E.294. Release 7.4.17
Release date: 2007-04-23
This release contains fixes from 7.4.16, including a security fix. For information about new features in the 7.4 major release, see Section E.311 .
E.294.1. Migration to Version 7.4.17
A dump/restore is not required for those running 7.4.X. However, if you are upgrading from a version earlier than 7.4.11, see Section E.300 .
E.294.2. Changes
-
Support explicit placement of the temporary-table schema within
search_path
, and disable searching it for functions and operators (Tom)This is needed to allow a security-definer function to set a truly secure value of
search_path
. Without it, an unprivileged SQL user can use temporary objects to execute code with the privileges of the security-definer function (CVE-2007-2138). SeeCREATE FUNCTION
for more information. -
/contrib/tsearch2
crash fixes (Teodor) -
Fix potential-data-corruption bug in how
VACUUM FULL
handlesUPDATE
chains (Tom, Pavan Deolasee) -
Fix PANIC during enlargement of a hash index (bug introduced in 7.4.15) (Tom)