Skip to content

Commit 392c530

Browse files
committed
Last-minute updates for release notes.
Security: CVE-2021-3393, CVE-2021-20229
1 parent f50e888 commit 392c530

File tree

1 file changed

+25
-1
lines changed

1 file changed

+25
-1
lines changed

doc/src/sgml/release-12.sgml

Lines changed: 25 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@
2323
</para>
2424

2525
<para>
26-
However, see the first two changelog items below,
26+
However, see the second and third changelog items below,
2727
which describe cases in which reindexing indexes after the upgrade
2828
may be advisable.
2929
</para>
@@ -42,6 +42,30 @@
4242
<listitem>
4343
<!--
4444
Author: Heikki Linnakangas <heikki.linnakangas@iki.fi>
45+
Branch: master [6214e2b22] 2021-02-08 11:01:51 +0200
46+
Branch: REL_13_STABLE [8e56684d5] 2021-02-08 11:01:55 +0200
47+
Branch: REL_12_STABLE [f50e88899] 2021-02-08 11:01:55 +0200
48+
Branch: REL_11_STABLE [cb5868cc1] 2021-02-08 11:01:55 +0200
49+
-->
50+
<para>
51+
Fix information leakage in constraint-violation error messages
52+
(Heikki Linnakangas)
53+
</para>
54+
55+
<para>
56+
If an <command>UPDATE</command> command attempts to move a row to a
57+
different partition but finds that it violates some constraint on
58+
the new partition, and the columns in that partition are in
59+
different physical positions than in the parent table, the error
60+
message could reveal the contents of columns that the user does not
61+
have <literal>SELECT</literal> privilege on.
62+
(CVE-2021-3393)
63+
</para>
64+
</listitem>
65+
66+
<listitem>
67+
<!--
68+
Author: Heikki Linnakangas <heikki.linnakangas@iki.fi>
4569
Branch: master [6b4d3046f] 2021-01-20 11:58:03 +0200
4670
Branch: REL_13_STABLE [b8403d140] 2021-01-20 11:58:25 +0200
4771
Branch: REL_12_STABLE [0326635dd] 2021-01-20 11:58:27 +0200

0 commit comments

Comments
 (0)
pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy