1
0
mirror of https://github.com/postgres/postgres.git synced 2025-07-30 11:03:19 +03:00

Last-minute updates for release notes.

Security: CVE-2021-3393, CVE-2021-20229
This commit is contained in:
Tom Lane
2021-02-08 11:10:40 -05:00
parent f50e888990
commit 392c530d10

View File

@ -23,7 +23,7 @@
</para>
<para>
However, see the first two changelog items below,
However, see the second and third changelog items below,
which describe cases in which reindexing indexes after the upgrade
may be advisable.
</para>
@ -42,6 +42,30 @@
<listitem>
<!--
Author: Heikki Linnakangas <heikki.linnakangas@iki.fi>
Branch: master [6214e2b22] 2021-02-08 11:01:51 +0200
Branch: REL_13_STABLE [8e56684d5] 2021-02-08 11:01:55 +0200
Branch: REL_12_STABLE [f50e88899] 2021-02-08 11:01:55 +0200
Branch: REL_11_STABLE [cb5868cc1] 2021-02-08 11:01:55 +0200
-->
<para>
Fix information leakage in constraint-violation error messages
(Heikki Linnakangas)
</para>
<para>
If an <command>UPDATE</command> command attempts to move a row to a
different partition but finds that it violates some constraint on
the new partition, and the columns in that partition are in
different physical positions than in the parent table, the error
message could reveal the contents of columns that the user does not
have <literal>SELECT</literal> privilege on.
(CVE-2021-3393)
</para>
</listitem>
<listitem>
<!--
Author: Heikki Linnakangas <heikki.linnakangas@iki.fi>
Branch: master [6b4d3046f] 2021-01-20 11:58:03 +0200
Branch: REL_13_STABLE [b8403d140] 2021-01-20 11:58:25 +0200
Branch: REL_12_STABLE [0326635dd] 2021-01-20 11:58:27 +0200