PostgreSQL 9.3
Read the English manualEnd of life · Recorded build 9.3.25 · 2018-11-08
This major branch is no longer supported. These records describe its history; the absence of newer security records does not establish that it is safe to run.
- First stable release
- 2013-09-09
- Support end
- 2018-11-08
- Indexed releases
- 26
- Original release-note entries
- 968
Manuals & provenance
PostgreSQL 9.3 English manual · 1265 loaded pages.
Manual loaded 2026-09-27T00:10:47.078613.
Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.
Upgrade considerations
Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.
Compatibility notes for 9.3.0 · Changes from the initial release through 9.3.25
Original migration guidance for 9.3.0
A dump/restore using pg_dumpall, or use of pg_upgrade, is required for those wishing to migrate data from any previous release.
Version 9.3 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:
Release history
Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.
| Release | Date / snapshot cutoff | All changes | Bug fixes | Migration entries | CVE mentions |
|---|---|---|---|---|---|
| 9.3.25 | 2018-11-08 | 35 | 17 | 0 | 0 |
| 9.3.24 | 2018-08-09 | 21 | 10 | 0 | 1 |
| 9.3.23 | 2018-05-10 | 27 | 12 | 0 | 0 |
| 9.3.22 | 2018-03-01 | 7 | 4 | 0 | 1 |
| 9.3.21 | 2018-02-08 | 24 | 13 | 0 | 1 |
| 9.3.20 | 2017-11-09 | 17 | 7 | 0 | 2 |
| 9.3.19 | 2017-08-31 | 7 | 1 | 0 | 0 |
| 9.3.18 | 2017-08-10 | 41 | 22 | 0 | 3 |
| 9.3.17 | 2017-05-11 | 28 | 14 | 0 | 4 |
| 9.3.16 | 2017-02-09 | 37 | 14 | 0 | 0 |
| 9.3.15 | 2016-10-27 | 22 | 12 | 0 | 0 |
| 9.3.14 | 2016-08-11 | 36 | 12 | 0 | 2 |
| 9.3.13 | 2016-05-12 | 16 | 8 | 0 | 0 |
| 9.3.12 | 2016-03-31 | 18 | 9 | 0 | 0 |
| 9.3.11 | 2016-02-11 | 56 | 24 | 0 | 4 |
| 9.3.10 | 2015-10-08 | 62 | 33 | 0 | 2 |
| 9.3.9 | 2015-06-12 | 4 | 3 | 0 | 0 |
| 9.3.8 | 2015-06-04 | 4 | 2 | 0 | 0 |
| 9.3.7 | 2015-05-22 | 47 | 18 | 0 | 3 |
| 9.3.6 | 2015-02-05 | 90 | 45 | 0 | 6 |
| 9.3.5 | 2014-07-24 | 54 | 29 | 0 | 1 |
| 9.3.4 | 2014-03-20 | 21 | 8 | 0 | 0 |
| 9.3.3 | 2014-02-20 | 71 | 33 | 0 | 8 |
| 9.3.2 | 2013-12-05 | 38 | 24 | 0 | 0 |
| 9.3.1 | 2013-10-10 | 8 | 5 | 0 | 0 |
| 9.3.0 | 2013-09-09 | 177 | 6 | 10 | 0 |
Initial release changes
Original entries from 9.3.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.
177 of 177 original entries.
Rename replication_timeout to wal_sender_timeout Compatibility Migration
Rename replication_timeout to wal_sender_timeout (Amit Kapila)
This setting controls the WAL sender timeout.
Original release occurrence ·
9.3.0/migration/001Require superuser privileges to set commit_delay because it can now potentially delay other sessions Compatibility Migration
Require superuser privileges to set commit_delay because it can now potentially delay other sessions (Simon Riggs)
Original release occurrence ·
9.3.0/migration/002Allow in-memory sorts to use their full memory allocation Compatibility Migration
Allow in-memory sorts to use their full memory allocation (Jeff Janes)
Users who have set work_mem based on the previous behavior may need to revisit that setting.
Original release occurrence ·
9.3.0/migration/003Throw an error if a tuple to be updated or deleted has already been updated or deleted by a BEFORE trigger Compatibility Migration
Throw an error if a tuple to be updated or deleted has already been updated or deleted by a BEFORE trigger (Kevin Grittner)
Formerly, the originally-intended update was silently skipped, resulting in logical inconsistency since the trigger might have propagated data to other places based on the intended update. Now an error is thrown to prevent the inconsistent results from being committed. If this change affects your application, the best solution is usually to move the data-propagation actions to an AFTER trigger.
This error will also be thrown if a query invokes a volatile function that modifies rows that are later modified by the query itself. Such cases likewise previously resulted in silently skipping updates.
Original release occurrence ·
9.3.0/migration/004Change multicolumn ON UPDATE SET NULL/SET DEFAULT foreign key actions to affect all columns of the constraint, not just those changed in the UPDATE Compatibility Migration
Change multicolumn ON UPDATE SET NULL/SET DEFAULT foreign key actions to affect all columns of the constraint, not just those changed in the UPDATE (Tom Lane)
Previously, we would set only those referencing columns that correspond to referenced columns that were changed by the UPDATE. This was what was required by SQL-92, but more recent editions of the SQL standard specify the new behavior.
Original release occurrence ·
9.3.0/migration/005Force cached plans to be replanned if the search_path changes Compatibility Migration
Force cached plans to be replanned if the search_path changes (Tom Lane)
Previously, cached plans already generated in the current session were not redone if the query was re-executed with a new search_path setting, resulting in surprising behavior.
Original release occurrence ·
9.3.0/migration/006Fix to_number() to properly handle a period used as a thousands separator Compatibility Migration
Fix
to_number()to properly handle a period used as a thousands separator (Tom Lane)Previously, a period was considered to be a decimal point even when the locale says it isn't and the D format code is used to specify use of the locale-specific decimal point. This resulted in wrong answers if FM format was also used.
Original release occurrence ·
9.3.0/migration/007Fix STRICT non-set-returning functions that have set-returning functions in their arguments to properly return null rows Compatibility Migration
Fix STRICT non-set-returning functions that have set-returning functions in their arguments to properly return null rows (Tom Lane)
A null value passed to the strict function should result in a null output, but instead, that output row was suppressed entirely.
Original release occurrence ·
9.3.0/migration/008Store WAL in a continuous stream, rather than skipping the last 16MB segment every 4GB Compatibility Migration
Store WAL in a continuous stream, rather than skipping the last 16MB segment every 4GB (Heikki Linnakangas)
Previously, WAL files with names ending in FF were not used because of this skipping. If you have WAL backup or restore scripts that took this behavior into account, they will need to be adjusted.
Original release occurrence ·
9.3.0/migration/009In pg_constraint.confmatchtype, store the default foreign key match type (non-FULL, non-PARTIAL) as s for "simple" Compatibility Migration
In pg_constraint.confmatchtype, store the default foreign key match type (non-FULL, non-PARTIAL) as s for "simple" (Tom Lane)
Previously this case was represented by u for "unspecified".
Original release occurrence ·
9.3.0/migration/010Prevent non-key-field row updates from blocking foreign key checks Features
Prevent non-key-field row updates from blocking foreign key checks (Álvaro Herrera, Noah Misch, Andres Freund, Alexander Shulgin, Marti Raudsepp, Alexander Shulgin)
This change improves concurrency and reduces the probability of deadlocks when updating tables involved in a foreign-key constraint. UPDATEs that do not change any columns referenced in a foreign key now take the new NO KEY UPDATE lock mode on the row, while foreign key checks use the new KEY SHARE lock mode, which does not conflict with NO KEY UPDATE. So there is no blocking unless a foreign-key column is changed.
Original release occurrence ·
9.3.0/changes/001Add configuration variable lock_timeout to allow limiting how long a session will wait to acquire any one lock Features
Add configuration variable lock_timeout to allow limiting how long a session will wait to acquire any one lock (Zoltán Böszörményi)
Original release occurrence ·
9.3.0/changes/002Add SP-GiST support for range data types Features
Add SP-GiST support for range data types (Alexander Korotkov)
Original release occurrence ·
9.3.0/changes/003Allow GiST indexes to be unlogged Features
Allow GiST indexes to be unlogged (Jeevan Chalke)
Original release occurrence ·
9.3.0/changes/004Improve performance of GiST index insertion by randomizing the choice of which page to descend to when there are multiple equally good alternatives Performance
Improve performance of GiST index insertion by randomizing the choice of which page to descend to when there are multiple equally good alternatives (Heikki Linnakangas)
Original release occurrence ·
9.3.0/changes/005Improve concurrency of hash index operations Features
Improve concurrency of hash index operations (Robert Haas)
Original release occurrence ·
9.3.0/changes/006Collect and use histograms of upper and lower bounds, as well as range lengths, for range types Features
Collect and use histograms of upper and lower bounds, as well as range lengths, for range types (Alexander Korotkov)
Original release occurrence ·
9.3.0/changes/007Improve optimizer's cost estimation for index access Features
Improve optimizer's cost estimation for index access (Tom Lane)
Original release occurrence ·
9.3.0/changes/008Improve optimizer's hash table size estimate for doing DISTINCT via hash aggregation Features
Improve optimizer's hash table size estimate for doing DISTINCT via hash aggregation (Tom Lane)
Original release occurrence ·
9.3.0/changes/009Suppress no-op Result and Limit plan nodes Features
Suppress no-op Result and Limit plan nodes (Kyotaro Horiguchi, Amit Kapila, Tom Lane)
Original release occurrence ·
9.3.0/changes/010Reduce optimizer overhead by not keeping plans on the basis of cheap startup cost when the optimizer only cares about total cost overall Performance
Reduce optimizer overhead by not keeping plans on the basis of cheap startup cost when the optimizer only cares about total cost overall (Tom Lane)
Original release occurrence ·
9.3.0/changes/011Add COPY FREEZE option to avoid the overhead of marking tuples as frozen later Performance
Add COPY FREEZE option to avoid the overhead of marking tuples as frozen later (Simon Riggs, Jeff Davis)
Original release occurrence ·
9.3.0/changes/012Improve performance of NUMERIC calculations Performance
Improve performance of NUMERIC calculations (Kyotaro Horiguchi)
Original release occurrence ·
9.3.0/changes/013Improve synchronization of sessions waiting for commit_delay Performance
Improve synchronization of sessions waiting for commit_delay (Peter Geoghegan)
This greatly improves the usefulness of commit_delay.
Original release occurrence ·
9.3.0/changes/014Improve performance of the CREATE TEMPORARY TABLE ... ON COMMIT DELETE ROWS option by not truncating such temporary tables in transactions that haven't touched any temporary tables Performance
Improve performance of the CREATE TEMPORARY TABLE ... ON COMMIT DELETE ROWS option by not truncating such temporary tables in transactions that haven't touched any temporary tables (Heikki Linnakangas)
Original release occurrence ·
9.3.0/changes/015Make vacuum recheck visibility after it has removed expired tuples Performance
Make vacuum recheck visibility after it has removed expired tuples (Pavan Deolasee)
This increases the chance of a page being marked as all-visible.
Original release occurrence ·
9.3.0/changes/016Add per-resource-owner lock caches Performance
Add per-resource-owner lock caches (Jeff Janes)
This speeds up lock bookkeeping at statement completion in multi-statement transactions that hold many locks; it is particularly useful for pg_dump.
Original release occurrence ·
9.3.0/changes/017Avoid scanning the entire relation cache at commit of a transaction that creates a new relation Performance
Avoid scanning the entire relation cache at commit of a transaction that creates a new relation (Jeff Janes)
This speeds up sessions that create many tables in successive small transactions, such as a pg_restore run.
Original release occurrence ·
9.3.0/changes/018Improve performance of transactions that drop many relations Performance
Improve performance of transactions that drop many relations (Tomas Vondra)
Original release occurrence ·
9.3.0/changes/019Add optional ability to checksum data pages and report corruption Features
Add optional ability to checksum data pages and report corruption (Simon Riggs, Jeff Davis, Greg Smith, Ants Aasma)
The checksum option can be set during initdb.
Original release occurrence ·
9.3.0/changes/020Split the statistics collector's data file into separate global and per-database files Features
Split the statistics collector's data file into separate global and per-database files (Tomas Vondra)
This reduces the I/O required for statistics tracking.
Original release occurrence ·
9.3.0/changes/021Fix the statistics collector to operate properly in cases where the system clock goes backwards Bug fixes
Fix the statistics collector to operate properly in cases where the system clock goes backwards (Tom Lane)
Previously, statistics collection would stop until the time again reached the latest time previously recorded.
Original release occurrence ·
9.3.0/changes/022Emit an informative message to postmaster standard error when we are about to stop logging there Features
Emit an informative message to postmaster standard error when we are about to stop logging there (Tom Lane)
This should help reduce user confusion about where to look for log output in common configurations that log to standard error only during postmaster startup.
Original release occurrence ·
9.3.0/changes/023When an authentication failure occurs, log the relevant pg_hba.conf line, to ease debugging of unintended failures Features
When an authentication failure occurs, log the relevant pg_hba.conf line, to ease debugging of unintended failures (Magnus Hagander)
Original release occurrence ·
9.3.0/changes/024Improve LDAP error reporting and documentation Features
Improve LDAP error reporting and documentation (Peter Eisentraut)
Original release occurrence ·
9.3.0/changes/025Add support for specifying LDAP authentication parameters in URL format, per RFC 4516 Features
Add support for specifying LDAP authentication parameters in URL format, per RFC 4516 (Peter Eisentraut)
Original release occurrence ·
9.3.0/changes/026Change the ssl_ciphers parameter to start with DEFAULT, rather than ALL, then remove insecure ciphers Features
Change the ssl_ciphers parameter to start with DEFAULT, rather than ALL, then remove insecure ciphers (Magnus Hagander)
This should yield a more appropriate SSL cipher set.
Original release occurrence ·
9.3.0/changes/027Parse and load pg_ident.conf once, not during each connection Features
Parse and load pg_ident.conf once, not during each connection (Amit Kapila)
This is similar to how pg_hba.conf is processed.
Original release occurrence ·
9.3.0/changes/028Greatly reduce System V shared memory requirements Features
Greatly reduce System V shared memory requirements (Robert Haas)
On Unix-like systems,
mmap()is now used for most of PostgreSQL's shared memory. For most users, this will eliminate any need to adjust kernel parameters for shared memory.Original release occurrence ·
9.3.0/changes/029Allow the postmaster to listen on multiple Unix-domain sockets Features
Allow the postmaster to listen on multiple Unix-domain sockets (Honza Horák)
The configuration parameter unix_socket_directory is replaced by unix_socket_directories, which accepts a list of directories.
Original release occurrence ·
9.3.0/changes/030Allow a directory of configuration files to be processed Features
Allow a directory of configuration files to be processed (Magnus Hagander, Greg Smith, Selena Deckelmann)
Such a directory is specified with include_dir in the server configuration file.
Original release occurrence ·
9.3.0/changes/031Increase the maximum initdb-configured value for shared_buffers to 128MB Features
Increase the maximum initdb-configured value for shared_buffers to 128MB (Robert Haas)
This is the maximum value that initdb will attempt to set in postgresql.conf; the previous maximum was 32MB.
Original release occurrence ·
9.3.0/changes/032Remove the external PID file, if any, on postmaster exit Features
Remove the external PID file, if any, on postmaster exit (Peter Eisentraut)
Original release occurrence ·
9.3.0/changes/033Allow a streaming replication standby to follow a timeline switch Features
Allow a streaming replication standby to follow a timeline switch (Heikki Linnakangas)
This allows streaming standby servers to receive WAL data from a slave newly promoted to master status. Previously, other standbys would require a resync to begin following the new master.
Original release occurrence ·
9.3.0/changes/034Add SQL functions pg_is_in_backup() and pg_backup_start_time() Features
Add SQL functions
pg_is_in_backup()andpg_backup_start_time()(Gilles Darold)These functions report the status of base backups.
Original release occurrence ·
9.3.0/changes/035Improve performance of streaming log shipping with synchronous_commit disabled Performance
Improve performance of streaming log shipping with synchronous_commit disabled (Andres Freund)
Original release occurrence ·
9.3.0/changes/036Allow much faster promotion of a streaming standby to primary Performance
Allow much faster promotion of a streaming standby to primary (Simon Riggs, Kyotaro Horiguchi)
Original release occurrence ·
9.3.0/changes/037Add the last checkpoint's redo location to pg_controldata's output Features
Add the last checkpoint's redo location to pg_controldata's output (Fujii Masao)
This information is useful for determining which WAL files are needed for restore.
Original release occurrence ·
9.3.0/changes/038Allow tools like pg_receivexlog to run on computers with different architectures Features
Allow tools like pg_receivexlog to run on computers with different architectures (Heikki Linnakangas)
WAL files can still only be replayed on servers with the same architecture as the primary; but they can now be transmitted to and stored on machines of any architecture, since the streaming replication protocol is now machine-independent.
Original release occurrence ·
9.3.0/changes/039Make pg_basebackup --write-recovery-conf output a minimal recovery.conf file Features
Make pg_basebackup --write-recovery-conf output a minimal recovery.conf file (Zoltán Böszörményi, Magnus Hagander)
This simplifies setting up a standby server.
Original release occurrence ·
9.3.0/changes/040Allow pg_receivexlog and pg_basebackup --xlog-method to handle streaming timeline switches Features
Allow pg_receivexlog and pg_basebackup --xlog-method to handle streaming timeline switches (Heikki Linnakangas)
Original release occurrence ·
9.3.0/changes/041Add wal_receiver_timeout parameter to control the WAL receiver's timeout Features
Add wal_receiver_timeout parameter to control the WAL receiver's timeout (Amit Kapila)
This allows more rapid detection of connection failure.
Original release occurrence ·
9.3.0/changes/042Change the WAL record format to allow splitting the record header across pages Features
Change the WAL record format to allow splitting the record header across pages (Heikki Linnakangas)
The new format is slightly more compact, and is more efficient to write.
Original release occurrence ·
9.3.0/changes/043Implement SQL-standard LATERAL option for FROM-clause subqueries and function calls Features
Implement SQL-standard LATERAL option for FROM-clause subqueries and function calls (Tom Lane)
This feature allows subqueries and functions in FROM to reference columns from other tables in the FROM clause. The LATERAL keyword is optional for functions.
Original release occurrence ·
9.3.0/changes/044Add support for piping COPY and psql \copy data to/from an external program Features
Original release occurrence ·
9.3.0/changes/045Allow a multirow VALUES clause in a rule to reference OLD/NEW Features
Allow a multirow VALUES clause in a rule to reference OLD/NEW (Tom Lane)
Original release occurrence ·
9.3.0/changes/046Add support for event triggers Features
Add support for event triggers (Dimitri Fontaine, Robert Haas, Álvaro Herrera)
This allows server-side functions written in event-enabled languages to be called when DDL commands are run.
Original release occurrence ·
9.3.0/changes/047Allow foreign data wrappers to support writes (inserts/updates/deletes) on foreign tables Features
Allow foreign data wrappers to support writes (inserts/updates/deletes) on foreign tables (KaiGai Kohei)
Original release occurrence ·
9.3.0/changes/048Add CREATE SCHEMA ... IF NOT EXISTS clause Features
Add CREATE SCHEMA ... IF NOT EXISTS clause (Fabrízio de Royes Mello)
Original release occurrence ·
9.3.0/changes/049Make REASSIGN OWNED also change ownership of shared objects Features
Make REASSIGN OWNED also change ownership of shared objects (Álvaro Herrera)
Original release occurrence ·
9.3.0/changes/050Make CREATE AGGREGATE complain if the given initial value string is not valid input for the transition datatype Features
Make CREATE AGGREGATE complain if the given initial value string is not valid input for the transition datatype (Tom Lane)
Original release occurrence ·
9.3.0/changes/051Suppress CREATE TABLE's messages about implicit index and sequence creation Features
Suppress CREATE TABLE's messages about implicit index and sequence creation (Robert Haas)
These messages now appear at DEBUG1 verbosity, so that they will not be shown by default.
Original release occurrence ·
9.3.0/changes/052Allow DROP TABLE IF EXISTS to succeed when a non-existent schema is specified in the table name Features
Allow DROP TABLE IF EXISTS to succeed when a non-existent schema is specified in the table name (Bruce Momjian)
Previously, it threw an error if the schema did not exist.
Original release occurrence ·
9.3.0/changes/053Provide clients with constraint violation details as separate fields Features
Provide clients with constraint violation details as separate fields (Pavel Stehule)
This allows clients to retrieve table, column, data type, or constraint name error details. Previously such information had to be extracted from error strings. Client library support is required to access these fields.
Original release occurrence ·
9.3.0/changes/054Support IF NOT EXISTS option in ALTER TYPE ... ADD VALUE Features
Support IF NOT EXISTS option in ALTER TYPE ... ADD VALUE (Andrew Dunstan)
This is useful for conditionally adding values to enumerated types.
Original release occurrence ·
9.3.0/changes/055Add ALTER ROLE ALL SET to establish settings for all users Features
Add ALTER ROLE ALL SET to establish settings for all users (Peter Eisentraut)
This allows settings to apply to all users in all databases. ALTER DATABASE SET already allowed addition of settings for all users in a single database. postgresql.conf has a similar effect.
Original release occurrence ·
9.3.0/changes/056Add support for ALTER RULE ... RENAME Features
Add support for ALTER RULE ... RENAME (Ali Dar)
Original release occurrence ·
9.3.0/changes/057Add materialized views Features
Add materialized views (Kevin Grittner)
Unlike ordinary views, where the base tables are read on every access, materialized views create physical tables at creation or refresh time. Access to the materialized view then reads from its physical table. There is not yet any facility for incrementally refreshing materialized views or auto-accessing them via base table access.
Original release occurrence ·
9.3.0/changes/058Make simple views auto-updatable Features
Make simple views auto-updatable (Dean Rasheed)
Simple views that reference some or all columns from a single base table are now updatable by default. More complex views can be made updatable using INSTEAD OF triggers or INSTEAD rules.
Original release occurrence ·
9.3.0/changes/059Add CREATE RECURSIVE VIEW syntax Features
Add CREATE RECURSIVE VIEW syntax (Peter Eisentraut)
Internally this is translated into CREATE VIEW ... WITH RECURSIVE ....
Original release occurrence ·
9.3.0/changes/060Improve view/rule printing code to handle cases where referenced tables are renamed, or columns are renamed, added, or dropped Features
Improve view/rule printing code to handle cases where referenced tables are renamed, or columns are renamed, added, or dropped (Tom Lane)
Table and column renamings can produce cases where, if we merely substitute the new name into the original text of a rule or view, the result is ambiguous. This change fixes the rule-dumping code to insert manufactured table and column aliases when needed to preserve the original semantics.
Original release occurrence ·
9.3.0/changes/061Increase the maximum size of large objects from 2GB to 4TB Features
Increase the maximum size of large objects from 2GB to 4TB (Nozomi Anzai, Yugo Nagata)
This change includes adding 64-bit-capable large object access functions, both in the server and in libpq.
Original release occurrence ·
9.3.0/changes/062Allow text timezone designations, e.g. "America/Chicago", in the "T" field of ISO-format timestamptz input Features
Allow text timezone designations, e.g. "America/Chicago", in the "T" field of ISO-format timestamptz input (Bruce Momjian)
Original release occurrence ·
9.3.0/changes/063Add operators and functions to extract elements from JSON values Features
Add operators and functions to extract elements from JSON values (Andrew Dunstan)
Original release occurrence ·
9.3.0/changes/064Allow JSON values to be converted into records Features
Allow JSON values to be converted into records (Andrew Dunstan)
Original release occurrence ·
9.3.0/changes/065Add functions to convert scalars, records, and hstore values to JSON Features
Add functions to convert scalars, records, and hstore values to JSON (Andrew Dunstan)
Original release occurrence ·
9.3.0/changes/066Add array_remove() and array_replace() functions Features
Add
array_remove()andarray_replace()functions (Marco Nenciarini, Gabriele Bartolini)Original release occurrence ·
9.3.0/changes/067Allow concat() and format() to properly expand VARIADIC-labeled arguments Features
Original release occurrence ·
9.3.0/changes/068Improve format() to provide field width and left/right alignment options Features
Improve
format()to provide field width and left/right alignment options (Pavel Stehule)Original release occurrence ·
9.3.0/changes/069Make to_char(), to_date(), and to_timestamp() handle negative (BC) century values properly Features
Make
to_char(),to_date(), andto_timestamp()handle negative (BC) century values properly (Bruce Momjian)Previously the behavior was either wrong or inconsistent with positive/AD handling, e.g. with the format mask "IYYY-IW-DY".
Original release occurrence ·
9.3.0/changes/070Make to_date() and to_timestamp() return proper results when mixing ISO and Gregorian week/day designations Features
Make
to_date()andto_timestamp()return proper results when mixing ISO and Gregorian week/day designations (Bruce Momjian)Original release occurrence ·
9.3.0/changes/071Cause pg_get_viewdef() to start a new line by default after each SELECT target list entry and FROM entry Features
Cause
pg_get_viewdef()to start a new line by default after each SELECT target list entry and FROM entry (Marko Tiikkaja)This reduces line length in view printing, for instance in pg_dump output.
Original release occurrence ·
9.3.0/changes/072Fix map_sql_value_to_xml_value() to print values of domain types the same way their base type would be printed Bug fixes
Fix
map_sql_value_to_xml_value()to print values of domain types the same way their base type would be printed (Pavel Stehule)There are special formatting rules for certain built-in types such as boolean; these rules now also apply to domains over these types.
Original release occurrence ·
9.3.0/changes/073Allow PL/pgSQL to use RETURN with a composite-type expression Features
Allow PL/pgSQL to use RETURN with a composite-type expression (Asif Rehman)
Previously, in a function returning a composite type, RETURN could only reference a variable of that type.
Original release occurrence ·
9.3.0/changes/074Allow PL/pgSQL to access constraint violation details as separate fields Features
Allow PL/pgSQL to access constraint violation details as separate fields (Pavel Stehule)
Original release occurrence ·
9.3.0/changes/075Allow PL/pgSQL to access the number of rows processed by COPY Features
Allow PL/pgSQL to access the number of rows processed by COPY (Pavel Stehule)
A COPY executed in a PL/pgSQL function now updates the value retrieved by GET DIAGNOSTICS x = ROW_COUNT.
Original release occurrence ·
9.3.0/changes/076Allow unreserved keywords to be used as identifiers everywhere in PL/pgSQL Features
Allow unreserved keywords to be used as identifiers everywhere in PL/pgSQL (Tom Lane)
In certain places in the PL/pgSQL grammar, keywords had to be quoted to be used as identifiers, even if they were nominally unreserved.
Original release occurrence ·
9.3.0/changes/077Add PL/Python result object string handler Features
Add PL/Python result object string handler (Peter Eisentraut)
This allows plpy.debug(rv) to output something reasonable.
Original release occurrence ·
9.3.0/changes/078Make PL/Python convert OID values to a proper Python numeric type Features
Make PL/Python convert OID values to a proper Python numeric type (Peter Eisentraut)
Original release occurrence ·
9.3.0/changes/079Handle SPI errors raised explicitly (with PL/Python's RAISE) the same as internal SPI errors Features
Handle SPI errors raised explicitly (with PL/Python's RAISE) the same as internal SPI errors (Oskari Saarenmaa and Jan Urbanski)
Original release occurrence ·
9.3.0/changes/080Prevent leakage of SPI tuple tables during subtransaction abort Bug fixes
Prevent leakage of SPI tuple tables during subtransaction abort (Tom Lane)
At the end of any failed subtransaction, the core SPI code now releases any SPI tuple tables that were created during that subtransaction. This avoids the need for SPI-using code to keep track of such tuple tables and release them manually in error-recovery code. Failure to do so caused a number of transaction-lifespan memory leakage issues in PL/pgSQL and perhaps other SPI clients.
SPI_freetuptable()now protects itself against multiple freeing requests, so any existing code that did take care to clean up shouldn't be broken by this change.Original release occurrence ·
9.3.0/changes/081Allow SPI functions to access the number of rows processed by COPY Features
Allow SPI functions to access the number of rows processed by COPY (Pavel Stehule)
Original release occurrence ·
9.3.0/changes/082Add command-line utility pg_isready to check if the server is ready to accept connections Features
Add command-line utility pg_isready to check if the server is ready to accept connections (Phil Sorber)
Original release occurrence ·
9.3.0/changes/083Support multiple --table arguments for pg_restore, clusterdb, reindexdb, and vacuumdb Features
Support multiple --table arguments for pg_restore, clusterdb, reindexdb, and vacuumdb (Josh Kupershmidt)
This is similar to the way pg_dump's --table option works.
Original release occurrence ·
9.3.0/changes/084Add --dbname option to pg_dumpall, pg_basebackup, and pg_receivexlog to allow specifying a connection string Features
Add --dbname option to pg_dumpall, pg_basebackup, and pg_receivexlog to allow specifying a connection string (Amit Kapila)
Original release occurrence ·
9.3.0/changes/085Add libpq function PQconninfo() to return connection information Features
Add libpq function
PQconninfo()to return connection information (Zoltán Böszörményi, Magnus Hagander)Original release occurrence ·
9.3.0/changes/086Adjust function cost settings so psql tab completion and pattern searching are more efficient Features
Adjust function cost settings so psql tab completion and pattern searching are more efficient (Tom Lane)
Original release occurrence ·
9.3.0/changes/087Improve psql's tab completion coverage Features
Improve psql's tab completion coverage (Jeff Janes, Dean Rasheed, Peter Eisentraut, Magnus Hagander)
Original release occurrence ·
9.3.0/changes/088Allow the psql --single-transaction mode to work when reading from standard input Features
Allow the psql --single-transaction mode to work when reading from standard input (Fabien Coelho, Robert Haas)
Previously this option only worked when reading from a file.
Original release occurrence ·
9.3.0/changes/089Remove psql warning when connecting to an older server Features
Remove psql warning when connecting to an older server (Peter Eisentraut)
A warning is still issued when connecting to a server of a newer major version than psql's.
Original release occurrence ·
9.3.0/changes/090Add psql command \watch to repeatedly execute a SQL command Features
Add psql command \watch to repeatedly execute a SQL command (Will Leinweber)
Original release occurrence ·
9.3.0/changes/091Add psql command \gset to store query results in psql variables Features
Add psql command \gset to store query results in psql variables (Pavel Stehule)
Original release occurrence ·
9.3.0/changes/092Add SSL information to psql's \conninfo command Features
Add SSL information to psql's \conninfo command (Alastair Turner)
Original release occurrence ·
9.3.0/changes/093Add "Security" column to psql's \df+ output Features
Add "Security" column to psql's \df+ output (Jon Erdman)
Original release occurrence ·
9.3.0/changes/094Allow psql command \l to accept a database name pattern Features
Allow psql command \l to accept a database name pattern (Peter Eisentraut)
Original release occurrence ·
9.3.0/changes/095In psql, do not allow \connect to use defaults if there is no active connection Features
In psql, do not allow \connect to use defaults if there is no active connection (Bruce Momjian)
This might be the case if the server had crashed.
Original release occurrence ·
9.3.0/changes/096Properly reset state after failure of a SQL command executed with psql's \g file Features
Properly reset state after failure of a SQL command executed with psql's \g file (Tom Lane)
Previously, the output from subsequent SQL commands would unexpectedly continue to go to the same file.
Original release occurrence ·
9.3.0/changes/097Add a latex-longtable output format to psql Features
Add a latex-longtable output format to psql (Bruce Momjian)
This format allows tables to span multiple pages.
Original release occurrence ·
9.3.0/changes/098Add a border=3 output mode to the psql latex format Features
Add a border=3 output mode to the psql latex format (Bruce Momjian)
Original release occurrence ·
9.3.0/changes/099In psql's tuples-only and expanded output modes, no longer emit "(No rows)" for zero rows Features
In psql's tuples-only and expanded output modes, no longer emit "(No rows)" for zero rows (Peter Eisentraut)
Original release occurrence ·
9.3.0/changes/100In psql's unaligned, expanded output mode, no longer print an empty line for zero rows Features
In psql's unaligned, expanded output mode, no longer print an empty line for zero rows (Peter Eisentraut)
Original release occurrence ·
9.3.0/changes/101Add pg_dump --jobs option to dump tables in parallel Features
Add pg_dump --jobs option to dump tables in parallel (Joachim Wieland)
Original release occurrence ·
9.3.0/changes/102Make pg_dump output functions in a more predictable order Features
Make pg_dump output functions in a more predictable order (Joel Jacobson)
Original release occurrence ·
9.3.0/changes/103Fix tar files emitted by pg_dump to be POSIX conformant Bug fixes
Fix tar files emitted by pg_dump to be POSIX conformant (Brian Weaver, Tom Lane)
Original release occurrence ·
9.3.0/changes/104Add --dbname option to pg_dump, for consistency with other client commands Features
Add --dbname option to pg_dump, for consistency with other client commands (Heikki Linnakangas)
The database name could already be supplied last without a flag.
Original release occurrence ·
9.3.0/changes/105Make initdb fsync the newly created data directory Features
Make initdb fsync the newly created data directory (Jeff Davis)
This insures data integrity in event of a system crash shortly after initdb. This can be disabled by using --nosync.
Original release occurrence ·
9.3.0/changes/106Add initdb --sync-only option to sync the data directory to durable storage Features
Add initdb --sync-only option to sync the data directory to durable storage (Bruce Momjian)
This is used by pg_upgrade.
Original release occurrence ·
9.3.0/changes/107Make initdb issue a warning about placing the data directory at the top of a file system mount point Features
Make initdb issue a warning about placing the data directory at the top of a file system mount point (Bruce Momjian)
Original release occurrence ·
9.3.0/changes/108Add infrastructure to allow plug-in background worker processes Features
Add infrastructure to allow plug-in background worker processes (Álvaro Herrera)
Original release occurrence ·
9.3.0/changes/109Create a centralized timeout API Features
Create a centralized timeout API (Zoltán Böszörményi)
Original release occurrence ·
9.3.0/changes/110Create libpgcommon and move pg_malloc() and other functions there Features
Create libpgcommon and move
pg_malloc()and other functions there (Álvaro Herrera, Andres Freund)This allows libpgport to be used solely for portability-related code.
Original release occurrence ·
9.3.0/changes/111Add support for list links embedded in larger structs Features
Add support for list links embedded in larger structs (Andres Freund)
Original release occurrence ·
9.3.0/changes/112Use SA_RESTART for all signals, including SIGALRM Features
Use SA_RESTART for all signals, including SIGALRM (Tom Lane)
Original release occurrence ·
9.3.0/changes/113Ensure that the correct text domain is used when translating errcontext() messages Bug fixes
Ensure that the correct text domain is used when translating
errcontext()messages (Heikki Linnakangas)Original release occurrence ·
9.3.0/changes/114Standardize naming of client-side memory allocation functions Features
Standardize naming of client-side memory allocation functions (Tom Lane)
Original release occurrence ·
9.3.0/changes/115Provide support for "static assertions" that will fail at compile time if some compile-time-constant condition is not met Features
Provide support for "static assertions" that will fail at compile time if some compile-time-constant condition is not met (Andres Freund, Tom Lane)
Original release occurrence ·
9.3.0/changes/116Support Assert() in client-side code Features
Support
Assert()in client-side code (Andrew Dunstan)Original release occurrence ·
9.3.0/changes/117Add decoration to inform the C compiler that some ereport() and elog() calls do not return Features
Add decoration to inform the C compiler that some
ereport()andelog()calls do not return (Peter Eisentraut, Andres Freund, Tom Lane, Heikki Linnakangas)Original release occurrence ·
9.3.0/changes/118Allow options to be passed to the regression test output comparison utility via PG_REGRESS_DIFF_OPTS Features
Allow options to be passed to the regression test output comparison utility via PG_REGRESS_DIFF_OPTS (Peter Eisentraut)
Original release occurrence ·
9.3.0/changes/119Add isolation tests for CREATE INDEX CONCURRENTLY Features
Add isolation tests for CREATE INDEX CONCURRENTLY (Abhijit Menon-Sen)
Original release occurrence ·
9.3.0/changes/120Remove typedefs for int2/int4 as they are better represented as int16/int32 Features
Remove typedefs for int2/int4 as they are better represented as int16/int32 (Peter Eisentraut)
Original release occurrence ·
9.3.0/changes/121Fix install-strip on Mac OS X Bug fixes
Fix install-strip on Mac OS X (Peter Eisentraut)
Original release occurrence ·
9.3.0/changes/122Remove configure flag --disable-shared, as it is no longer supported Features
Remove configure flag --disable-shared, as it is no longer supported (Bruce Momjian)
Original release occurrence ·
9.3.0/changes/123Rewrite pgindent in Perl Features
Rewrite pgindent in Perl (Andrew Dunstan)
Original release occurrence ·
9.3.0/changes/124Provide Emacs macro to set Perl formatting to match PostgreSQL's perltidy settings Features
Provide Emacs macro to set Perl formatting to match PostgreSQL's perltidy settings (Peter Eisentraut)
Original release occurrence ·
9.3.0/changes/125Run tool to check the keyword list whenever the backend grammar is changed Features
Run tool to check the keyword list whenever the backend grammar is changed (Tom Lane)
Original release occurrence ·
9.3.0/changes/126Change the way UESCAPE is lexed, to significantly reduce the size of the lexer tables Features
Change the way UESCAPE is lexed, to significantly reduce the size of the lexer tables (Heikki Linnakangas)
Original release occurrence ·
9.3.0/changes/127Centralize flex and bison make rules Features
Centralize flex and bison make rules (Peter Eisentraut)
This is useful for pgxs authors.
Original release occurrence ·
9.3.0/changes/128Change many internal backend functions to return object OIDs rather than void Features
Change many internal backend functions to return object OIDs rather than void (Dimitri Fontaine)
This is useful for event triggers.
Original release occurrence ·
9.3.0/changes/129Invent pre-commit/pre-prepare/pre-subcommit events for transaction callbacks Features
Invent pre-commit/pre-prepare/pre-subcommit events for transaction callbacks (Tom Lane)
Loadable modules that use transaction callbacks might need modification to handle these new event types.
Original release occurrence ·
9.3.0/changes/130Add function pg_identify_object() to produce a machine-readable description of a database object Features
Add function
pg_identify_object()to produce a machine-readable description of a database object (Álvaro Herrera)Original release occurrence ·
9.3.0/changes/131Add post-ALTER-object server hooks Features
Add post-ALTER-object server hooks (KaiGai Kohei)
Original release occurrence ·
9.3.0/changes/132Implement a generic binary heap and use it for Merge-Append operations Features
Implement a generic binary heap and use it for Merge-Append operations (Abhijit Menon-Sen)
Original release occurrence ·
9.3.0/changes/133Provide a tool to help detect timezone abbreviation changes when updating the src/timezone/data files Features
Provide a tool to help detect timezone abbreviation changes when updating the src/timezone/data files (Tom Lane)
Original release occurrence ·
9.3.0/changes/134Add pkg-config support for libpq and ecpg libraries Features
Add pkg-config support for libpq and ecpg libraries (Peter Eisentraut)
Original release occurrence ·
9.3.0/changes/135Remove src/tools/backend, now that the content is on the PostgreSQL wiki Features
Remove src/tools/backend, now that the content is on the PostgreSQL wiki (Bruce Momjian)
Original release occurrence ·
9.3.0/changes/136Split out WAL reading as an independent facility Features
Split out WAL reading as an independent facility (Heikki Linnakangas, Andres Freund)
Original release occurrence ·
9.3.0/changes/137Use a 64-bit integer to represent WAL positions (XLogRecPtr) instead of two 32-bit integers Features
Use a 64-bit integer to represent WAL positions (XLogRecPtr) instead of two 32-bit integers (Heikki Linnakangas)
Generally, tools that need to read the WAL format will need to be adjusted.
Original release occurrence ·
9.3.0/changes/138Allow PL/Python to support platform-specific include directories Features
Allow PL/Python to support platform-specific include directories (Peter Eisentraut)
Original release occurrence ·
9.3.0/changes/139Allow PL/Python on OS X to build against custom versions of Python Features
Allow PL/Python on OS X to build against custom versions of Python (Peter Eisentraut)
Original release occurrence ·
9.3.0/changes/140Add a Postgres foreign data wrapper contrib module to allow access to other Postgres servers Features
Add a Postgres foreign data wrapper contrib module to allow access to other Postgres servers (Shigeru Hanada)
This foreign data wrapper supports writes.
Original release occurrence ·
9.3.0/changes/141Add pg_xlogdump contrib program Features
Add pg_xlogdump contrib program (Andres Freund)
Original release occurrence ·
9.3.0/changes/142Add support for indexing of regular-expression searches in pg_trgm Features
Add support for indexing of regular-expression searches in pg_trgm (Alexander Korotkov)
Original release occurrence ·
9.3.0/changes/143Improve pg_trgm's handling of multibyte characters Features
Improve pg_trgm's handling of multibyte characters (Tom Lane)
On a platform that does not have the wcstombs() or towlower() library functions, this could result in an incompatible change in the contents of pg_trgm indexes for non-ASCII data. In such cases, REINDEX those indexes to ensure correct search results.
Original release occurrence ·
9.3.0/changes/144Add a pgstattuple function to report the size of the pending-insertions list of a GIN index Features
Add a pgstattuple function to report the size of the pending-insertions list of a GIN index (Fujii Masao)
Original release occurrence ·
9.3.0/changes/145Make oid2name, pgbench, and vacuumlo set fallback_application_name Features
Original release occurrence ·
9.3.0/changes/146Improve output of pg_test_timing Features
Improve output of pg_test_timing (Bruce Momjian)
Original release occurrence ·
9.3.0/changes/147Improve output of pg_test_fsync Features
Improve output of pg_test_fsync (Peter Geoghegan)
Original release occurrence ·
9.3.0/changes/148Create a dedicated foreign data wrapper, with its own option validator function, for dblink Features
Create a dedicated foreign data wrapper, with its own option validator function, for dblink (Shigeru Hanada)
When using this FDW to define the target of a dblink connection, instead of using a hard-wired list of connection options, the underlying libpq library is consulted to see what connection options it supports.
Original release occurrence ·
9.3.0/changes/149Allow pg_upgrade to do dumps and restores in parallel Features
Allow pg_upgrade to do dumps and restores in parallel (Bruce Momjian, Andrew Dunstan)
This allows parallel schema dump/restore of databases, as well as parallel copy/link of data files per tablespace. Use the --jobs option to specify the level of parallelism.
Original release occurrence ·
9.3.0/changes/150Make pg_upgrade create Unix-domain sockets in the current directory Features
Make pg_upgrade create Unix-domain sockets in the current directory (Bruce Momjian, Tom Lane)
This reduces the possibility that someone will accidentally connect during the upgrade.
Original release occurrence ·
9.3.0/changes/151Make pg_upgrade --check mode properly detect the location of non-default socket directories Features
Make pg_upgrade --check mode properly detect the location of non-default socket directories (Bruce Momjian, Tom Lane)
Original release occurrence ·
9.3.0/changes/152Improve performance of pg_upgrade for databases with many tables Performance
Improve performance of pg_upgrade for databases with many tables (Bruce Momjian)
Original release occurrence ·
9.3.0/changes/153Improve pg_upgrade's logs by showing executed commands Features
Improve pg_upgrade's logs by showing executed commands (Álvaro Herrera)
Original release occurrence ·
9.3.0/changes/154Improve pg_upgrade's status display during copy/link Features
Improve pg_upgrade's status display during copy/link (Bruce Momjian)
Original release occurrence ·
9.3.0/changes/155Add --foreign-keys option to pgbench Features
Add --foreign-keys option to pgbench (Jeff Janes)
This adds foreign key constraints to the standard tables created by pgbench, for use in foreign key performance testing.
Original release occurrence ·
9.3.0/changes/156Allow pgbench to aggregate performance statistics and produce output every --aggregate-interval seconds Features
Allow pgbench to aggregate performance statistics and produce output every --aggregate-interval seconds (Tomas Vondra)
Original release occurrence ·
9.3.0/changes/157Add pgbench --sampling-rate option to control the percentage of transactions logged Features
Add pgbench --sampling-rate option to control the percentage of transactions logged (Tomas Vondra)
Original release occurrence ·
9.3.0/changes/158Reduce and improve the status message output of pgbench's initialization mode Features
Reduce and improve the status message output of pgbench's initialization mode (Robert Haas, Peter Eisentraut)
Original release occurrence ·
9.3.0/changes/159Add pgbench -q mode to print one output line every five seconds Features
Add pgbench -q mode to print one output line every five seconds (Tomas Vondra)
Original release occurrence ·
9.3.0/changes/160Output pgbench elapsed and estimated remaining time during initialization Features
Output pgbench elapsed and estimated remaining time during initialization (Tomas Vondra)
Original release occurrence ·
9.3.0/changes/161Allow pgbench to use much larger scale factors, by changing relevant columns from integer to bigint when the requested scale factor exceeds 20000 Features
Allow pgbench to use much larger scale factors, by changing relevant columns from integer to bigint when the requested scale factor exceeds 20000 (Greg Smith)
Original release occurrence ·
9.3.0/changes/162Allow EPUB-format documentation to be created Features
Allow EPUB-format documentation to be created (Peter Eisentraut)
Original release occurrence ·
9.3.0/changes/163Update FreeBSD kernel configuration documentation Features
Update FreeBSD kernel configuration documentation (Brad Davis)
Original release occurrence ·
9.3.0/changes/164Improve WINDOW function documentation Features
Improve WINDOW function documentation (Bruce Momjian, Florian Pflug)
Original release occurrence ·
9.3.0/changes/165Add instructions for setting up the documentation tool chain on macOS Features
Add instructions for setting up the documentation tool chain on macOS (Peter Eisentraut)
Original release occurrence ·
9.3.0/changes/166Improve commit_delay documentation Features
Improve commit_delay documentation (Peter Geoghegan)
Original release occurrence ·
9.3.0/changes/167
Security evidence
35 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.
CVE-2018-10915 · Certain host connection parameters defeat client-side security defenses CVSS 8.5
Fixed in this branch: 9.3.24. Component: client.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Release-note mentions:
CVE-2018-1058 · Uncontrolled search path element in pg_dump and other client applications CVSS 8.8
Fixed in this branch: 9.3.22. Component: client.
Official affected-branch entry: 9.3.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2018-1053 · pg_upgrade creates file of sensitive metadata under prevailing umask CVSS 6.7
Fixed in this branch: 9.3.21. Component: client.
Official affected-branch entry: 9.3.
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7547 · pg_user_mappings view discloses passwords to users lacking server privileges CVSS 8.5
Fixed in this branch: 9.3.18. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7546 · empty password accepted in some authentication methods CVSS 8.1
Fixed in this branch: 9.3.18. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7486 · pg_user_mappings view discloses foreign server passwords CVSS 8.5
Fixed in this branch: 9.3.17. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7485 · libpq ignores PGREQUIRESSL environment variable CVSS 8.1
Fixed in this branch: 9.3.17. Component: client.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks CVSS 4.3
Fixed in this branch: 9.3.17. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2017-15098 · Memory disclosure in JSON functions CVSS 4.3
Fixed in this branch: 9.3.20. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2017-12172 · Start scripts permit database administrator to modify root-owned files CVSS 8.4
Fixed in this branch: 9.3.20. Component: contrib module.
Official affected-branch entry: 9.3.
AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Release-note mentions:
CVE-2016-7048 · Interactive installer downloads software over plain HTTP, then executes it CVSS 7.5
Fixed in this branch: 9.3.15. Component: packaging.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2016-5424 · Exceptional database and role names could enable escalation to superuser CVSS 8.5
Fixed in this branch: 9.3.14. Component: client.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Release-note mentions:
CVE-2016-5423 · Certain nested CASE/WHEN expressions can crash server CVSS 4.3
Fixed in this branch: 9.3.14. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2016-0773 · Unchecked regex can crash the server CVSS 6.5
Fixed in this branch: 9.3.11. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Release-note mentions:
CVE-2016-0766 · CVE-2016-0766
No fixed version for this branch is recorded.
Release-note mentions:
CVE-2015-7499 · CVE-2015-7499
No fixed version for this branch is recorded.
Release-note mentions:
CVE-2015-5289 · Unchecked JSON input can crash the server CVSS 5.9
Fixed in this branch: 9.3.10. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Release-note mentions:
CVE-2015-5288 · Memory leak in crypt() function. CVSS 3.1
Fixed in this branch: 9.3.10. Component: contrib module.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2015-3167 · pgcrypto has multiple error messages for decryption with an incorrect key. CVSS 3.7
Fixed in this branch: 9.3.7. Component: contrib module.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2015-3166 · Unanticipated errors from the standard library. CVSS 5.6
Fixed in this branch: 9.3.7. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Release-note mentions:
CVE-2015-3165 · Double "free" after authentication timeout CVSS 7.5
Fixed in this branch: 9.3.7. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Release-note mentions:
CVE-2015-0244 · An error in extended protocol message reading. CVSS 8.1
Fixed in this branch: 9.3.6. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2015-0243 · Memory errors in functions in the pgcrypto extension. CVSS 6.5
Fixed in this branch: 9.3.6. Component: contrib module.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Release-note mentions:
CVE-2015-0242 · Buffer overrun in replacement printf family of functions. CVSS 4.2
Fixed in this branch: 9.3.6. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2015-0241 · Buffer overruns in "to_char" functions. CVSS 4.2
Fixed in this branch: 9.3.6. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2014-8161 · Constraint violation errors can cause display of values in columns which the user would not normally have rights to see. CVSS 3.1
Fixed in this branch: 9.3.6. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2014-0067 · Unauthenticated users may gain access to the database server during "make check".. CVSS 7.0
Fixed in this branch: 9.3.6. Component: other.
Official affected-branch entry: 9.3.
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2014-0066 · Potential null pointer dereference crash when crypt(3) returns NULL. CVSS 0.0
Fixed in this branch: 9.3.3. Component: contrib module.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N
Release-note mentions:
CVE-2014-0065 · Potential buffer overruns of fixed-size buffers. CVSS 0.0
Fixed in this branch: 9.3.3. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N
Release-note mentions:
CVE-2014-0064 · Potential buffer overruns due to integer overflow in size calculations. CVSS 6.5
Fixed in this branch: 9.3.3. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Release-note mentions:
CVE-2014-0063 · Potential buffer overruns in datetime input/output. CVSS 4.3
Fixed in this branch: 9.3.3. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Release-note mentions:
CVE-2014-0062 · Race condition in CREATE INDEX allows for privilege escalation. CVSS 8.8
Fixed in this branch: 9.3.3. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2014-0061 · Privilege escalation via calls to validator functions. CVSS 7.5
Fixed in this branch: 9.3.3. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2014-0060 · SET ROLE bypasses lack of ADMIN OPTION. CVSS 3.1
Fixed in this branch: 9.3.3. Component: core server.
Official affected-branch entry: 9.3.
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Release-note mentions:
CVE-2007-4772 · CVE-2007-4772
No fixed version for this branch is recorded.
Release-note mentions:
Export this branch as JSON · Compare any two indexed releases