Oval Definition:oval:org.opensuse.security:def:110727
Revision Date:2020-08-17Version:1
Title:Security update for postgresql, postgresql96, postgresql10, postgresql12 (Moderate)
Description:

This update for postgresql, postgresql96, postgresql10, postgresql12 fixes the following issues:

Postgresql12 was updated to 12.3 (bsc#1171924).

- https://www.postgresql.org/about/news/2038/ - https://www.postgresql.org/docs/12/release-12-3.html

- Let postgresqlXX conflict with postgresql-noarch < 12.0.1 to get a clean and complete cutover to the new packaging schema.

Also changed in the postgresql wrapper package:

- Bump version to 12.0.1, so that the binary packages also have a cut-point to conflict with.

- Conflict with versions of the binary packages prior to the May 2020 update, because we changed the package layout at that point and need a clean cutover.

- Bump package version to 12, but leave default at 10 for SLE-15 and SLE-15-SP1.

postgresql11 was updated to 11.9:



CVE-2020-14349, bsc#1175193: Set a secure search_path in logical replication walsenders and apply workers * CVE-2020-14350, bsc#1175194: Make contrib modules' installation scripts more secure. * https://www.postgresql.org/docs/11/release-11-9.html - Pack the /usr/lib/postgresql symlink only into the main package.

postgresql11 was updated to 11.8 (bsc#1171924).

https://www.postgresql.org/about/news/2038/ * https://www.postgresql.org/docs/11/release-11-8.html

- Unify the spec file to work across all current PostgreSQL versions to simplify future maintenance. - Move from the 'libs' build flavour to a 'mini' package that will only be used inside the build service and not get shipped, to avoid confusion with the debuginfo packages (bsc#1148643).

postgresql10 was updated to 10.13 (bsc#1171924).

- https://www.postgresql.org/about/news/2038/ - https://www.postgresql.org/docs/10/release-10-13.html

- Unify the spec file to work across all current PostgreSQL versions to simplify future maintenance. - Move from the 'libs' build flavour to a 'mini' package that will only be used inside the build service and not get shipped, to avoid confusion with the debuginfo packages (bsc#1148643).

postgresql96 was updated to 9.6.19:

* CVE-2020-14350, boo#1175194: Make contrib modules' installation scripts more secure. * https://www.postgresql.org/docs/9.6/release-9-6-19.html

- Pack the /usr/lib/postgresql symlink only into the main package.

- Let postgresqlXX conflict with postgresql-noarch < 12.0.1 to get a clean and complete cutover to the new packaging schema.

- update to 9.6.18 (boo#1171924). https://www.postgresql.org/about/news/2038/ https://www.postgresql.org/docs/9.6/release-9-6-18.html - Unify the spec file to work across all current PostgreSQL versions to simplify future maintenance. - Move from the 'libs' build flavour to a 'mini' package that will only be used inside the build service and not get shipped, to avoid confusion with the debuginfo packages (boo#1148643).

This update was imported from the SUSE:SLE-15-SP2:Update update project.
Family:unixClass:patch
Status:Reference(s):1148643
1171924
1175193
1175194
CVE-2020-14349
CVE-2020-14350
openSUSE-SU-2020:1228-1
Platform(s):openSUSE Leap 15.2
Product(s):
Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • libecpg6-12.3-lp152.3.4.1 is installed
  • OR libecpg6-32bit-12.3-lp152.3.4.1 is installed
  • OR libpq5-12.3-lp152.3.4.1 is installed
  • OR libpq5-32bit-12.3-lp152.3.4.1 is installed
  • OR postgresql-12.0.1-lp152.3.3.2 is installed
  • OR postgresql-contrib-12.0.1-lp152.3.3.2 is installed
  • OR postgresql-devel-12.0.1-lp152.3.3.2 is installed
  • OR postgresql-docs-12.0.1-lp152.3.3.2 is installed
  • OR postgresql-llvmjit-12.0.1-lp152.3.3.2 is installed
  • OR postgresql-plperl-12.0.1-lp152.3.3.2 is installed
  • OR postgresql-plpython-12.0.1-lp152.3.3.2 is installed
  • OR postgresql-pltcl-12.0.1-lp152.3.3.2 is installed
  • OR postgresql-server-12.0.1-lp152.3.3.2 is installed
  • OR postgresql-server-devel-12.0.1-lp152.3.3.2 is installed
  • OR postgresql-test-12.0.1-lp152.3.3.2 is installed
  • OR postgresql10-10.13-lp152.2.3.1 is installed
  • OR postgresql10-contrib-10.13-lp152.2.3.1 is installed
  • OR postgresql10-devel-10.13-lp152.2.3.1 is installed
  • OR postgresql10-docs-10.13-lp152.2.3.1 is installed
  • OR postgresql10-plperl-10.13-lp152.2.3.1 is installed
  • OR postgresql10-plpython-10.13-lp152.2.3.1 is installed
  • OR postgresql10-pltcl-10.13-lp152.2.3.1 is installed
  • OR postgresql10-server-10.13-lp152.2.3.1 is installed
  • OR postgresql10-test-10.13-lp152.2.3.1 is installed
  • OR postgresql11-11.9-lp152.3.3.1 is installed
  • OR postgresql11-contrib-11.9-lp152.3.3.1 is installed
  • OR postgresql11-devel-11.9-lp152.3.3.1 is installed
  • OR postgresql11-docs-11.9-lp152.3.3.1 is installed
  • OR postgresql11-llvmjit-11.9-lp152.3.3.1 is installed
  • OR postgresql11-plperl-11.9-lp152.3.3.1 is installed
  • OR postgresql11-plpython-11.9-lp152.3.3.1 is installed
  • OR postgresql11-pltcl-11.9-lp152.3.3.1 is installed
  • OR postgresql11-server-11.9-lp152.3.3.1 is installed
  • OR postgresql11-server-devel-11.9-lp152.3.3.1 is installed
  • OR postgresql11-test-11.9-lp152.3.3.1 is installed
  • OR postgresql12-12.3-lp152.3.4.1 is installed
  • OR postgresql12-contrib-12.3-lp152.3.4.1 is installed
  • OR postgresql12-devel-12.3-lp152.3.4.1 is installed
  • OR postgresql12-docs-12.3-lp152.3.4.1 is installed
  • OR postgresql12-llvmjit-12.3-lp152.3.4.1 is installed
  • OR postgresql12-plperl-12.3-lp152.3.4.1 is installed
  • OR postgresql12-plpython-12.3-lp152.3.4.1 is installed
  • OR postgresql12-pltcl-12.3-lp152.3.4.1 is installed
  • OR postgresql12-server-12.3-lp152.3.4.1 is installed
  • OR postgresql12-server-devel-12.3-lp152.3.4.1 is installed
  • OR postgresql12-test-12.3-lp152.3.4.1 is installed
  • OR postgresql96-9.6.19-lp152.2.3.1 is installed
  • OR postgresql96-contrib-9.6.19-lp152.2.3.1 is installed
  • OR postgresql96-devel-9.6.19-lp152.2.3.1 is installed
  • OR postgresql96-docs-9.6.19-lp152.2.3.1 is installed
  • OR postgresql96-plperl-9.6.19-lp152.2.3.1 is installed
  • OR postgresql96-plpython-9.6.19-lp152.2.3.1 is installed
  • OR postgresql96-pltcl-9.6.19-lp152.2.3.1 is installed
  • OR postgresql96-server-9.6.19-lp152.2.3.1 is installed
  • OR postgresql96-test-9.6.19-lp152.2.3.1 is installed
  • BACK