PostgreSQL 11.1 Released To Address The Latest Open-Source Security Vulnerability
Written by Michael Larabel in Free Software on 8 November 2018 at 09:05 AM EST. 13 Comments
FREE SOFTWARE --
PostgreSQL 11.1 is out today with fixes over last month's PostgreSQL 11 introduction but there are also updates to the 10.6, 9.6, 9.4, 9.4, and 9.3 release streams due to a new security issue.

The security issue is CVE-2018-16850 that warrants the six new PostgreSQL point releases today. The security issue stems from a SQL injection issue with pg_upgrade/pg_dump that could lead to an attacker running arbitrary SQL statements with super-user privileges. Fortunately, the impact appears to be limited to when a super-user is running the PostgreSQL dump/upgrade commands. "Using a purpose-crafted trigger definition, an attacker can run arbitrary SQL statements with superuser privileges when a superuser runs pg_upgrade on the database or during a pg_dump dump/restore cycle. This attack requires a CREATE privilege on some non-temporary schema or a TRIGGER privilege on a table. This is exploitable in the default PostgreSQL configuration, where all users have CREATE privilege on public schema."

Besides this security fix, PostgreSQL 11.1 also has several other fixes, build improvements for macOS Mojave, Windows platform build fixes, and some crash fixes. If you missed the PostgreSQL 11.0 announcement from nearly a month ago, there are several improvements with this updated SQL database server release.

More details on the slew of PostgreSQL updates via PostgreSQL.org.
Related News
About The Author
Author picture

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter or contacted via MichaelLarabel.com.

Popular News This Week

çeviri malatya oto kiralama parça eşya taşıma şehirler arası nakliyat şehirlerarası evden eve nakliyat istanbul bursa şehirler arası nakliyat malatya oto kiralama istanbul evden eve nakliyat ofis taşıma ofis taşımacılığı evden eve nakliyat evden eve nakliyat büyü aşk büyüsü ayırma büyüsü medyum medyum şikayetleri medyum yorumları büyü aşk büyüsü bağlama büyüsü dua aşk duası aşk büyüsü büyü aşk büyüsü bağlama büyüsü medyum dolunay medyum aşk büyüsü medyum medyum şikayetleri medyum yorumları metal galvanizli sac paslanmaz sac metal hrp sac paslanmaz çelik mekjoy.com seo seo kursu sex shop istanbul sex shop ataşehir sex shop İstanbul evden eve nakliyat eşya depolama eşya depolama viagra fiyatı cialis fiyat b374k shell