Sign Up
Log In
Log In
or
Sign Up
Places
All Projects
Status Monitor
Collapse sidebar
openSUSE:Step:15-SP2
patchinfo.17475
_patchinfo
Overview
Repositories
Revisions
Requests
Users
Attributes
Meta
File _patchinfo of Package patchinfo.17475
<patchinfo incident="17475"> <issue tracker="bnc" id="1178668">VUL-0: CVE-2020-25696: postgresql96,postgresql10,postgresql12: \gset command from modifying specially-treated variables</issue> <issue tracker="bnc" id="1178667">VUL-0: CVE-2020-25694: postgresql96,postgresql10,postgresql12: Fix usage of complex connection-string parameters in pg_ tools</issue> <issue tracker="bnc" id="1178961">got a weird warning when removing "postgresql10-devel" package</issue> <issue tracker="bnc" id="1178666">VUL-0: CVE-2020-25695: postgresql96,postgresql10,postgresql12: potential query escalation</issue> <issue tracker="cve" id="2020-25695"/> <issue tracker="cve" id="2020-25696"/> <issue tracker="cve" id="2020-25694"/> <issue tracker="jsc" id="ECO-3049"/> <packager>rmax</packager> <rating>moderate</rating> <category>security</category> <summary>Security update for postgresql, postgresql13</summary> <description>This update for postgresql, postgresql13 fixes the following issues: This update ships postgresql13. Upgrade to version 13.1: * CVE-2020-25695, bsc#1178666: Block DECLARE CURSOR ... WITH HOLD and firing of deferred triggers within index expressions and materialized view queries. * CVE-2020-25694, bsc#1178667: a) Fix usage of complex connection-string parameters in pg_dump, pg_restore, clusterdb, reindexdb, and vacuumdb. b) When psql's \connect command re-uses connection parameters, ensure that all non-overridden parameters from a previous connection string are re-used. * CVE-2020-25696, bsc#1178668: Prevent psql's \gset command from modifying specially-treated variables. * Fix recently-added timetz test case so it works when the USA is not observing daylight savings time. (obsoletes postgresql-timetz.patch) * https://www.postgresql.org/about/news/2111/ * https://www.postgresql.org/docs/13/release-13-1.html Initial packaging of PostgreSQL 13: * https://www.postgresql.org/about/news/2077/ * https://www.postgresql.org/docs/13/release-13.html - bsc#1178961: %ghost the symlinks to pg_config and ecpg. Changes in postgresql wrapper package: - Bump major version to 13. - We also transfer PostgreSQL 9.4.26 to the new package layout in SLE12-SP2 and newer. Reflect this in the conflict with postgresql94. - Also conflict with PostgreSQL versions before 9. - Conflicting with older versions is not limited to SLE. </description> </patchinfo>
Locations
Projects
Search
Status Monitor
Help
OpenBuildService.org
Documentation
API Documentation
Code of Conduct
Contact
Support
@OBShq
Terms
openSUSE Build Service is sponsored by
The Open Build Service is an
openSUSE project
.
Sign Up
Log In
Places
Places
All Projects
Status Monitor