Oval Definition:oval:org.opensuse.security:def:59344
Revision Date:2020-12-01Version:1
Title:Security update for postgresql10 (Important)
Description:

This update for postgresql10 fixes the following issues:

Upgrade to version 10.15:

* CVE-2020-25695, bsc#1178666: Block DECLARE CURSOR ... WITH HOLD and firing of deferred triggers within index expressions and materialized view queries. * CVE-2020-25694, bsc#1178667: a) Fix usage of complex connection-string parameters in pg_dump, pg_restore, clusterdb, reindexdb, and vacuumdb. b) When psql's \connect command re-uses connection parameters, ensure that all non-overridden parameters from a previous connection string are re-used. * CVE-2020-25696, bsc#1178668: Prevent psql's \gset command from modifying specially-treated variables. * https://www.postgresql.org/about/news/2111/ * https://www.postgresql.org/docs/10/release-10-15.html

Update to 10.14:

* CVE-2020-14349, bsc#1175193: Set a secure search_path in logical replication walsenders and apply workers * CVE-2020-14350, bsc#1175194: Make contrib modules' installation scripts more secure. * https://www.postgresql.org/docs/10/release-10-14.html

Family:unixClass:patch
Status:Reference(s):1016715
1036304
1045735
1049825
1070851
1076192
1079334
1080891
1082023
1082318
1088681
1088705
1091624
1092413
1092493
1092544
1096803
1097410
1099847
1100028
1101349
1102429
1104826
1105988
1106873
1111331
1118021
1118024
1118099
1119069
1119105
1131595
1135273
1156323
1156324
1156326
1156328
1156329
1158785
1158787
1158788
1158789
1158790
1158791
1158792
1158793
1158795
1162687
1162689
1162691
1172031
1172225
1173991
1174284
1174415
1174421
1175193
1175194
1175686
1178666
1178667
1178668
CVE-2011-0523
CVE-2011-0524
CVE-2012-0862
CVE-2013-4342
CVE-2014-4362
CVE-2016-4975
CVE-2016-8743
CVE-2017-9269
CVE-2018-0495
CVE-2018-12126
CVE-2018-12127
CVE-2018-12130
CVE-2018-12384
CVE-2018-12404
CVE-2018-12405
CVE-2018-15869
CVE-2018-17466
CVE-2018-18492
CVE-2018-18493
CVE-2018-18494
CVE-2018-18498
CVE-2018-2755
CVE-2018-2759
CVE-2018-2761
CVE-2018-2766
CVE-2018-2767
CVE-2018-2771
CVE-2018-2777
CVE-2018-2781
CVE-2018-2782
CVE-2018-2784
CVE-2018-2786
CVE-2018-2787
CVE-2018-2810
CVE-2018-2813
CVE-2018-2817
CVE-2018-2819
CVE-2018-7685
CVE-2019-11091
CVE-2019-12523
CVE-2019-12526
CVE-2019-12528
CVE-2019-1348
CVE-2019-1349
CVE-2019-1350
CVE-2019-1351
CVE-2019-1352
CVE-2019-1353
CVE-2019-1354
CVE-2019-1387
CVE-2019-18676
CVE-2019-18677
CVE-2019-18678
CVE-2019-18679
CVE-2019-19604
CVE-2019-20807
CVE-2019-3886
CVE-2020-14349
CVE-2020-14350
CVE-2020-15663
CVE-2020-15664
CVE-2020-15670
CVE-2020-15705
CVE-2020-15900
CVE-2020-25694
CVE-2020-25695
CVE-2020-25696
CVE-2020-8449
CVE-2020-8450
CVE-2020-8517
SUSE-SU-2018:1771-1
SUSE-SU-2018:2716-2
SUSE-SU-2018:4236-1
SUSE-SU-2019:1438-1
SUSE-SU-2019:3311-1
SUSE-SU-2020:0251-1
SUSE-SU-2020:0661-1
SUSE-SU-2020:2097-1
SUSE-SU-2020:2308-1
SUSE-SU-2020:2544-1
SUSE-SU-2020:3464-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-LTSS
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND python2-paramiko-2.4.1-lp150.1 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • kernel-debug-4.12.14-lp151.28.10 is installed
  • OR kernel-debug-base-4.12.14-lp151.28.10 is installed
  • OR kernel-debug-devel-4.12.14-lp151.28.10 is installed
  • OR kernel-default-4.12.14-lp151.28.10 is installed
  • OR kernel-default-base-4.12.14-lp151.28.10 is installed
  • OR kernel-default-devel-4.12.14-lp151.28.10 is installed
  • OR kernel-devel-4.12.14-lp151.28.10 is installed
  • OR kernel-docs-4.12.14-lp151.28.10 is installed
  • OR kernel-docs-html-4.12.14-lp151.28.10 is installed
  • OR kernel-kvmsmall-4.12.14-lp151.28.10 is installed
  • OR kernel-kvmsmall-base-4.12.14-lp151.28.10 is installed
  • OR kernel-kvmsmall-devel-4.12.14-lp151.28.10 is installed
  • OR kernel-macros-4.12.14-lp151.28.10 is installed
  • OR kernel-obs-build-4.12.14-lp151.28.10 is installed
  • OR kernel-obs-qa-4.12.14-lp151.28.10 is installed
  • OR kernel-source-4.12.14-lp151.28.10 is installed
  • OR kernel-source-vanilla-4.12.14-lp151.28.10 is installed
  • OR kernel-syms-4.12.14-lp151.28.10 is installed
  • OR kernel-vanilla-4.12.14-lp151.28.10 is installed
  • OR kernel-vanilla-base-4.12.14-lp151.28.10 is installed
  • OR kernel-vanilla-devel-4.12.14-lp151.28.10 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • libzypp-16.17.20-27.52 is installed
  • OR zypper-1.13.45-18.33 is installed
  • OR zypper-log-1.13.45-18.33 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • apache2-2.4.23-29.24 is installed
  • OR apache2-doc-2.4.23-29.24 is installed
  • OR apache2-example-pages-2.4.23-29.24 is installed
  • OR apache2-prefork-2.4.23-29.24 is installed
  • OR apache2-utils-2.4.23-29.24 is installed
  • OR apache2-worker-2.4.23-29.24 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • postgresql10-10.15-4.9 is installed
  • OR postgresql10-contrib-10.15-4.9 is installed
  • OR postgresql10-docs-10.15-4.9 is installed
  • OR postgresql10-plperl-10.15-4.9 is installed
  • OR postgresql10-plpython-10.15-4.9 is installed
  • OR postgresql10-pltcl-10.15-4.9 is installed
  • OR postgresql10-server-10.15-4.9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND davfs2-1.5.2-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • kernel-default-4.4.180-94.107 is installed
  • OR kernel-default-base-4.4.180-94.107 is installed
  • OR kernel-default-devel-4.4.180-94.107 is installed
  • OR kernel-devel-4.4.180-94.107 is installed
  • OR kernel-macros-4.4.180-94.107 is installed
  • OR kernel-source-4.4.180-94.107 is installed
  • OR kernel-syms-4.4.180-94.107 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • bzip2-1.0.6-30.8 is installed
  • OR bzip2-doc-1.0.6-30.8 is installed
  • OR libbz2-1-1.0.6-30.8 is installed
  • OR libbz2-1-32bit-1.0.6-30.8 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • glibc-2.22-62.22 is installed
  • OR glibc-32bit-2.22-62.22 is installed
  • OR glibc-devel-2.22-62.22 is installed
  • OR glibc-devel-32bit-2.22-62.22 is installed
  • OR glibc-html-2.22-62.22 is installed
  • OR glibc-i18ndata-2.22-62.22 is installed
  • OR glibc-info-2.22-62.22 is installed
  • OR glibc-locale-2.22-62.22 is installed
  • OR glibc-locale-32bit-2.22-62.22 is installed
  • OR glibc-profile-2.22-62.22 is installed
  • OR glibc-profile-32bit-2.22-62.22 is installed
  • OR nscd-2.22-62.22 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • gdm-3.10.0.1-54.6 is installed
  • OR gdm-lang-3.10.0.1-54.6 is installed
  • OR gdmflexiserver-3.10.0.1-54.6 is installed
  • OR libgdm1-3.10.0.1-54.6 is installed
  • OR typelib-1_0-Gdm-1_0-3.10.0.1-54.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • DirectFB-1.7.1-6 is installed
  • OR lib++dfb-1_7-1-1.7.1-6 is installed
  • OR libdirectfb-1_7-1-1.7.1-6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND Package Information
  • xen-4.11.4_04-2.30 is installed
  • OR xen-doc-html-4.11.4_04-2.30 is installed
  • OR xen-libs-4.11.4_04-2.30 is installed
  • OR xen-libs-32bit-4.11.4_04-2.30 is installed
  • OR xen-tools-4.11.4_04-2.30 is installed
  • OR xen-tools-domU-4.11.4_04-2.30 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • libmariadb3-3.0.3-3.3 is installed
  • OR mariadb-10.2.15-4.3 is installed
  • OR mariadb-client-10.2.15-4.3 is installed
  • OR mariadb-connector-c-3.0.3-3.3 is installed
  • OR mariadb-errormessages-10.2.15-4.3 is installed
  • OR mariadb-galera-10.2.15-4.3 is installed
  • OR mariadb-tools-10.2.15-4.3 is installed
  • OR xtrabackup-2.4.10-4.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 9 is installed
  • AND xrdp-0.9.0~git.1456906198.f422461-21.27 is installed
  • BACK