summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--doc/src/sgml/release-8.2.sgml13
-rw-r--r--doc/src/sgml/release-8.3.sgml13
2 files changed, 26 insertions, 0 deletions
diff --git a/doc/src/sgml/release-8.2.sgml b/doc/src/sgml/release-8.2.sgml
index dd82ee69d3a..2dd49d6a063 100644
--- a/doc/src/sgml/release-8.2.sgml
+++ b/doc/src/sgml/release-8.2.sgml
@@ -102,6 +102,19 @@
<listitem>
<para>
+ Fix buffer overrun in <filename>contrib/intarray</>'s input function
+ for the <type>query_int</> type (Apple)
+ </para>
+
+ <para>
+ This bug is a security risk since the function's return address could
+ be overwritten. Thanks to Apple Inc's security team for reporting this
+ issue and supplying the fix. (CVE-2010-4015)
+ </para>
+ </listitem>
+
+ <listitem>
+ <para>
Fix bug in <filename>contrib/seg</>'s GiST picksplit algorithm
(Alexander Korotkov)
</para>
diff --git a/doc/src/sgml/release-8.3.sgml b/doc/src/sgml/release-8.3.sgml
index 5d691a4183f..c0595ab5df0 100644
--- a/doc/src/sgml/release-8.3.sgml
+++ b/doc/src/sgml/release-8.3.sgml
@@ -102,6 +102,19 @@
<listitem>
<para>
+ Fix buffer overrun in <filename>contrib/intarray</>'s input function
+ for the <type>query_int</> type (Apple)
+ </para>
+
+ <para>
+ This bug is a security risk since the function's return address could
+ be overwritten. Thanks to Apple Inc's security team for reporting this
+ issue and supplying the fix. (CVE-2010-4015)
+ </para>
+ </listitem>
+
+ <listitem>
+ <para>
Fix bug in <filename>contrib/seg</>'s GiST picksplit algorithm
(Alexander Korotkov)
</para>