Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

openSUSE 13.2: SU-2016:2425-2 Critical Vulnerabilities in PostgreSQL94

opensuse
Calendar Grey September 30, 2016
Dist Opensuse Esm H88
A crucial openSUSE security patch for postgresql94 tackles various vulnerabilities and enhances system reliability.
An update that fixes two vulnerabilities is now available

Description

The postgresql server postgresql93 was updated to 9.3.14 fixes the

following issues:

Update to version 9.3.14:

* Fix possible mis-evaluation of nested CASE-WHEN expressions

(CVE-2016-5423, boo#993454)

* Fix client programs' handling of special characters in database and role

names (CVE-2016-5424, boo#993453)

* Fix corner-case misbehaviors for IS NULL/IS NOT NULL applied to nested

composite values

* Make the inet and cidr data types properly reject IPv6 addresses with

too many colon-separated fields

* Prevent crash in close_ps() (the point ## lseg operator) for NaN input

coordinates

* Fix several one-byte buffer over-reads in to_number()

* Avoid unsafe intermediate state during expensive paths through

heap_update()

* For the other bug fixes, see the release notes:

https://www.postgresql.org/docs/9.3/release-9-3-14.html

Update to version 9.3.13:

This update fixes several problems which caused downtime for...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.2:

zypper in -t patch openSUSE-2016-1140=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.2 (i586 x86_64):

libecpg6-9.3.14-2.13.1

libecpg6-debuginfo-9.3.14-2.13.1

libpq5-9.3.14-2.13.1

libpq5-debuginfo-9.3.14-2.13.1

postgresql93-9.3.14-2.13.1

postgresql93-contrib-9.3.14-2.13.1

postgresql93-contrib-debuginfo-9.3.14-2.13.1

postgresql93-debuginfo-9.3.14-2.13.1

postgresql93-debugsource-9.3.14-2.13.1

postgresql93-devel-9.3.14-2.13.1

postgresql93-devel-debuginfo-9.3.14-2.13.1

postgresql93-libs-debugsource-9.3.14-2.13.1

postgresql93-plperl-9.3.14-2.13.1

postgresql93-plperl-debuginfo-9.3.14-2.13.1

postgresql93-plpython-9.3.14-2.13.1

postgresql93-plpython-debuginfo-9.3.14-2.13.1

postgresql93-pltcl-9.3.14-2.13.1

postgresql93-pltcl-debuginfo-9.3.14-2.13.1

postgresql93-server-9.3.14-2.13.1

postgresql93-server-debuginfo-9.3.14-2.13.1

postgresql93-test-9.3.14-2.13.1

- openSUSE 13.2 (noarch):

postgresql93-docs-9.3.14-2.13.1

- openSUSE 13.2 (x86_64):

libecpg6-32bit-9.3.14-2.13.1

libecpg6-debuginfo-32bit-9.3.14-2.13.1

libpq5-32bit-9.3.14-2.13.1

libpq5-debuginfo-32bit-9.3.14-2.13.1

References

https://www.suse.com/security/cve/CVE-2016-5423.html

https://www.suse.com/security/cve/CVE-2016-5424.html

https://bugzilla.suse.com/993453

https://bugzilla.suse.com/993454

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:2425-1
Rating: important
Affected Products: openSUSE 13.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here