↑↓ 选择 ↵ 打开 ⌫ 改范围 完整检索页

pgsql.cc 提供对 postgresql.org 官网内容的中文翻译,由 Pigsty 团队维护。

百科 / 版本发布

PostgreSQL 9.5

已停止支持 · 记录构建 9.5.25 · 2021-02-11

此大版本已停止支持,相关记录用于查阅历史;没有更新的安全记录不代表仍可安全运行。

首次正式发布
2016-01-07
支持结束
2021-02-11
已收录发布版本
26
原始发布说明条目
1026

手册与来源

PostgreSQL 9.5 本站手册 · 已加载 959 页。

手册加载时间:2026-09-27T00:10:45.258078。

发布说明快照:2026-09-26。安全证据快照:2026-09-26。PDF 链接按本地文件是否存在提供,历史版本的语言与 HTML 手册可能不同。生命周期参见官方版本政策。

升级注意事项

跨大版本升级需要导出/恢复或 pg_upgrade 等迁移方式,应阅读沿途大版本的发布说明与目标版本手册。小版本更新也可能要求额外操作,请核对对应发布的迁移说明。官方升级政策。

9.5.0 的兼容性变化 · 从首发到 9.5.25 的变化

9.5.0 的原始迁移说明

希望从任何之前的版本迁移数据的用户,需要使用pg_dumpall进行转储/恢复,或使用pg_upgrade。

版本 9.5 包含许多可能影响与以前版本兼容性的变更。请注意以下不兼容之处:

发布历史

每次发布的原始变更均独立保留。CVE 数量表示发布说明中的提及,可能包含后续纠正,不等于本次新修复漏洞数。

版本日期/快照截止时间全部变化BUG 修复迁移条目提及 CVE
9.5.25 2021-02-11 321500
9.5.24 2020-11-12 341003
9.5.23 2020-08-13 251102
9.5.22 2020-05-14 331400
9.5.21 2020-02-13 291600
9.5.20 2019-11-14 501900
9.5.19 2019-08-08 20702
9.5.18 2019-06-20 14800
9.5.17 2019-05-09 311802
9.5.16 2019-02-14 392200
9.5.15 2018-11-08 522500
9.5.14 2018-08-09 301402
9.5.13 2018-05-10 382000
9.5.12 2018-03-01 7401
9.5.11 2018-02-08 321801
9.5.10 2017-11-09 281403
9.5.9 2017-08-31 8200
9.5.8 2017-08-10 563004
9.5.7 2017-05-11 402304
9.5.6 2017-02-09 562900
9.5.5 2016-10-27 472200
9.5.4 2016-08-11 512302
9.5.3 2016-05-12 251400
9.5.2 2016-03-31 332002
9.5.1 2016-02-11 231202
9.5.0 2016-01-07 1931120

首次发布变化

9.5.0 的原始条目,包含功能和兼容性变化。类别用于浏览,不是上游原始分类。

匹配 193 / 193 条原始变更。

安全证据

共 33 条记录,来自官方安全矩阵及发布说明的提及。只有安全快照明确列出此分支时才显示修复版本;仅有提及不能确定漏洞适用性或新修复。

CVE-2020-25696 · psql's \gset allows overwriting specially treated variables · CVSS 7.5

The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.5.24。组件:client。

官方受影响分支记录:9.5。

AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2020-25695 · Multiple features escape "security restricted operation" sandbox · CVSS 8.8

An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.5.24。组件:core server。

官方受影响分支记录:9.5。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2020-25694 · Reconnection can downgrade connection security settings · CVSS 8.1

Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.5.24。组件:client。

官方受影响分支记录:9.5。

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2020-14350 · Uncontrolled search path element in CREATE EXTENSION · CVSS 7.1

When a superuser runs certain CREATE EXTENSION statements, users may be able to execute arbitrary SQL functions under the identity of that superuser. The attacker must have permission to create objects in the new extension's schema or a schema of a prerequisite extension. Not all extensions are vulnerable. In addition to correcting the extensions provided with PostgreSQL, the PostgreSQL Global Development Group is issuing guidance for third-party extension authors to secure their own work. The PostgreSQL project thanks Andres Freund for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.5.23。组件:core server。

官方受影响分支记录:9.5。

AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2020-10733 · Windows installer runs executables from uncontrolled directories · CVSS 6.7

The Windows installer for PostgreSQL invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. The PostgreSQL project thanks Hou JingYi (@hjy79425575) for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.5.22。组件:packaging。

官方受影响分支记录:9.5。

AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVE-2019-3466 · pg_ctlcluster script in postgresql-common does not drop privileges when creating socket/statistics temporary directories · CVSS 8.4

A PostgreSQL superuser could escalate to root using a deficiency in the pg_ctlcluster command. pg_ctlcluster is a utility provided by the "postgresql-common" package that is installed with PostgreSQL on Debian and Ubuntu platforms.

以上保留官方英文漏洞说明。

本分支修复于:9.5.20。组件:packaging。

官方受影响分支记录:9.5。

AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

CVE-2019-10211 · Windows installer bundled OpenSSL executes code from unprotected directory · CVSS 7.8

When the database server or libpq client library initializes SSL, libeay32.dll attempts to read configuration from a hard-coded directory. Typically, the directory does not exist, but any local user could create it and inject configuration. This configuration can direct OpenSSL to load and execute arbitrary code as the user running a PostgreSQL server or client. Most PostgreSQL client tools and libraries use libpq , and one can encounter this vulnerability by using any of them. This vulnerability is much like CVE-2019-5443 , but it originated independently. One can work around the vulnerability by setting environment variable OPENSSL_CONF to "NUL:/openssl.cnf" or any other name that cannot exist as a file. The PostgreSQL project thanks Daniel Gustafsson of the curl security team for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.5.19。组件:packaging。

官方受影响分支记录:9.5。

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2019-10210 · Windows installer writes superuser password to unprotected temporary file · CVSS 6.7

The EnterpriseDB Windows installer writes a password to a temporary file in its installation directory, creates initial databases, and deletes the file. During those seconds while the file exists, a local attacker can read the PostgreSQL superuser password from the file. The PostgreSQL project thanks Noah Misch for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.5.19。组件:packaging。

官方受影响分支记录:9.5。

AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVE-2019-10208 · TYPE in pg_temp executes arbitrary SQL during SECURITY DEFINER execution · CVSS 7.5

Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function call having inexact argument type match. For example, length('foo'::varchar) and length('foo') are inexact, while length('foo'::text) is exact. As part of exploiting this vulnerability, the attacker uses CREATE DOMAIN to create a type in a pg_temp schema. The attack pattern and fix are similar to that for CVE-2007-2138 . Writing SECURITY DEFINER functions continues to require following the considerations noted in the documentation: https://www.postgresql.org/docs/current/sql-createfunction.html#SQL-CREATEFUNCTION-SECURITY The PostgreSQL project thanks Tom Lane for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.5.19。组件:core server。

官方受影响分支记录:9.5。

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2019-10130 · Selectivity estimators bypass row security policies · CVSS 3.1

PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user able to execute SQL queries with permissions to read a given column could craft a leaky operator that could read whatever data had been sampled from that column. If this happened to include values from rows that the user is forbidden to see by a row security policy, the user could effectively bypass the policy. This is fixed by only allowing a non-leakproof operator to use this data if there are no relevant row security policies for the table. The PostgreSQL project thanks Dean Rasheed for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.5.17。组件:core server。

官方受影响分支记录:9.5。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2019-10128 · EnterpriseDB Windows installer does not clear permissive ACL entries · CVSS 7.0

Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.5.17。组件:packaging。

官方受影响分支记录:9.5。

AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2019-10127 · BigSQL Windows installer does not clear permissive ACL entries. · CVSS 7.0

Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.

以上保留官方英文漏洞说明。

本分支修复于:9.5.17。组件:packaging。

官方受影响分支记录:9.5。

AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2018-10925 · Memory disclosure and missing authorization in INSERT ... ON CONFLICT DO UPDATE. · CVSS 7.1

本分支修复于:9.5.14。组件:core server。

官方受影响分支记录:9.5。

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

发布说明中的提及:

CVE-2018-10915 · Certain host connection parameters defeat client-side security defenses · CVSS 8.5

本分支修复于:9.5.14。组件:client。

官方受影响分支记录:9.5。

AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

发布说明中的提及:

CVE-2018-1058 · Uncontrolled search path element in pg_dump and other client applications · CVSS 8.8
CVE-2018-1053 · pg_upgrade creates file of sensitive metadata under prevailing umask · CVSS 6.7

本分支修复于:9.5.11。组件:client。

官方受影响分支记录:9.5。

AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2017-7548 · lo_put() function ignores ACLs · CVSS 3.1

本分支修复于:9.5.8。组件:core server。

官方受影响分支记录:9.5。

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

发布说明中的提及:

CVE-2017-7547 · pg_user_mappings view discloses passwords to users lacking server privileges · CVSS 8.5
CVE-2017-7546 · empty password accepted in some authentication methods · CVSS 8.1

本分支修复于:9.5.8。组件:core server。

官方受影响分支记录:9.5。

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2017-7486 · pg_user_mappings view discloses foreign server passwords · CVSS 8.5
CVE-2017-7485 · libpq ignores PGREQUIRESSL environment variable · CVSS 8.1

本分支修复于:9.5.7。组件:client。

官方受影响分支记录:9.5。

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

发布说明中的提及:

CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks · CVSS 4.3

本分支修复于:9.5.7。组件:core server。

官方受影响分支记录:9.5。

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2017-15099 · INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges · CVSS 3.1

本分支修复于:9.5.10。组件:core server。

官方受影响分支记录:9.5。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2017-15098 · Memory disclosure in JSON functions · CVSS 4.3

本分支修复于:9.5.10。组件:core server。

官方受影响分支记录:9.5。

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2017-12172 · Start scripts permit database administrator to modify root-owned files · CVSS 8.4

本分支修复于:9.5.10。组件:contrib module。

官方受影响分支记录:9.5。

AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

发布说明中的提及:

CVE-2016-7048 · Interactive installer downloads software over plain HTTP, then executes it · CVSS 7.5

本分支修复于:9.5.5。组件:packaging。

官方受影响分支记录:9.5。

AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2016-5424 · Exceptional database and role names could enable escalation to superuser · CVSS 8.5

本分支修复于:9.5.4。组件:client。

官方受影响分支记录:9.5。

AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

发布说明中的提及:

CVE-2016-5423 · Certain nested CASE/WHEN expressions can crash server · CVSS 4.3

本分支修复于:9.5.4。组件:core server。

官方受影响分支记录:9.5。

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2016-3065 · pageinspect does not check permissions for BRIN indexes · CVSS 3.1

本分支修复于:9.5.2。组件:contrib module。

官方受影响分支记录:9.5。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

发布说明中的提及:

CVE-2016-2193 · Plan cache might use wrong role context for RLS policy · CVSS 4.2

本分支修复于:9.5.2。组件:core server。

官方受影响分支记录:9.5。

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

发布说明中的提及:

CVE-2016-0773 · Unchecked regex can crash the server · CVSS 6.5

本分支修复于:9.5.1。组件:core server。

官方受影响分支记录:9.5。

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

发布说明中的提及:

CVE-2016-0766 · CVE-2016-0766

尚未记录本分支的修复版本。

发布说明中的提及:

CVE-2007-2138 · A vulnerability involving insecure search_path settings allows unprivileged users to gain the SQL privileges of the owner of any SECURITY DEFINER function they are allowed to call. Securing such a function requires both a software update and changes to the function definition.

尚未记录本分支的修复版本。

发布说明中的提及:

导出此分支 JSON · 比较已收录的发布版本