Univention Bugzilla – Bug 46620
postgresql-9.6: Multiple issues (4.3)
Last modified: 2018-05-16 17:04:00 CEST
New Debian postgresql-9.6 9.6.7-0+deb9u1 fixes: This update addresses the following issues: * Ensure that all temporary files made by pg_upgrade are non-world-readable (CVE-2018-1053) * Change the behavior of contrib/cube's cube ~> int operator to make it compatible with KNN search. The meaning of the second argument (the dimension selector) has been changed to make it predictable which value is selected even when dealing with cubes of varying dimensionalities. This is an incompatible change, but since the point of the operator was to be used in KNN searches, it seems rather useless as-is. After installing this update, any expression indexes or materialized views using this operator will need to be reindexed/refreshed. CVE-2018-1053 postgresql: pg_upgrade creates file of sensitive metadata under prevailing umask
[4.3-0] 796e07c3cb Bug #46620: postgresql-9.6_9.6.7-0+deb9u1
--- mirror/ftp/4.3/unmaintained/4.3-0/source/postgresql-9.6_9.6.6-0+deb9u1.dsc +++ apt/ucs_4.3-0-errata4.3-0/source/postgresql-9.6_9.6.7-0+deb9u1.dsc @@ -1,3 +1,21 @@ +9.6.7-0+deb9u1 [Wed, 07 Feb 2018 15:01:25 +0100] Christoph Berg <christoph.berg@credativ.de>: + + * New upstream version. + + Ensure that all temporary files made by pg_upgrade are + non-world-readable (CVE-2018-1053) + + + Change the behavior of contrib/cube's cube ~> int operator to make it + compatible with KNN search. + + The meaning of the second argument (the dimension selector) has been + changed to make it predictable which value is selected even when + dealing with cubes of varying dimensionalities. + + This is an incompatible change, but since the point of the operator + was to be used in KNN searches, it seems rather useless as-is. + After installing this update, any expression indexes or materialized + views using this operator will need to be reindexed/refreshed. + 9.6.6-0+deb9u1 [Wed, 08 Nov 2017 10:40:59 +0100] Christoph Berg <christoph.berg@credativ.de>: * New upstream version.
* No UCS specific patches * Comparison to previously shipped version ok * Binary package update Ok * Advisory Ok
<http://errata.software-univention.de/ucs/4.3/69.html>