From 613373b52b08dee01fad2f25162dd92486740c76 Mon Sep 17 00:00:00 2001 From: Tom Lane Date: Mon, 5 Nov 2018 10:48:23 -0500 Subject: [PATCH] Last-minute updates for release notes. Security: CVE-2018-16850 --- doc/src/sgml/release-10.sgml | 41 +++++++++++++++++++++++++++++------- 1 file changed, 33 insertions(+), 8 deletions(-) diff --git a/doc/src/sgml/release-10.sgml b/doc/src/sgml/release-10.sgml index 12e9df753cb..372307c250a 100644 --- a/doc/src/sgml/release-10.sgml +++ b/doc/src/sgml/release-10.sgml @@ -38,6 +38,20 @@ + + + Ensure proper quoting of transition table names + when pg_dump emits CREATE TRIGGER + ... REFERENCING commands (Tom Lane) + + + + This oversight could be exploited by an unprivileged user to gain + superuser privileges during the next dump/reload + or pg_upgrade run. (CVE-2018-16850) + + +