E.318. Release 7.2.7
Release date: 2005-01-31
This release contains a variety of fixes from 7.2.6, including several security-related issues.
E.318.1. Migration to Version 7.2.7
A dump/restore is not required for those running 7.2.X.
E.318.2. Changes
-
Disallow
LOAD
to non-superusersOn platforms that will automatically execute initialization functions of a shared library (this includes at least Windows and ELF-based Unixen),
LOAD
can be used to make the server execute arbitrary code. Thanks to NGS Software for reporting this. -
Add needed STRICT marking to some contrib functions (Kris Jurka)
-
Avoid buffer overrun when plpgsql cursor declaration has too many parameters (Neil)
-
Fix planning error for FULL and RIGHT outer joins
The result of the join was mistakenly supposed to be sorted the same as the left input. This could not only deliver mis-sorted output to the user, but in case of nested merge joins could give outright wrong answers.
-
Fix display of negative intervals in SQL and GERMAN datestyles