E.236. Release 7.4.17
Release date: 2007-04-23
This release contains fixes from 7.4.16, including a security
fix. For information about new features in the 7.4 major
release, see Section E.253, « Release
7.4 ».
E.236.1. Migration to Version 7.4.17
A dump/restore is not required for those running 7.4.X.
However, if you are upgrading from a version earlier than
7.4.11, see Section E.242,
« Release 7.4.11 ».
E.236.2. Changes
-
Support explicit placement of the temporary-table
schema within search_path, and
disable searching it for functions and operators (Tom)
This is needed to allow a security-definer function to
set a truly secure value of search_path. Without it, an unprivileged
SQL user can use temporary objects to execute code with
the privileges of the security-definer function
(CVE-2007-2138). See CREATE FUNCTION for
more information.
-
/contrib/tsearch2 crash fixes
(Teodor)
-
Fix potential-data-corruption bug in how VACUUM FULL handles
UPDATE
chains (Tom, Pavan Deolasee)
-
Fix PANIC during enlargement of a hash index (bug
introduced in 7.4.15) (Tom)