From: Tom Lane Date: Mon, 10 Feb 2020 17:51:07 +0000 (-0500) Subject: Last-minute updates for release notes. X-Git-Tag: REL_10_12~1 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=27cfad5c8630428f7a2f63fd53b2e4a4fb248a90;p=thirdparty%2Fpostgresql.git Last-minute updates for release notes. Security: CVE-2020-1720 --- diff --git a/doc/src/sgml/release-10.sgml b/doc/src/sgml/release-10.sgml index e4d60b3dd72..9556e38e322 100644 --- a/doc/src/sgml/release-10.sgml +++ b/doc/src/sgml/release-10.sgml @@ -35,6 +35,30 @@ + + Add missing permissions checks for ALTER ... DEPENDS ON + EXTENSION (Álvaro Herrera) + + + + Marking an object as dependent on an extension did not have any + privilege check whatsoever. This oversight allowed any user to mark + routines, triggers, materialized views, or indexes as droppable by + anyone able to drop an extension. Require that the calling user own + the specified object (and hence have privilege to drop it). + (CVE-2020-1720) + + + + + + + Apply more thorough syntax checking + to createuser's + option (Álvaro Herrera) + + + + +