Oval Definition:oval:org.opensuse.security:def:66785
Revision Date:2021-01-20Version:1
Title:Security update for postgresql, postgresql13 (Moderate)
Description:

This update for postgresql, postgresql13 fixes the following issues:

This update ships postgresql13.

Upgrade to version 13.1:

CVE-2020-25695, bsc#1178666: Block DECLARE CURSOR ... WITH HOLD and firing of deferred triggers within index expressions and materialized view queries. * CVE-2020-25694, bsc#1178667: a) Fix usage of complex connection-string parameters in pg_dump, pg_restore, clusterdb, reindexdb, and vacuumdb. b) When psql's \connect command re-uses connection parameters, ensure that all non-overridden parameters from a previous connection string are re-used. * CVE-2020-25696, bsc#1178668: Prevent psql's \gset command from modifying specially-treated variables. * Fix recently-added timetz test case so it works when the USA is not observing daylight savings time. (obsoletes postgresql-timetz.patch) * https://www.postgresql.org/about/news/2111/ * https://www.postgresql.org/docs/13/release-13-1.html

Initial packaging of PostgreSQL 13:

https://www.postgresql.org/about/news/2077/ * https://www.postgresql.org/docs/13/release-13.html

- bsc#1178961: %ghost the symlinks to pg_config and ecpg.

Changes in postgresql wrapper package:

- Bump major version to 13. - We also transfer PostgreSQL 9.4.26 to the new package layout in SLE12-SP2 and newer. Reflect this in the conflict with postgresql94. - Also conflict with PostgreSQL versions before 9. - Conflicting with older versions is not limited to SLE.
Family:unixClass:patch
Status:Reference(s):1178666
1178667
1178668
1178961
CVE-2017-5884
CVE-2017-5885
CVE-2019-15681
CVE-2020-25694
CVE-2020-25695
CVE-2020-25696
Platform(s):SUSE Linux Enterprise Module for Desktop Applications 15 SP2
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2
SUSE Linux Enterprise Module for Server Applications 15 SP2
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Desktop Applications 15 SP2 is installed
  • AND Package Information
  • vino-3.22.0-9 is installed
  • OR vino-lang-3.22.0-9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 SP2 is installed
  • AND Package Information
  • gtk-vnc-devel-1.0.0-2 is installed
  • OR libgvncpulse-1_0-0-1.0.0-2 is installed
  • OR typelib-1_0-GVnc-1_0-1.0.0-2 is installed
  • OR typelib-1_0-GVncPulse-1_0-1.0.0-2 is installed
  • OR typelib-1_0-GtkVnc-1_0-0.7.2-1 is installed
  • OR typelib-1_0-GtkVnc-2_0-1.0.0-2 is installed
  • BACK