Protect against indirect security threats caused by index functions
changing session-local state (Gurjeet Singh, Tom)
This change prevents allegedly-immutable index functions from possibly
subverting a superuser's session (CVE-2009-4136).
Reject SSL certificates containing an embedded null byte in the common
name (CN) field (Magnus)
This prevents unintended matching of a certificate to a server or client
name during SSL validation (CVE-2009-4034).
Fix possible crash during backend-startup-time cache initialization (Tom)
Prevent signals from interrupting VACUUM at unsafe times
(Alvaro)
This fix prevents a PANIC if a VACUUM FULL is canceled
after it's already committed its tuple movements, as well as transient
errors if a plain VACUUM is interrupted after having
truncated the table.
Fix possible crash due to integer overflow in hash table size
calculation (Tom)
This could occur with extremely large planner estimates for the size of
a hashjoin's result.
Fix very rare crash in inet/cidr comparisons (Chris
Mikkelson)
Fix premature drop of temporary files used for a cursor that is accessed
within a subtransaction (Heikki)
Fix PAM password processing to be more robust (Tom)
The previous code is known to fail with the combination of the Linux
pam_krb5 PAM module with Microsoft Active Directory as the
domain controller. It might have problems elsewhere too, since it was
making unjustified assumptions about what arguments the PAM stack would
pass to it.
Fix rare crash in exception processing in PL/Python (Peter)
Ensure psql's flex module is compiled with the correct
system header definitions (Tom)
This fixes build failures on platforms where
--enable-largefile causes incompatible changes in the
generated code.
Make the postmaster ignore any application_name parameter in
connection request packets, to improve compatibility with future libpq
versions (Tom)
Update time zone data files to tzdata release 2009s
for DST law changes in Antarctica, Argentina, Bangladesh, Fiji,
Novokuznetsk, Pakistan, Palestine, Samoa, Syria; also historical
corrections for Hong Kong.