~ubuntu-branches/ubuntu/vivid/postgresql-9.4/vivid-updates

« back to all changes in this revision

Viewing changes to doc/src/sgml/html/release-9-0-12.html

  • Committer: Package Import Robot
  • Author(s): Martin Pitt
  • Date: 2015-10-08 15:36:31 UTC
  • mfrom: (1.2.3) (11.1.2 vivid-proposed)
  • Revision ID: package-import@ubuntu.com-20151008153631-dyiutwil2zjh9pxs
Tags: 9.4.5-0ubuntu0.15.04
* New upstream security/bug fix release: (LP: #1504132)
  - Guard against stack overflows in json parsing.
    If an application constructs PostgreSQL json or jsonb values from
    arbitrary user input, the application's users can reliably crash the
    PostgreSQL server, causing momentary denial of service.  (CVE-2015-5289)

  - Fix contrib/pgcrypto to detect and report too-short crypt() salts
    Certain invalid salt arguments crashed the server or disclosed a few
    bytes of server memory.  We have not ruled out the viability of attacks
    that arrange for presence of confidential information in the disclosed
    bytes, but they seem unlikely.  (CVE-2015-5288)

  - See release notes for details about other fixes.

Show diffs side-by-side

added added

removed removed

Lines of Context:
9
9
REV="MADE"
10
10
HREF="mailto:pgsql-docs@postgresql.org"><LINK
11
11
REL="HOME"
12
 
TITLE="PostgreSQL 9.4.2 Documentation"
 
12
TITLE="PostgreSQL 9.4.5 Documentation"
13
13
HREF="index.html"><LINK
14
14
REL="UP"
15
15
TITLE="Release Notes"
26
26
HTTP-EQUIV="Content-Type"
27
27
CONTENT="text/html; charset=ISO-8859-1"><META
28
28
NAME="creation"
29
 
CONTENT="2015-05-19T23:16:15"></HEAD
 
29
CONTENT="2015-10-05T19:28:19"></HEAD
30
30
><BODY
31
31
CLASS="SECT1"
32
32
><DIV
44
44
VALIGN="bottom"
45
45
><A
46
46
HREF="index.html"
47
 
>PostgreSQL 9.4.2 Documentation</A
 
47
>PostgreSQL 9.4.5 Documentation</A
48
48
></TH
49
49
></TR
50
50
><TR
93
93
CLASS="SECT1"
94
94
><A
95
95
NAME="RELEASE-9-0-12"
96
 
>E.49. Release 9.0.12</A
 
96
>E.64. Release 9.0.12</A
97
97
></H1
98
98
><DIV
99
99
CLASS="NOTE"
110
110
   For information about new features in the 9.0 major release, see
111
111
   <A
112
112
HREF="release-9-0.html"
113
 
>Section E.61</A
 
113
>Section E.76</A
114
114
>.
115
115
  </P
116
116
><DIV
118
118
><H2
119
119
CLASS="SECT2"
120
120
><A
121
 
NAME="AEN131386"
122
 
>E.49.1. Migration to Version 9.0.12</A
 
121
NAME="AEN133049"
 
122
>E.64.1. Migration to Version 9.0.12</A
123
123
></H2
124
124
><P
125
125
>    A dump/restore is not required for those running 9.0.X.
128
128
>    However, if you are upgrading from a version earlier than 9.0.6,
129
129
    see <A
130
130
HREF="release-9-0-6.html"
131
 
>Section E.55</A
 
131
>Section E.70</A
132
132
>.
133
133
   </P
134
134
></DIV
137
137
><H2
138
138
CLASS="SECT2"
139
139
><A
140
 
NAME="AEN131391"
141
 
>E.49.2. Changes</A
 
140
NAME="AEN133054"
 
141
>E.64.2. Changes</A
142
142
></H2
143
143
><P
144
144
></P