Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-RU-2020:1280-1

Опубликовано: 14 мая 2020
Источник: suse-cvrf

Описание

Recommended update for postgresql, postgresql10, postgresql12

This update for postgresql, postgresql10, postgresql12 fixes the following issues:

Changes in the postgresql wrapper package:

  • Sync ownership of /run/postgresql in the file list with tmpfiles.
  • Use the correct content for .bash_profile (bsc#1153168).
  • Stop shipping SUSEfirewall2 config files (bsc#1151591).
  • Use /run/postgresql instead of /var/run/postgresql in %ghost and postgresql-tmpfiles.conf to avoid rpmlint warnings and errors.
  • add /var/run/postgresql to the filelist. as %ghost for systemd systems and directly for non systemd systems

Changes in postgresql10:

  • packaging changed to no longer build the libraries, these now come from postgresql12.

Changes in postgresql12:

Initial package for the postgresql 12 branch

https://www.postgresql.org/about/news/1976/

python-psycopg2 was updated to 2.8.4 to allow working with postgresql12.

Список пакетов

Container suse/manager/5.0/x86_64/server:latest
python3-psycopg2-2.8.4-5.4.6
Container suse/postgres:10
postgresql10-10.12-8.13.10
postgresql10-server-10.12-8.13.10
Image SLES15-SP1-Manager-4-0-Azure-BYOS-Server
libpq5-12.2-3.5.2
postgresql-12-8.11.3
postgresql-contrib-12-8.11.3
postgresql-server-12-8.11.3
postgresql10-10.12-8.13.10
postgresql10-contrib-10.12-8.13.10
postgresql10-server-10.12-8.13.10
python3-psycopg2-2.8.4-5.4.6
Image SLES15-SP1-Manager-4-0-EC2-HVM-BYOS-Server
libpq5-12.2-3.5.2
postgresql-12-8.11.3
postgresql-contrib-12-8.11.3
postgresql-server-12-8.11.3
postgresql10-10.12-8.13.10
postgresql10-contrib-10.12-8.13.10
postgresql10-server-10.12-8.13.10
python3-psycopg2-2.8.4-5.4.6
Image SLES15-SP1-Manager-4-0-GCE-BYOS-Server
libpq5-12.2-3.5.2
postgresql-12-8.11.3
postgresql-contrib-12-8.11.3
postgresql-server-12-8.11.3
postgresql10-10.12-8.13.10
postgresql10-contrib-10.12-8.13.10
postgresql10-server-10.12-8.13.10
python3-psycopg2-2.8.4-5.4.6
Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure
python3-psycopg2-2.8.4-5.4.6
Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM
python3-psycopg2-2.8.4-5.4.6
Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE
python3-psycopg2-2.8.4-5.4.6
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure
python3-psycopg2-2.8.4-5.4.6
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM
python3-psycopg2-2.8.4-5.4.6
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE
python3-psycopg2-2.8.4-5.4.6
Image SLES15-SP4-Manager-Server-4-3
python3-psycopg2-2.8.4-5.4.6
Image SLES15-SP4-Manager-Server-4-3-Azure-llc
python3-psycopg2-2.8.4-5.4.6
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd
python3-psycopg2-2.8.4-5.4.6
Image SLES15-SP4-Manager-Server-4-3-BYOS
python3-psycopg2-2.8.4-5.4.6
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure
python3-psycopg2-2.8.4-5.4.6
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
python3-psycopg2-2.8.4-5.4.6
Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE
python3-psycopg2-2.8.4-5.4.6
Image SLES15-SP4-Manager-Server-4-3-EC2-llc
python3-psycopg2-2.8.4-5.4.6
Image SLES15-SP4-Manager-Server-4-3-EC2-ltd
python3-psycopg2-2.8.4-5.4.6
Image server-image
python3-psycopg2-2.8.4-5.4.6
SUSE Linux Enterprise Module for Basesystem 15 SP1
libpq5-12.2-3.5.2
postgresql-12-8.11.3
postgresql10-10.12-8.13.10
postgresql12-12.2-3.5.2
python3-psycopg2-2.8.4-5.4.6
SUSE Linux Enterprise Module for Server Applications 15 SP1
libecpg6-12.2-3.5.2
postgresql-contrib-12-8.11.3
postgresql-devel-12-8.11.3
postgresql-docs-12-8.11.3
postgresql-plperl-12-8.11.3
postgresql-plpython-12-8.11.3
postgresql-pltcl-12-8.11.3
postgresql-server-12-8.11.3
postgresql-server-devel-12-8.11.3
postgresql10-contrib-10.12-8.13.10
postgresql10-devel-10.12-8.13.9
postgresql10-docs-10.12-8.13.10
postgresql10-plperl-10.12-8.13.10
postgresql10-plpython-10.12-8.13.10
postgresql10-pltcl-10.12-8.13.10
postgresql10-server-10.12-8.13.10
postgresql12-contrib-12.2-3.5.2
postgresql12-devel-12.2-3.5.2
postgresql12-docs-12.2-3.5.2
postgresql12-plperl-12.2-3.5.2
postgresql12-plpython-12.2-3.5.2
postgresql12-pltcl-12.2-3.5.2
postgresql12-server-12.2-3.5.2
postgresql12-server-devel-12.2-3.5.2

Описание

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:python3-psycopg2-2.8.4-5.4.6
Container suse/postgres:10:postgresql10-10.12-8.13.10
Container suse/postgres:10:postgresql10-server-10.12-8.13.10
Image SLES15-SP1-Manager-4-0-Azure-BYOS-Server:libpq5-12.2-3.5.2

Ссылки

Описание

A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database corruption. This issue affects PostgreSQL versions before 12.2, before 11.7, before 10.12 and before 9.6.17.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:python3-psycopg2-2.8.4-5.4.6
Container suse/postgres:10:postgresql10-10.12-8.13.10
Container suse/postgres:10:postgresql10-server-10.12-8.13.10
Image SLES15-SP1-Manager-4-0-Azure-BYOS-Server:libpq5-12.2-3.5.2

Ссылки
Уязвимость SUSE-RU-2020:1280-1