mem控制,这很不方便,因为
work_mem的合适值对此用途往往太大了。原始发布条目 ·
9.5.0/changes/004通过“缩写”键提高 varchar、text 和 numeric 字段的排序速度 · 性能改进
通过“缩写”键提高
varchar、text和numeric字段的排序速度(Peter Geoghegan、Andrew Gierth、Robert Haas)原始发布条目 ·
9.5.0/changes/006扩展允许由内联的、非 SQL 可调用的比较函数执行排序的基础设施,使其覆盖 CREATE INDEX、REINDEX 和 CLUSTER · 性能改进
扩展允许由内联的、非 SQL 可调用的比较函数执行排序的基础设施,使其覆盖
CREATE INDEX、REINDEX和CLUSTER(Peter Geoghegan)原始发布条目 ·
9.5.0/changes/007如果非防泄漏函数不接收任何视图输出列,则允许把它下推到安全屏障视图中 · 性能改进
如果非防泄漏函数不接收任何视图输出列,则允许把它下推到安全屏障视图中(Dean Rasheed)
原始发布条目 ·
9.5.0/changes/015当 WHERE 中出现匹配的函数调用时,让规划器使用从布尔返回函数表达式索引获得的统计信息 · 性能改进
当
WHERE中出现匹配的函数调用时,让规划器使用从布尔返回函数表达式索引获得的统计信息(Tom Lane)原始发布条目 ·
9.5.0/changes/016即使列的数据类型缺少相等函数,也让 ANALYZE 计算基本统计信息(空值比例和平均列宽) · 性能改进
即使列的数据类型缺少相等函数,也让
ANALYZE计算基本统计信息(空值比例和平均列宽)(Oleksandr Shulgin)原始发布条目 ·
9.5.0/changes/017加速 CRC(循环冗余校验)计算并切换到 CRC-32C · 性能改进
加速 CRC(循环冗余校验)计算并切换到 CRC-32C(Abhijit Menon-Sen、Heikki Linnakangas)
原始发布条目 ·
9.5.0/changes/018通过避免不必要的内存复制加速 CREATE INDEX · 性能改进
通过避免不必要的内存复制加速
CREATE INDEX(Robert Haas)原始发布条目 ·
9.5.0/changes/020增加缓冲区映射的分区数 · 性能改进
增加缓冲区映射的分区数(Amit Kapila、Andres Freund、Robert Haas)
这提高了高并发负载下的性能。
原始发布条目 ·
9.5.0/changes/021通过新的 log_autovacuum_min_duration 存储参数添加按表的自动清理日志控制 · 新功能
通过新的
log_autovacuum_min_duration存储参数添加按表的自动清理日志控制(Michael Paquier)原始发布条目 ·
9.5.0/changes/022添加新的配置参数cluster_name · 新功能
添加新的配置参数cluster_name(Thomas Munro)
这个字符串通常在
postgresql.conf中设置,让客户端能够识别集群。该名称还会出现在所有服务器进程的进程标题中,便于识别属于同一集群的进程。原始发布条目 ·
9.5.0/changes/023防止非超级用户在连接启动时更改log_disconnections · 新功能
防止非超级用户在连接启动时更改log_disconnections(Fujii Masao)
原始发布条目 ·
9.5.0/changes/024检查 SSL 服务器证书中的“使用者可选名称(Subject Alternative Names)”(如果存在) · 新功能
检查 SSL 服务器证书中的“使用者可选名称(Subject Alternative Names)”(如果存在)(Alexey Klyukin)
当它们存在时,这将取代对证书“通用名称(Common Name)”的检查。
原始发布条目 ·
9.5.0/changes/025添加系统视图 pg_stat_ssl,用于报告 SSL 连接信息 · 新功能
添加系统视图
pg_stat_ssl,用于报告 SSL 连接信息(Magnus Hagander)原始发布条目 ·
9.5.0/changes/026添加以与实现无关的方式返回 SSL 信息的 libpq 函数 · 新功能
添加以与实现无关的方式返回 SSL 信息的 libpq 函数(Heikki Linnakangas)
虽然
PQgetssl()仍可用于调用 OpenSSL 函数,但它现在被视为已弃用,因为未来版本的 libpq 可能支持其他 SSL 实现。在可能的情况下,请使用新函数PQsslAttribute()、PQsslAttributeNames()和PQsslInUse(),以与 SSL 实现无关的方式获取 SSL 信息。原始发布条目 ·
9.5.0/changes/027使 libpq 遵循任何 OpenSSL 线程回调 · 新功能
使 libpq 遵循任何 OpenSSL 线程回调(Jan Urbanski)
以前它们会被覆盖。
原始发布条目 ·
9.5.0/changes/028用min_wal_size和max_wal_size替换配置参数 checkpoint_segments · 新功能
用min_wal_size和max_wal_size替换配置参数
checkpoint_segments(Heikki Linnakangas)此变更允许分配大量 WAL 文件,而在不再需要之后不必保留它们。因此
max_wal_size的默认值被设置为1GB,比过去checkpoint_segments的默认值大得多。另请注意,备库会执行重做点以尝试把 WAL 空间消耗限制在max_wal_size以内;以前它们完全不理会checkpoint_segments。原始发布条目 ·
9.5.0/changes/029通过新的环境变量 PG_OOM_ADJUST_FILE 和 PG_OOM_ADJUST_VALUE 控制 Linux 的 OOM killer · 新功能
通过新的环境变量
PG_OOM_ADJUST_FILE和PG_OOM_ADJUST_VALUE控制 Linux 的 OOM killer(Gurjeet Singh)以前的 OOM 控制基础设施涉及编译时选项
LINUX_OOM_SCORE_ADJ和LINUX_OOM_ADJ,它们不再受支持。新的行为在所有构建中都可用。原始发布条目 ·
9.5.0/changes/030当配置参数track_commit_timestamp启用时,允许记录事务提交时间戳 · 新功能
当配置参数track_commit_timestamp启用时,允许记录事务提交时间戳(Álvaro Herrera、Petr Jelínek)
时间戳信息可以通过函数
pg_xact_commit_timestamp()和pg_last_committed_xact()访问。原始发布条目 ·
9.5.0/changes/031允许通过 ALTER ROLE SET 设置local_preload_libraries · 新功能
允许通过
ALTER ROLE SET设置local_preload_libraries(Peter Eisentraut、Kyotaro Horiguchi)原始发布条目 ·
9.5.0/changes/032把配置参数debug_assertions设为只读 · 新功能
把配置参数debug_assertions设为只读(Andres Freund)
这意味着,如果在编译时启用了断言,就无法再关闭它们,从而允许更高效的代码优化。此变更还移除了 postgres 的
-A选项。原始发布条目 ·
9.5.0/changes/034允许在不生效的系统上设置effective_io_concurrency · 新功能
允许在不生效的系统上设置effective_io_concurrency(Peter Eisentraut)
原始发布条目 ·
9.5.0/changes/035添加系统视图 pg_file_settings,用于显示服务器配置文件的内容 · 新功能
添加系统视图
pg_file_settings,用于显示服务器配置文件的内容(Sawada Masahiko)原始发布条目 ·
9.5.0/changes/036向系统视图 pg_settings 添加 pending_restart,用于指示已做出更改但在数据库重启之前不会生效 · 新功能
向系统视图
pg_settings添加pending_restart,用于指示已做出更改但在数据库重启之前不会生效(Peter Eisentraut)原始发布条目 ·
9.5.0/changes/037允许用 ALTER SYSTEM RESET 重置 ALTER SYSTEM 的值 · 新功能
允许用
ALTER SYSTEM RESET重置ALTER SYSTEM的值(Vik Fearing)此命令会从
postgresql.auto.conf中移除指定的设置。原始发布条目 ·
9.5.0/changes/038重做多事务提交日志的截断逻辑,使其正确记录 WAL · 新功能
重做多事务提交日志的截断逻辑,使其正确记录 WAL(Andres Freund)
这使事情变得明显更简单、更健壮。
原始发布条目 ·
9.5.0/changes/040添加 recovery.conf 参数 recovery_target_action 来控制恢复之后的动作 · 新功能
添加
recovery.conf参数recovery_target_action来控制恢复之后的动作(Petr Jelínek)它取代了旧的参数
pause_at_recovery_target。原始发布条目 ·
9.5.0/changes/041为archive_mode添加新值 always,允许备库始终归档收到的 WAL 文件 · 新功能
为archive_mode添加新值
always,允许备库始终归档收到的 WAL 文件(Fujii Masao)原始发布条目 ·
9.5.0/changes/042添加配置参数wal_retrieve_retry_interval,控制在失败后重试读取 WAL 的间隔 · 新功能
添加配置参数wal_retrieve_retry_interval,控制在失败后重试读取 WAL 的间隔(Alexey Vasiliev、Michael Paquier)
这对温备库特别有用。
原始发布条目 ·
9.5.0/changes/043允许压缩存储在 WAL 中的全页映像 · 新功能
允许压缩存储在 WAL 中的全页映像(Rahila Syed、Michael Paquier)
此特性可减少 WAL 量,代价是 WAL 记录和 WAL 重放消耗更多 CPU 时间。它由新的配置参数wal_compression控制,目前默认关闭。
原始发布条目 ·
9.5.0/changes/044在备库提升期间为 WAL 文件加上 .partial 后缀后归档 · 新功能
在备库提升期间为 WAL 文件加上
.partial后缀后归档(Heikki Linnakangas)原始发布条目 ·
9.5.0/changes/045添加配置参数log_replication_commands来记录复制命令 · 新功能
添加配置参数log_replication_commands来记录复制命令(Fujii Masao)
默认情况下,复制命令(例如
IDENTIFY_SYSTEM)不会被记录,即使log_statement被设置为all。原始发布条目 ·
9.5.0/changes/046在 pg_replication_slots 中报告持有复制槽的进程 · 新功能
在
pg_replication_slots中报告持有复制槽的进程(Craig Ringer)新增的输出列为
active_pid。原始发布条目 ·
9.5.0/changes/047允许 recovery.conf 的 primary_conninfo 设置使用连接 URI(例如 postgres://) · 新功能
允许
recovery.conf的primary_conninfo设置使用连接 URI(例如postgres://)(Alexander Shulgin)原始发布条目 ·
9.5.0/changes/048添加 GROUP BY 分析特性 GROUPING SETS、CUBE 和 ROLLUP · 新功能
添加
GROUP BY分析特性GROUPING SETS、CUBE和ROLLUP(Andrew Gierth、Atri Sharma)原始发布条目 ·
9.5.0/changes/050为 SELECT 添加选项 TABLESAMPLE,用于返回表的子集 · 新功能
为
SELECT添加选项TABLESAMPLE,用于返回表的子集(Petr Jelínek)此特性支持 SQL 标准的表采样方法。此外,还为用户自定义表采样方法提供了机制。
原始发布条目 ·
9.5.0/changes/053允许 REINDEX 使用 SCHEMA 选项对整个模式重新索引 · 新功能
允许
REINDEX使用SCHEMA选项对整个模式重新索引(Sawada Masahiko)原始发布条目 ·
9.5.0/changes/058防止 REINDEX DATABASE 和 SCHEMA 输出对象名称,除非使用 VERBOSE · 新功能
防止
REINDEX DATABASE和SCHEMA输出对象名称,除非使用VERBOSE(Simon Riggs)原始发布条目 ·
9.5.0/changes/060添加行级安全性控制 · 新功能
添加行级安全性控制(Craig Ringer、KaiGai Kohei、Adam Brightwell、Dean Rasheed、Stephen Frost)
此特性允许逐行控制哪些用户可以添加、修改甚至看到表中的行。它由新命令
CREATE/ALTER/DROP POLICY以及ALTER TABLE ... ENABLE/DISABLE ROW SECURITY控制。原始发布条目 ·
9.5.0/changes/062允许在创建表之后用 ALTER TABLE ... SET LOGGED / UNLOGGED 更改其 WAL 记录状态 · 新功能
允许在创建表之后用
ALTER TABLE ... SET LOGGED / UNLOGGED更改其 WAL 记录状态(Fabrízio de Royes Mello)原始发布条目 ·
9.5.0/changes/063为 CREATE TABLE AS、CREATE INDEX、CREATE SEQUENCE 和 CREATE MATERIALIZED VIEW 添加 IF NOT EXISTS 子句 · 新功能
为
CREATE TABLE AS、CREATE INDEX、CREATE SEQUENCE和CREATE MATERIALIZED VIEW添加IF NOT EXISTS子句(Fabrízio de Royes Mello)原始发布条目 ·
9.5.0/changes/064为 ALTER TABLE ... RENAME CONSTRAINT 添加对 IF EXISTS 的支持 · 新功能
为
ALTER TABLE ... RENAME CONSTRAINT添加对IF EXISTS的支持(Bruce Momjian)原始发布条目 ·
9.5.0/changes/065允许一些 DDL 命令接受 CURRENT_USER 或 SESSION_USER(即当前用户或会话用户)来代替特定的用户名 · 新功能
允许一些 DDL 命令接受
CURRENT_USER或SESSION_USER(即当前用户或会话用户)来代替特定的用户名(Kyotaro Horiguchi、Álvaro Herrera)ALTER USER、ALTER GROUP、ALTER ROLE、GRANT以及
ALTER命令现在支持此特性。objectOWNER TO原始发布条目 ·
9.5.0/changes/066降低一些创建/更改触发器和外键命令的锁定级别 · 新功能
降低一些创建/更改触发器和外键命令的锁定级别(Simon Riggs、Andreas Karlsson)
原始发布条目 ·
9.5.0/changes/068允许对目标表具有 INSERT 权限的用户执行 LOCK TABLE ... ROW EXCLUSIVE MODE · 新功能
允许对目标表具有
INSERT权限的用户执行LOCK TABLE ... ROW EXCLUSIVE MODE(Stephen Frost)以前此命令要求
UPDATE、DELETE或TRUNCATE权限。原始发布条目 ·
9.5.0/changes/069允许 CREATE/ALTER DATABASE 操纵 datistemplate 和 datallowconn · 新功能
允许
CREATE/ALTER DATABASE操纵datistemplate和datallowconn(Vik Fearing)这样无需手动修改
pg_database系统目录即可更改这些按数据库的设置。原始发布条目 ·
9.5.0/changes/071添加对IMPORT FOREIGN SCHEMA的支持 · 新功能
添加对IMPORT FOREIGN SCHEMA的支持(Ronan Dunklau、Michael Paquier、Tom Lane)
此命令允许自动创建与远程服务器上现有表结构匹配的本地外部表。
原始发布条目 ·
9.5.0/changes/072允许外部表参与继承 · 新功能
允许外部表参与继承(Shigeru Hanada、Etsuro Fujita)
为使其自然工作,现在允许外部表带有标记为 NOT VALID 的检查约束,并允许设置存储和
OID特性,尽管这些操作对外部表实际上是空操作。原始发布条目 ·
9.5.0/changes/074只要安装了 ddl_command_end 事件触发器,就会捕获 DDL 活动的细节供其检查 · 新功能
只要安装了
ddl_command_end事件触发器,就会捕获 DDL 活动的细节供其检查(Álvaro Herrera)这些信息可以通过集合返回函数
pg_event_trigger_ddl_commands()获取;如果该函数提供的细节不够,也可以通过检查 C 数据结构获取。原始发布条目 ·
9.5.0/changes/076允许对由 ALTER TABLE 引起的表重写设置事件触发器 · 新功能
允许对由
ALTER TABLE引起的表重写设置事件触发器(Dimitri Fontaine)原始发布条目 ·
9.5.0/changes/077为数据库级的 COMMENT、SECURITY LABEL 和 GRANT/REVOKE 添加事件触发器支持 · 新功能
为数据库级的
COMMENT、SECURITY LABEL和GRANT/REVOKE添加事件触发器支持(Álvaro Herrera)原始发布条目 ·
9.5.0/changes/078向 pg_event_trigger_dropped_objects 的输出添加列 · 新功能
向
pg_event_trigger_dropped_objects的输出添加列(Álvaro Herrera)这使删除操作的处理更简单。
原始发布条目 ·
9.5.0/changes/079添加数据类型 regrole 和 regnamespace,以简化角色或命名空间 OID 的输入与美化打印 · 新功能
添加数据类型
regrole和regnamespace,以简化角色或命名空间OID的输入与美化打印(Kyotaro Horiguchi)原始发布条目 ·
9.5.0/changes/084添加 jsonb 函数 jsonb_set() 和 jsonb_pretty() · 新功能
添加
jsonb函数jsonb_set()和jsonb_pretty()(Dmitry Dolgov、Andrew Dunstan、Petr Jelínek)原始发布条目 ·
9.5.0/changes/085添加 jsonb 生成函数 to_jsonb()、jsonb_object()、jsonb_build_object()、jsonb_build_array()、jsonb_agg() 和 jsonb_object_agg() · 新功能
添加
jsonb生成函数to_jsonb()、jsonb_object()、jsonb_build_object()、jsonb_build_array()、jsonb_agg()和jsonb_object_agg()(Andrew Dunstan)json类型此前已有等效函数。原始发布条目 ·
9.5.0/changes/086添加 json_strip_nulls() 和 jsonb_strip_nulls() 函数,用于从文档中移除 JSON 空值 · 新功能
添加
json_strip_nulls()和jsonb_strip_nulls()函数,用于从文档中移除 JSON 空值(Andrew Dunstan)原始发布条目 ·
9.5.0/changes/090为 numeric 值添加 generate_series() · 新功能
为
numeric值添加generate_series()(Plato Malugin)原始发布条目 ·
9.5.0/changes/091允许 array_agg() 和 ARRAY() 接受数组作为输入 · 新功能
允许
array_agg()和ARRAY()接受数组作为输入(Ali Akbar、Tom Lane)原始发布条目 ·
9.5.0/changes/092添加函数 array_position() 和 array_positions(),用于返回数组值的下标 · 新功能
添加函数
array_position()和array_positions(),用于返回数组值的下标(Pavel Stehule)原始发布条目 ·
9.5.0/changes/093允许在 SIMILAR TO 和 SUBSTRING 中使用多字节字符作为转义符 · 新功能
允许在
SIMILAR TO和SUBSTRING中使用多字节字符作为转义符(Jeff Davis)以前只允许单字节字符作为转义符。
原始发布条目 ·
9.5.0/changes/095添加 width_bucket() 的一个变体,支持任何可排序的数据类型和非均匀的桶宽 · 新功能
添加
width_bucket()的一个变体,支持任何可排序的数据类型和非均匀的桶宽(Petr Jelínek)原始发布条目 ·
9.5.0/changes/096为 pg_read_file() 及相关函数添加可选的 missing_ok 参数 · 新功能
为
pg_read_file()及相关函数添加可选的missing_ok参数(Michael Paquier、Heikki Linnakangas)原始发布条目 ·
9.5.0/changes/097为使用 PostgreSQL 提供的舍入函数的平台添加符合 POSIX 的舍入 · 新功能
为使用 PostgreSQL 提供的舍入函数的平台添加符合 POSIX 的舍入(Pedro Gimeno Fortea)
原始发布条目 ·
9.5.0/changes/099添加函数 pg_get_object_address()(返回唯一标识对象的 OID)和函数 pg_identify_object_as_address()(基于 OID 返回对象信息) · 新功能
添加函数
pg_get_object_address()(返回唯一标识对象的OID)和函数pg_identify_object_as_address()(基于OID返回对象信息)(Álvaro Herrera)原始发布条目 ·
9.5.0/changes/100放宽在 pg_stat_activity 中查看查询、执行 pg_cancel_backend() 和执行 pg_terminate_backend() 的安全检查 · 新功能
放宽在
pg_stat_activity中查看查询、执行pg_cancel_backend()和执行pg_terminate_backend()的安全检查(Stephen Frost)以前,只有拥有目标会话的那个特定角色才能执行这些操作;现在,是该角色的成员即可。
原始发布条目 ·
9.5.0/changes/101添加 pg_stat_get_snapshot_timestamp(),用于输出统计快照的时间戳 · 新功能
添加
pg_stat_get_snapshot_timestamp(),用于输出统计快照的时间戳(Matt Kelly)它表示快照文件最后一次写入文件系统的时间。
原始发布条目 ·
9.5.0/changes/102添加 mxid_age(),用于计算多事务 ID 的年龄 · 新功能
添加
mxid_age(),用于计算多事务 ID 的年龄(Bruce Momjian)原始发布条目 ·
9.5.0/changes/103在支持的平台上,使用 128 位整数作为某些聚合函数的累加器 · 新功能
在支持的平台上,使用 128 位整数作为某些聚合函数的累加器(Andreas Karlsson)
原始发布条目 ·
9.5.0/changes/105把pg_archivecleanup、pg_test_fsync、pg_test_timing和pg_xlogdump从 contrib 移到 src/bin · 新功能
把pg_archivecleanup、pg_test_fsync、pg_test_timing和pg_xlogdump从
contrib移到src/bin(Peter Eisentraut)这应使这些程序在大多数安装中默认被安装。
原始发布条目 ·
9.5.0/changes/112允许pg_receivexlog管理物理复制槽 · 新功能
允许pg_receivexlog管理物理复制槽(Michael Paquier)
这通过新的
--create-slot和--drop-slot选项控制。原始发布条目 ·
9.5.0/changes/114允许pg_receivexlog使用新的 --synchronous 选项同步刷写 WAL 到存储 · 新功能
允许pg_receivexlog使用新的
--synchronous选项同步刷写 WAL 到存储(Furuya Osamu、Fujii Masao)若不使用该选项,WAL 文件只在关闭时被 fsync。
原始发布条目 ·
9.5.0/changes/115使pg_basebackup在使用 tar 格式时使用表空间映射文件,以支持 MS Windows 上的符号链接和 100 字符以上的文件路径 · 新功能
使pg_basebackup在使用 tar 格式时使用表空间映射文件,以支持 MS Windows 上的符号链接和 100 字符以上的文件路径(Amit Kapila)
原始发布条目 ·
9.5.0/changes/119为pg_xlogdump添加 --stats 选项,用于显示摘要统计 · 新功能
为pg_xlogdump添加
--stats选项,用于显示摘要统计(Abhijit Menon-Sen)原始发布条目 ·
9.5.0/changes/120为 psql 的 ECHO 变量添加 errors 模式,只显示失败的命令 · 新功能
为 psql 的
ECHO变量添加errors模式,只显示失败的命令(Pavel Stehule)该行为也可以通过 psql 的
-b选项选择。原始发布条目 ·
9.5.0/changes/122在 psql 的 unicode 线型中提供对列、表头和边框线型的分别控制 · 新功能
在 psql 的 unicode 线型中提供对列、表头和边框线型的分别控制(Pavel Stehule)
支持单线或双线;默认为
single。原始发布条目 ·
9.5.0/changes/123添加 \pset 选项 pager_min_lines,用于控制分页器的调用 · 新功能
添加
\pset选项pager_min_lines,用于控制分页器的调用(Andrew Dunstan)原始发布条目 ·
9.5.0/changes/125改进 psql 在决定是否调用分页器时使用的行数统计 · 新功能
改进 psql 在决定是否调用分页器时使用的行数统计(Andrew Dunstan)
原始发布条目 ·
9.5.0/changes/126如果 --output 或 --log-file 开关指定的文件无法写入,psql 现在会失败 · 新功能
如果
--output或--log-file开关指定的文件无法写入,psql 现在会失败(Tom Lane、Daniel Vérité)以前在这种情况下它实际上会忽略该开关。
原始发布条目 ·
9.5.0/changes/127为设置search_path变量添加 psql Tab 补全 · 新功能
为设置search_path变量添加 psql Tab 补全(Jeff Janes)
目前只有第一个模式可以被 Tab 补全。
原始发布条目 ·
9.5.0/changes/128为 psql 的 \? 帮助添加 variables 和 options 小节 · 新功能
为 psql 的
\?帮助添加variables和options小节(Pavel Stehule)\? variables显示 psql 的特殊变量,\? options显示命令行选项。\? commands显示元命令,这是传统输出,仍为默认。这些帮助显示也可以通过命令行选项--help=获取。section原始发布条目 ·
9.5.0/changes/130在 psql 的 \db+ 中显示表空间大小 · 新功能
在 psql 的
\db+中显示表空间大小(Fabrízio de Royes Mello)原始发布条目 ·
9.5.0/changes/131允许 psql 的 \watch 输出 \timing 信息 · 新功能
允许 psql 的
\watch输出\timing信息(Fujii Masao)同时防止
--echo-hidden回显\watch查询,因为这通常是不需要的。原始发布条目 ·
9.5.0/changes/133使 psql 的 \sf 和 \ef 命令遵循 ECHO_HIDDEN · 新功能
使 psql 的
\sf和\ef命令遵循ECHO_HIDDEN(Andrew Dunstan)原始发布条目 ·
9.5.0/changes/134改进 psql 对 \set、\unset 和 :variable 名称的 Tab 补全 · 新功能
改进 psql 对
\set、\unset和:variable名称的 Tab 补全(Pavel Stehule)原始发布条目 ·
9.5.0/changes/135允许 pg_dump 使用 --snapshot 共享另一个会话取得的快照 · 新功能
允许 pg_dump 使用
--snapshot共享另一个会话取得的快照(Simon Riggs、Michael Paquier)远程快照必须是由
pg_export_snapshot()或逻辑复制槽创建所导出的。这可用于在多个 pg_dump 进程之间共享一致的快照。原始发布条目 ·
9.5.0/changes/137支持 tar 归档格式中超过 8GB 的表 · 新功能
支持 tar 归档格式中超过 8GB 的表(Tom Lane)
POSIX 的 tar 格式标准不允许 tar 归档的元素超过 8GB,但大多数现代 tar 实现支持一个允许超过该限制的扩展。必要时使用扩展格式,而不是失败。
原始发布条目 ·
9.5.0/changes/138使 pg_dump 始终打印服务器和 pg_dump 的版本 · 新功能
使 pg_dump 始终打印服务器和 pg_dump 的版本(Jing Wang)
以前,版本信息只在
--verbose模式下打印。原始发布条目 ·
9.5.0/changes/139从 pg_dump、pg_dumpall 和 pg_restore 中移除早已被忽略的 -i/--ignore-version 选项 · 新功能
从 pg_dump、pg_dumpall 和 pg_restore 中移除早已被忽略的
-i/--ignore-version选项(Fujii Masao)原始发布条目 ·
9.5.0/changes/140允许在 MS Windows 上控制 pg_ctl 的事件源日志 · 新功能
允许在 MS Windows 上控制 pg_ctl 的事件源日志(MauMau)
这只控制 pg_ctl,不控制服务器;服务器在
postgresql.conf中有单独的设置。原始发布条目 ·
9.5.0/changes/142如果服务器的监听地址设置为通配值(IPv4 的 0.0.0.0 或 IPv6 的 ::),则通过回环地址连接,而不是尝试按字面使用通配地址 · 新功能
如果服务器的监听地址设置为通配值(IPv4 的
0.0.0.0或 IPv6 的::),则通过回环地址连接,而不是尝试按字面使用通配地址(Kondo Yuta)此修复主要影响 Windows,因为在其他平台上 pg_ctl 会优先使用 Unix 域套接字。
原始发布条目 ·
9.5.0/changes/143把 pg_upgrade 从 contrib 移到 src/bin · 新功能
把 pg_upgrade 从
contrib移到src/bin(Peter Eisentraut)与此变更相关,先前由 pg_upgrade_support 模块提供的功能已被移入核心服务器。
原始发布条目 ·
9.5.0/changes/144支持多个 pg_upgrade 的 -o/-O 选项,将其值串联 · 新功能
支持多个 pg_upgrade 的
-o/-O选项,将其值串联(Bruce Momjian)原始发布条目 ·
9.5.0/changes/145改进 pg_upgrade 中的数据库排序规则比较 · 新功能
改进 pg_upgrade 中的数据库排序规则比较(Heikki Linnakangas)
原始发布条目 ·
9.5.0/changes/146把 pgbench 从 contrib 移到 src/bin · 新功能
把 pgbench 从
contrib移到src/bin(Peter Eisentraut)原始发布条目 ·
9.5.0/changes/148修复“excluding connections establishing”(排除连接建立)的 TPS 数值的计算 · BUG 修复
修复“excluding connections establishing”(排除连接建立)的 TPS 数值的计算(Tatsuo Ishii、Fabien Coelho)
每当 pgbench 线程数少于客户端连接数时,连接建立的开销就会被算错。虽然这显然是个 bug,但我们不会把它回移植到 9.5 之前的分支,因为这会使 TPS 数值无法与以前的结果比较。
原始发布条目 ·
9.5.0/changes/149允许统计超过指定时间的 pgbench 事务 · 新功能
允许统计超过指定时间的 pgbench 事务(Fabien Coelho)
这由新的
--latency-limit选项控制。原始发布条目 ·
9.5.0/changes/150允许 pgbench 使用 \setrandom 生成高斯/指数分布 · 新功能
允许 pgbench 使用
\setrandom生成高斯/指数分布(Kondo Mitsumasa、Fabien Coelho)原始发布条目 ·
9.5.0/changes/151允许 pgbench 的 \set 命令处理包含多个操作符的算术表达式,并向其支持的操作符集合添加 %(取模) · 新功能
允许 pgbench 的
\set命令处理包含多个操作符的算术表达式,并向其支持的操作符集合添加%(取模)(Robert Haas、Fabien Coelho)原始发布条目 ·
9.5.0/changes/152允许自定义路径和扫描方法 · 新功能
允许自定义路径和扫描方法(KaiGai Kohei、Tom Lane)
这允许扩展对优化器和执行器进行更大的控制。
原始发布条目 ·
9.5.0/changes/156外部表现在可以参与 INSERT ... ON CONFLICT DO NOTHING 查询 · 新功能
外部表现在可以参与
INSERT ... ON CONFLICT DO NOTHING查询(Peter Geoghegan、Heikki Linnakangas、Andres Freund)必须修改外部数据包装器才能处理这一点。外部表不支持
INSERT ... ON CONFLICT DO UPDATE。原始发布条目 ·
9.5.0/changes/158改进 hash_create() 选择简单二进制键哈希函数的 API · 新功能
改进
hash_create()选择简单二进制键哈希函数的 API(Teodor Sigaev、Tom Lane)原始发布条目 ·
9.5.0/changes/159改进并行执行基础设施 · 新功能
改进并行执行基础设施(Robert Haas、Amit Kapila、Noah Misch、Rushabh Lathia、Jeevan Chalke)
原始发布条目 ·
9.5.0/changes/160移除 Alpha(CPU)和 Tru64(操作系统)移植 · 新功能
移除 Alpha(CPU)和 Tru64(操作系统)移植(Andres Freund)
原始发布条目 ·
9.5.0/changes/161移除 ARMv5 及更早 CPU 的基于字节交换的自旋锁实现 · 新功能
移除 ARMv5 及更早 CPU 的基于字节交换的自旋锁实现(Robert Haas)
ARMv5 的弱内存排序使这种锁定实现不安全。在支持原子操作的较新 gcc 实现上,自旋锁支持仍然可能。
原始发布条目 ·
9.5.0/changes/162当过长的(100 字符以上)文件路径被写入 tar 文件时产生错误 · 新功能
当过长的(100 字符以上)文件路径被写入 tar 文件时产生错误(Peter Eisentraut)
tar 不支持这种过长的路径。
原始发布条目 ·
9.5.0/changes/163把列 pg_seclabel.provider 和 pg_shseclabel.provider 的索引操作符类改为 text_pattern_ops · 新功能
把列
pg_seclabel.provider和pg_shseclabel.provider的索引操作符类改为text_pattern_ops(Tom Lane)这避免了当集群中不同数据库具有不同默认排序规则时这些索引可能出现的问题。
原始发布条目 ·
9.5.0/changes/164在 Windows 8、Windows Server 2012 及更高版本的 Windows 系统上允许更高精度的时间戳分辨率 · 新功能
在 Windows 8、Windows Server 2012 及更高版本的 Windows 系统上允许更高精度的时间戳分辨率(Craig Ringer)
原始发布条目 ·
9.5.0/changes/166在 MS Windows 上把共享库安装到 bin · 新功能
在 MS Windows 上把共享库安装到
bin(Peter Eisentraut、Michael Paquier)原始发布条目 ·
9.5.0/changes/167在 MSVC 构建中把 src/test/modules 与 contrib 一起安装 · 新功能
在 MSVC 构建中把
src/test/modules与contrib一起安装(Michael Paquier)原始发布条目 ·
9.5.0/changes/168把 PGFILEDESC 传入 MSVC contrib 构建 · 新功能
把
PGFILEDESC传入 MSVC contrib 构建(Michael Paquier)原始发布条目 ·
9.5.0/changes/170为所有 MSVC 构建的二进制文件添加图标,并为所有 MS Windows 二进制文件添加版本信息 · 新功能
为所有 MSVC 构建的二进制文件添加图标,并为所有 MS Windows 二进制文件添加版本信息(Noah Misch)
MinGW 此前已有此类图标。
原始发布条目 ·
9.5.0/changes/171为内部的 getopt_long() 实现添加可选参数支持 · 新功能
为内部的
getopt_long()实现添加可选参数支持(Michael Paquier、Andres Freund)这被 MSVC 构建使用。
原始发布条目 ·
9.5.0/changes/172为pg_stat_statements添加最小、最大、平均和标准差时间统计 · 新功能
为pg_stat_statements添加最小、最大、平均和标准差时间统计(Mitsumasa Kondo、Andrew Dunstan)
原始发布条目 ·
9.5.0/changes/173添加 contrib 模块tsm_system_rows和tsm_system_time,以提供更多的表采样方法 · 新功能
添加
contrib模块tsm_system_rows和tsm_system_time,以提供更多的表采样方法(Petr Jelínek)原始发布条目 ·
9.5.0/changes/177为pageinspect添加 GIN 索引检查函数 · 新功能
为pageinspect添加 GIN 索引检查函数(Heikki Linnakangas、Peter Geoghegan、Michael Paquier)
原始发布条目 ·
9.5.0/changes/178在pg_buffercache显示中添加有关缓冲区引脚的信息 · 新功能
在pg_buffercache显示中添加有关缓冲区引脚的信息(Andres Freund)
原始发布条目 ·
9.5.0/changes/179允许pgstattuple使用 pgstattuple_approx() 以更低的开销报告近似结果 · 新功能
允许pgstattuple使用
pgstattuple_approx()以更低的开销报告近似结果(Abhijit Menon-Sen)原始发布条目 ·
9.5.0/changes/180把 dummy_seclabel、test_shm_mq、test_parser 和 worker_spi 从 contrib 移到 src/test/modules · 新功能
把 dummy_seclabel、test_shm_mq、test_parser 和 worker_spi 从
contrib移到src/test/modules(Álvaro Herrera)这些模块仅用于服务器测试,因此在打包 PostgreSQL 时无需构建或安装它们。
原始发布条目 ·
9.5.0/changes/181
安全证据
共 33 条记录,来自官方安全矩阵及发布说明的提及。只有安全快照明确列出此分支时才显示修复版本;仅有提及不能确定漏洞适用性或新修复。
CVE-2020-25696 · psql's \gset allows overwriting specially treated variables · CVSS 7.5
The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:9.5.24。组件:client。
官方受影响分支记录:9.5。
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2020-25695 · Multiple features escape "security restricted operation" sandbox · CVSS 8.8
An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:9.5.24。组件:core server。
官方受影响分支记录:9.5。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2020-25694 · Reconnection can downgrade connection security settings · CVSS 8.1
Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:9.5.24。组件:client。
官方受影响分支记录:9.5。
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2020-14350 · Uncontrolled search path element in CREATE EXTENSION · CVSS 7.1
When a superuser runs certain CREATE EXTENSION statements, users may be able to execute arbitrary SQL functions under the identity of that superuser. The attacker must have permission to create objects in the new extension's schema or a schema of a prerequisite extension. Not all extensions are vulnerable. In addition to correcting the extensions provided with PostgreSQL, the PostgreSQL Global Development Group is issuing guidance for third-party extension authors to secure their own work. The PostgreSQL project thanks Andres Freund for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:9.5.23。组件:core server。
官方受影响分支记录:9.5。
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2020-10733 · Windows installer runs executables from uncontrolled directories · CVSS 6.7
The Windows installer for PostgreSQL invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. The PostgreSQL project thanks Hou JingYi (@hjy79425575) for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:9.5.22。组件:packaging。
官方受影响分支记录:9.5。
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVE-2019-3466 · pg_ctlcluster script in postgresql-common does not drop privileges when creating socket/statistics temporary directories · CVSS 8.4
A PostgreSQL superuser could escalate to root using a deficiency in the pg_ctlcluster command. pg_ctlcluster is a utility provided by the "postgresql-common" package that is installed with PostgreSQL on Debian and Ubuntu platforms.
以上保留官方英文漏洞说明。
本分支修复于:9.5.20。组件:packaging。
官方受影响分支记录:9.5。
AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CVE-2019-10211 · Windows installer bundled OpenSSL executes code from unprotected directory · CVSS 7.8
When the database server or libpq client library initializes SSL, libeay32.dll attempts to read configuration from a hard-coded directory. Typically, the directory does not exist, but any local user could create it and inject configuration. This configuration can direct OpenSSL to load and execute arbitrary code as the user running a PostgreSQL server or client. Most PostgreSQL client tools and libraries use libpq , and one can encounter this vulnerability by using any of them. This vulnerability is much like CVE-2019-5443 , but it originated independently. One can work around the vulnerability by setting environment variable OPENSSL_CONF to "NUL:/openssl.cnf" or any other name that cannot exist as a file. The PostgreSQL project thanks Daniel Gustafsson of the curl security team for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:9.5.19。组件:packaging。
官方受影响分支记录:9.5。
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2019-10210 · Windows installer writes superuser password to unprotected temporary file · CVSS 6.7
The EnterpriseDB Windows installer writes a password to a temporary file in its installation directory, creates initial databases, and deletes the file. During those seconds while the file exists, a local attacker can read the PostgreSQL superuser password from the file. The PostgreSQL project thanks Noah Misch for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:9.5.19。组件:packaging。
官方受影响分支记录:9.5。
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVE-2019-10208 · TYPE in pg_temp executes arbitrary SQL during SECURITY DEFINER execution · CVSS 7.5
Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function call having inexact argument type match. For example, length('foo'::varchar) and length('foo') are inexact, while length('foo'::text) is exact. As part of exploiting this vulnerability, the attacker uses CREATE DOMAIN to create a type in a pg_temp schema. The attack pattern and fix are similar to that for CVE-2007-2138 . Writing SECURITY DEFINER functions continues to require following the considerations noted in the documentation: https://www.postgresql.org/docs/current/sql-createfunction.html#SQL-CREATEFUNCTION-SECURITY The PostgreSQL project thanks Tom Lane for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:9.5.19。组件:core server。
官方受影响分支记录:9.5。
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2019-10130 · Selectivity estimators bypass row security policies · CVSS 3.1
PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user able to execute SQL queries with permissions to read a given column could craft a leaky operator that could read whatever data had been sampled from that column. If this happened to include values from rows that the user is forbidden to see by a row security policy, the user could effectively bypass the policy. This is fixed by only allowing a non-leakproof operator to use this data if there are no relevant row security policies for the table. The PostgreSQL project thanks Dean Rasheed for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:9.5.17。组件:core server。
官方受影响分支记录:9.5。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2019-10128 · EnterpriseDB Windows installer does not clear permissive ACL entries · CVSS 7.0
Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:9.5.17。组件:packaging。
官方受影响分支记录:9.5。
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2019-10127 · BigSQL Windows installer does not clear permissive ACL entries. · CVSS 7.0
Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:9.5.17。组件:packaging。
官方受影响分支记录:9.5。
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H