postgresql-8.4 (8.4.22-0ubuntu0.10.04) lucid-proposed; urgency=medium

  * New upstream bug fix release: (LP: #1348176)
    - Various data integrity and other bug fixes.
    - Secure Unix-domain sockets of temporary postmasters started during make
       check.
       Any local user able to access the socket file could connect as the
       server's bootstrap superuser, then proceed to execute arbitrary code as
       the operating-system user running the test, as we previously noted in
       CVE-2014-0067. This change defends against that risk by placing the
       server's socket in a temporary, mode 0700 subdirectory of /tmp.
    - See release notes for details:
      http://www.postgresql.org/docs/current/static/release-8-4-22.html
  * Drop pg_regress patch to run tests with socket in /tmp, obsolete with
    above upstream changes and not applicable any more.
  * Add debian/postgresql-8.4.NEWS to point out that upstream support ends
    now.

Date: 2014-07-30 09:18:09.343691+00:00
Changed-By: Martin Pitt <martin.p...@ubuntu.com>
Signed-By: Scott Kitterman <ubu...@kitterman.com>
https://launchpad.net/ubuntu/lucid/+source/postgresql-8.4/8.4.22-0ubuntu0.10.04
Sorry, changesfile not available.
-- 
Lucid-changes mailing list
Lucid-changes@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/lucid-changes

Reply via email to