From: Tom Lane Date: Mon, 5 Nov 2018 15:48:23 +0000 (-0500) Subject: Last-minute updates for release notes. X-Git-Tag: REL_10_6~3 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=613373b52b08dee01fad2f25162dd92486740c76;p=thirdparty%2Fpostgresql.git Last-minute updates for release notes. Security: CVE-2018-16850 --- diff --git a/doc/src/sgml/release-10.sgml b/doc/src/sgml/release-10.sgml index 12e9df753cb..372307c250a 100644 --- a/doc/src/sgml/release-10.sgml +++ b/doc/src/sgml/release-10.sgml @@ -38,6 +38,20 @@ + + + Ensure proper quoting of transition table names + when pg_dump emits CREATE TRIGGER + ... REFERENCING commands (Tom Lane) + + + + This oversight could be exploited by an unprivileged user to gain + superuser privileges during the next dump/reload + or pg_upgrade run. (CVE-2018-16850) + + +