PostgreSQL 8.4 beta

Free PostgreSQL - a great and easy to use database management tool
3.8 
Rating
Your vote:
Latest version:
17.5 See all
Screenshots
1 / 36
Awards (7)
Show all awards
Software Informer Editor Rating 5 Software Informer Virus Free award
Download
Free  

Enforce restrictions in plperl using an opmask applied to the whole interpreter, instead of using Safe.pm (Tim Bunce, Andrew Dunstan)
Recent developments have convinced us that Safe.pm is too insecure to rely on for making plperl trustable. This change removes use of Safe.pm altogether, in favor of using a separate interpreter with an opcode mask that is always applied. Pleasant side effects of the change include that it is now possible to use Perl's strict pragma in a natural way in plperl, and that Perl's $a and $b variables work as expected in sort routines, and that function compilation is significantly faster. (CVE-2010-1169)

Prevent PL/Tcl from executing untrustworthy code from pltcl_modules (Tom)

PL/Tcl's feature for autoloading Tcl code from a database table could be exploited for trojan-horse attacks, because there was no restriction on who could create or insert into that table. This change disables the feature unless pltcl_modules is owned by a superuser. (However, the permissions on the table are not checked, so installations that really need a less-than-secure modules table can still grant suitable privileges to trusted non-superusers.) Also, prevent loading code into the unrestricted "normal" Tcl interpreter unless we are really going to execute a pltclu function. (CVE-2010-1170)

Fix data corruption during WAL replay of ALTER ... SET TABLESPACE (Tom) more

Comments (3)

3.8
Rating
53 votes
5 stars
29
4 stars
6
3 stars
7
2 stars
1
1 stars
10
User

Your vote:

J
John
rating
Amazing old-fashion SQL database!

| Reply
G
I'm trying it first time. Let's see how fine it works.

| Reply
T
I like it

| Reply

Related suggestions