Last-minute updates for release notes.
authorTom Lane
Mon, 5 Nov 2018 15:48:23 +0000 (10:48 -0500)
committerTom Lane
Mon, 5 Nov 2018 15:48:23 +0000 (10:48 -0500)
Security: CVE-2018-16850

doc/src/sgml/release-10.sgml

index 12e9df753cba7696142de72e15fada40dab63dae..372307c250a9a67f5f4d59fa287629fc9ae8226c 100644 (file)
 
    
 
+    
+     
+      Ensure proper quoting of transition table names
+      when pg_dump emits CREATE TRIGGER
+      ... REFERENCING commands (Tom Lane)
+     
+
+     
+      This oversight could be exploited by an unprivileged user to gain
+      superuser privileges during the next dump/reload
+      or pg_upgrade run.  (CVE-2018-16850)
+     
+    
+