summaryrefslogtreecommitdiff
path: root/databases/postgresql93-server/files/patch-src:backend:utils:misc:postgresql.conf.sample
diff options
context:
space:
mode:
authorPalle Girgensohn <girgen@FreeBSD.org>2014-02-20 18:11:25 +0000
committerPalle Girgensohn <girgen@FreeBSD.org>2014-02-20 18:11:25 +0000
commit083cb42200b7a3328d418c05862e21dd8a043f84 (patch)
tree698ff0b3f9a62f2406ff217b4ec4df3a30b9e4d4 /databases/postgresql93-server/files/patch-src:backend:utils:misc:postgresql.conf.sample
parent- Fix a duplicate LATEST_LINK by removing sysutils/liblogging and reviving de... (diff)
The PostgreSQL Global Development Group has released an important
update to all supported versions of the PostgreSQL database system, which includes minor versions 9.3.3, 9.2.7, 9.1.12, 9.0.16, and 8.4.20. This update contains fixes for multiple security issues, as well as several fixes for replication and data integrity issues. All users are urged to update their installations at the earliest opportunity, especially those using binary replication or running a high-security application. This update fixes CVE-2014-0060, in which PostgreSQL did not properly enforce the WITH ADMIN OPTION permission for ROLE management. Before this fix, any member of a ROLE was able to grant others access to the same ROLE regardless if the member was given the WITH ADMIN OPTION permission. It also fixes multiple privilege escalation issues, including: CVE-2014-0061, CVE-2014-0062, CVE-2014-0063, CVE-2014-0064, CVE-2014-0065, and CVE-2014-0066. More information on these issues can be found on our security page and the security issue detail wiki page. Security: CVE-2014-0060,CVE-2014-0061,CVE-2014-0062,CVE-2014-0063 CVE-2014-0064,CVE-2014-0065,CVE-2014-0066,CVE-2014-0067
Notes
Notes: svn path=/head/; revision=345256
Diffstat (limited to 'databases/postgresql93-server/files/patch-src:backend:utils:misc:postgresql.conf.sample')
0 files changed, 0 insertions, 0 deletions