Additional Advisory to 2019-11-14 Cumulative Update Release for Debian and Ubuntu Users

"Jonathan S. Katz" <[email protected]> Wed, 4 Dec 2019 10:18:10 -0500
Newsgroups gmane.comp.db.postgresql.announce
Message-ID <[email protected]>
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--2rwxvRb2e0uDrCObp3FkeVWxoyBMIWAjY
Content-Type: multipart/mixed; boundary="ktkpTzkNAYlko9Y0dKieRr9KRRgd3dIKo"

--ktkpTzkNAYlko9Y0dKieRr9KRRgd3dIKo
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable

The PostgreSQL Global Development Group, in conjunction with the
cumulative update release on November 14, 2019 for versions 12.1, 11.6,
10.11, 9.6.16, 9.5.20, and 9.4.25, advises all users on Debian and
Ubuntu to update their "postgresql-common" packages as soon as possible.

The latest releases of PostgreSQL packages from apt.postgresql.org,
debian.org, and ubuntu.com closed a vulnerability (CVE-2019-3466) in
which the PostgreSQL superuser could escalate to root using a deficiency
in the `pg_ctlcluster` command. `pg_ctlcluster` is a utility provided by
the "postgresql-common" package that is installed with PostgreSQL on
theses platforms.

Updating
--------

All PostgreSQL update releases are cumulative. As with other minor
releases, users are not required to dump and reload their database or
use `pg_upgrade` in order to apply this update release; you may simply
shutdown PostgreSQL and update its binaries.

Users who have skipped one or more update releases may need to run
additional, post-update steps; please see the release notes for earlier
versions for details.

**NOTE**: PostgreSQL 9.4 will stop receiving fixes on February 13, 2020.
Please see our versioning policy for more information:

    https://www.postgresql.org/support/versioning/

Links
-----
* Download: https://www.postgresql.org/download/
* 2019-11-14 Release Announcement:
https://www.postgresql.org/about/news/1994/
* Release Notes: https://www.postgresql.org/docs/current/release.html
* Security Page: https://www.postgresql.org/support/security/
* Versioning Policy: https://www.postgresql.org/support/versioning/
* Follow @postgresql on Twitter: https://twitter.com/postgresql


--ktkpTzkNAYlko9Y0dKieRr9KRRgd3dIKo--

--2rwxvRb2e0uDrCObp3FkeVWxoyBMIWAjY
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE+oS2la8r95ogZD/x8QSccp8cZScFAl3nzjIACgkQ8QSccp8c
ZSfWyA/8C9zW3jQa2KwQGCP8G2xc7DhwhjiUTHgZKKcmYWY8t7nuIeUG39bt2nNQ
TjH41+Bz0jhDgsakTH8Ewvd3e+ICGNrAs1e2TJaIylaQXtcp515Djlj6sOCdTIfW
BNDF2PMW63FvPHLk8PW/z4ZbM9aoJMUuN1lJksSlxPBmUNMJOjT63GngWfjx+UDe
il7iaZJG4UOfwU6caaCs0LSviaVqjMO9Cvrr8SENzPJRbET5DkTwD4ramkqtcL70
HBX71sMFHQT6BXjcINISqSbLF7epyqVhI9AqEk87pJ0rCTDvZX+JA5EnbaGcdzfP
l5OXv7FNATv4A3J8W5s7ayqVAZ66qCuotVlPcBmVtvbupoFu4O10Bps/7blECk0W
G5ixG5ppMiLvvTpWy3fJGUHEatf5ECIpW5Bj/TioVgzXL2Jm0/gjGPxAAHH0lJ2s
kZKKjp4W/6U6BT9O9Nhpt0i9cwe/ZKRsupoNVPQa8HNLhWow/e/UAEgaKK6E2F4C
alNZ/rZ1VraT2b8KYOekAPH7niTL1im7p5ZuAEq8L+34UuGunRXWv+ZzL25fwGbH
55/fEokMEN1bplquv2u0qZqtaAshUuOQy+zb3hB7MJOFOG2lIfiO32/4S25axj8h
FMnlEy+48uf4YMmtZEax+TMRz2ur8XtDf0+CCN6xmGG3P7WMbac=
=uWeG
-----END PGP SIGNATURE-----

--2rwxvRb2e0uDrCObp3FkeVWxoyBMIWAjY--