Oval Definition:oval:org.opensuse.security:def:81184
Revision Date:2017-06-26Version:1
Title:Security update for postgresql94 (Moderate)
Description:

This update for postgresql94 to 9.4.12 fixes the following issues:

Upstream changelogs:

- https://www.postgresql.org/docs/9.4/static/release-9-4-12.html - https://www.postgresql.org/docs/9.4/static/release-9-4-11.html - https://www.postgresql.org/docs/9.4/static/release-9-4-10.html

Security issues fixed:

CVE-2017-7486: Restrict visibility of pg_user_mappings.umoptions, to protect passwords stored as user mapping options. (bsc#1037624)

Please note that manual action is needed to fix this in existing databases See the upstream release notes for details. * CVE-2017-7485: recognize PGREQUIRESSL variable again. (bsc#1038293) * CVE-2017-7484: Prevent exposure of statistical information via leaky operators. (bsc#1037603)

Changes in version 9.4.12:

Build corruption with CREATE INDEX CONCURRENTLY * Fixes for visibility and write-ahead-log stability

Changes in version 9.4.10:

Fix WAL-logging of truncation of relation free space maps and visibility maps * Fix incorrect creation of GIN index WAL records on big-endian machines * Fix SELECT FOR UPDATE/SHARE to correctly lock tuples that have been updated by a subsequently-aborted transaction * Fix EvalPlanQual rechecks involving CTE scans * Fix improper repetition of previous results from hashed aggregation in a subquery

The libraries libpq and libecpg are now supplied by postgresql 9.6.
Family:unixClass:patch
Status:Reference(s):1037603
1037624
1038293
CVE-2017-7484
CVE-2017-7485
CVE-2017-7486
SUSE-SU-2017:1690-1
Platform(s):SUSE Linux Enterprise Server 12 SP2
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • postgresql94-9.4.12-20.1 is installed
  • OR postgresql94-contrib-9.4.12-20.1 is installed
  • OR postgresql94-docs-9.4.12-20.1 is installed
  • OR postgresql94-server-9.4.12-20.1 is installed
  • BACK