Oval Definition:oval:org.opensuse.security:def:59699
Revision Date:2020-12-04Version:1
Title:Security update for postgresql12 (Important)
Description:



This update for postgresql12 fixes the following issues:

Upgrade to version 12.5:

CVE-2020-25695, bsc#1178666: Block DECLARE CURSOR ... WITH HOLD and firing of deferred triggers within index expressions and materialized view queries. * CVE-2020-25694, bsc#1178667: a) Fix usage of complex connection-string parameters in pg_dump, pg_restore, clusterdb, reindexdb, and vacuumdb. b) When psql's \connect command re-uses connection parameters, ensure that all non-overridden parameters from a previous connection string are re-used. * CVE-2020-25696, bsc#1178668: Prevent psql's \gset command from modifying specially-treated variables. * Fix recently-added timetz test case so it works when the USA is not observing daylight savings time. (obsoletes postgresql-timetz.patch) * https://www.postgresql.org/about/news/2111/ * https://www.postgresql.org/docs/12/release-12-5.html

The previous postgresql12 update already addressed:

Update to 12.4:

CVE-2020-14349, bsc#1175193: Set a secure search_path in logical replication walsenders and apply workers * CVE-2020-14350, bsc#1175194: Make contrib modules' installation scripts more secure.

https://www.postgresql.org/docs/12/release-12-4.html


Family:unixClass:patch
Status:Reference(s):1012382
1031717
1046610
1057734
1070536
1075428
1076847
1077560
1081741
1082153
1082299
1083125
1083745
1083836
1084353
1084610
1084721
1084829
1085042
1085185
1085224
1085402
1085404
1086162
1086194
1087088
1087260
1087845
1088241
1088242
1088600
1088684
1089198
1089608
1089644
1089752
1090643
1095218
1095219
1103040
1103411
1104457
1104467
1110723
1110949
1114837
1118597
1122292
1122293
1122299
1128158
1130246
1140738
1141329
1141332
1141780
1141782
1141783
1141785
1141787
1141789
1147021
1161167
1162610
1170170
1173100
1173659
1173661
1173869
1173942
1173963
1174247
1174922
1174923
1175193
1175194
1178666
1178667
1178668
CVE-2009-0186
CVE-2011-2696
CVE-2014-9496
CVE-2014-9756
CVE-2015-7805
CVE-2015-8075
CVE-2017-18257
CVE-2017-7585
CVE-2017-7586
CVE-2017-7741
CVE-2017-7742
CVE-2017-8361
CVE-2017-8362
CVE-2017-8363
CVE-2017-8365
CVE-2018-10087
CVE-2018-10124
CVE-2018-1050
CVE-2018-10858
CVE-2018-1087
CVE-2018-11212
CVE-2018-11212
CVE-2018-11233
CVE-2018-11235
CVE-2018-14680
CVE-2018-14681
CVE-2018-14682
CVE-2018-15378
CVE-2018-16850
CVE-2018-17204
CVE-2018-17205
CVE-2018-17206
CVE-2018-17456
CVE-2018-1890
CVE-2018-19870
CVE-2018-19872
CVE-2018-7740
CVE-2018-8043
CVE-2018-8781
CVE-2018-8822
CVE-2018-8897
CVE-2019-11771
CVE-2019-11772
CVE-2019-11775
CVE-2019-12525
CVE-2019-12529
CVE-2019-13345
CVE-2019-14895
CVE-2019-14901
CVE-2019-16746
CVE-2019-19447
CVE-2019-2422
CVE-2019-2449
CVE-2019-2449
CVE-2019-2762
CVE-2019-2766
CVE-2019-2769
CVE-2019-2786
CVE-2019-2816
CVE-2019-4473
CVE-2019-7317
CVE-2019-9458
CVE-2020-0569
CVE-2020-11668
CVE-2020-12059
CVE-2020-12673
CVE-2020-12674
CVE-2020-14331
CVE-2020-14349
CVE-2020-14350
CVE-2020-25694
CVE-2020-25695
CVE-2020-25696
CVE-2020-8597
SUSE-SU-2018:1566-1
SUSE-SU-2018:3770-1
SUSE-SU-2018:4088-1
SUSE-SU-2018:4128-1
SUSE-SU-2019:2371-1
SUSE-SU-2020:0318-1
SUSE-SU-2020:0490-1
SUSE-SU-2020:1158-1
SUSE-SU-2020:2274-1
SUSE-SU-2020:3630-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-ESPOS
SUSE Linux Enterprise Server 12 SP4-LTSS
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • xorg-x11-server-1.19.6-lp150.6 is installed
  • OR xorg-x11-server-extra-1.19.6-lp150.6 is installed
  • OR xorg-x11-server-wayland-1.19.6-lp150.6 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • go1.12-1.12.9-lp151.2.17 is installed
  • OR go1.12-doc-1.12.9-lp151.2.17 is installed
  • OR go1.12-race-1.12.9-lp151.2.17 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • libQt5Concurrent5-5.6.1-17.13 is installed
  • OR libQt5Core5-5.6.1-17.13 is installed
  • OR libQt5DBus5-5.6.1-17.13 is installed
  • OR libQt5Gui5-5.6.1-17.13 is installed
  • OR libQt5Network5-5.6.1-17.13 is installed
  • OR libQt5OpenGL5-5.6.1-17.13 is installed
  • OR libQt5PrintSupport5-5.6.1-17.13 is installed
  • OR libQt5Sql5-5.6.1-17.13 is installed
  • OR libQt5Sql5-mysql-5.6.1-17.13 is installed
  • OR libQt5Sql5-postgresql-5.6.1-17.13 is installed
  • OR libQt5Sql5-sqlite-5.6.1-17.13 is installed
  • OR libQt5Sql5-unixODBC-5.6.1-17.13 is installed
  • OR libQt5Test5-5.6.1-17.13 is installed
  • OR libQt5Widgets5-5.6.1-17.13 is installed
  • OR libQt5Xml5-5.6.1-17.13 is installed
  • OR libqt5-qtbase-5.6.1-17.13 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • libdcerpc-atsvc0-4.2.4-28.29 is installed
  • OR samba-4.2.4-28.29 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • libsndfile1-1.0.25-35 is installed
  • OR libsndfile1-32bit-1.0.25-35 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • MozillaFirefox-60.9.0-109.86 is installed
  • OR MozillaFirefox-translations-common-60.9.0-109.86 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • kernel-default-4.4.180-94.107 is installed
  • OR kernel-default-base-4.4.180-94.107 is installed
  • OR kernel-default-devel-4.4.180-94.107 is installed
  • OR kernel-default-kgraft-4.4.180-94.107 is installed
  • OR kernel-devel-4.4.180-94.107 is installed
  • OR kernel-macros-4.4.180-94.107 is installed
  • OR kernel-source-4.4.180-94.107 is installed
  • OR kernel-syms-4.4.180-94.107 is installed
  • OR kgraft-patch-4_4_180-94_107-default-1-4.3 is installed
  • OR kgraft-patch-SLE12-SP3_Update_29-1-4.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • ghostscript-9.27-23.28 is installed
  • OR ghostscript-x11-9.27-23.28 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • gnome-shell-search-provider-nautilus-3.20.3-23.6 is installed
  • OR libnautilus-extension1-3.20.3-23.6 is installed
  • OR nautilus-3.20.3-23.6 is installed
  • OR nautilus-lang-3.20.3-23.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • ghostscript-9.25-23.13 is installed
  • OR ghostscript-x11-9.25-23.13 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND Package Information
  • libfreebl3-3.53.1-58.48 is installed
  • OR libfreebl3-32bit-3.53.1-58.48 is installed
  • OR libfreebl3-hmac-3.53.1-58.48 is installed
  • OR libfreebl3-hmac-32bit-3.53.1-58.48 is installed
  • OR libsoftokn3-3.53.1-58.48 is installed
  • OR libsoftokn3-32bit-3.53.1-58.48 is installed
  • OR libsoftokn3-hmac-3.53.1-58.48 is installed
  • OR libsoftokn3-hmac-32bit-3.53.1-58.48 is installed
  • OR mozilla-nspr-4.25-19.15 is installed
  • OR mozilla-nspr-32bit-4.25-19.15 is installed
  • OR mozilla-nspr-devel-4.25-19.15 is installed
  • OR mozilla-nss-3.53.1-58.48 is installed
  • OR mozilla-nss-32bit-3.53.1-58.48 is installed
  • OR mozilla-nss-certs-3.53.1-58.48 is installed
  • OR mozilla-nss-certs-32bit-3.53.1-58.48 is installed
  • OR mozilla-nss-devel-3.53.1-58.48 is installed
  • OR mozilla-nss-sysinit-3.53.1-58.48 is installed
  • OR mozilla-nss-sysinit-32bit-3.53.1-58.48 is installed
  • OR mozilla-nss-tools-3.53.1-58.48 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND Package Information
  • libecpg6-12.5-3.9.3 is installed
  • OR libpq5-12.5-3.9.3 is installed
  • OR libpq5-32bit-12.5-3.9.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • java-1_8_0-ibm-1.8.0_sr5.40-30.54 is installed
  • OR java-1_8_0-ibm-alsa-1.8.0_sr5.40-30.54 is installed
  • OR java-1_8_0-ibm-plugin-1.8.0_sr5.40-30.54 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • ceph-12.2.12+git.1587570958.35d78d0243-2.45 is installed
  • OR ceph-common-12.2.12+git.1587570958.35d78d0243-2.45 is installed
  • OR libcephfs2-12.2.12+git.1587570958.35d78d0243-2.45 is installed
  • OR librados2-12.2.12+git.1587570958.35d78d0243-2.45 is installed
  • OR libradosstriper1-12.2.12+git.1587570958.35d78d0243-2.45 is installed
  • OR librbd1-12.2.12+git.1587570958.35d78d0243-2.45 is installed
  • OR librgw2-12.2.12+git.1587570958.35d78d0243-2.45 is installed
  • OR python-cephfs-12.2.12+git.1587570958.35d78d0243-2.45 is installed
  • OR python-rados-12.2.12+git.1587570958.35d78d0243-2.45 is installed
  • OR python-rbd-12.2.12+git.1587570958.35d78d0243-2.45 is installed
  • OR python-rgw-12.2.12+git.1587570958.35d78d0243-2.45 is installed
  • BACK