Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

openSUSE Leap 15.0: 2018:2599-1 Moderate: PostgreSQL10 Security Fixes

opensuse
Calendar Grey September 4, 2018
Dist Opensuse Esm H88
A recent patch for Fedora tackles significant MySQL vulnerabilities while improving data security throughout various software platforms.
An update that fixes three vulnerabilities is now available.

Description

This update for postgresql10 fixes the following issues:

PostgreSQL 10 was updated to 10.5:

- https://www.postgresql.org/about/news/postgresql-104-969-9513-9418-and-9323-released-1851/

- https://www.postgresql.org/docs/10/release-10-5.html

A dump/restore is not required for those running 10.X. However, if you

use the adminpack extension, you should update it as per the first

changelog entry below. Also, if the function marking mistakes mentioned in

the second and third changelog entries below affect you, you will want to

take steps to correct your database catalogs.

Security issues fixed:

- CVE-2018-1115: Remove public execute privilege from contrib/adminpack's

pg_logfile_rotate() function pg_logfile_rotate() is a deprecated wrapper

for the core function pg_rotate_logfile(). When that function was

changed to rely on SQL privileges for access control rather than a

hard-coded superuser check, pg_logfile_rotate() should have...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2018-955=1

Package List

- openSUSE Leap 15.0 (i586 x86_64):

libecpg6-10.5-lp150.3.3.1

libecpg6-debuginfo-10.5-lp150.3.3.1

libpq5-10.5-lp150.3.3.1

libpq5-debuginfo-10.5-lp150.3.3.1

postgresql10-10.5-lp150.3.3.1

postgresql10-contrib-10.5-lp150.3.3.1

postgresql10-contrib-debuginfo-10.5-lp150.3.3.1

postgresql10-debuginfo-10.5-lp150.3.3.1

postgresql10-debugsource-10.5-lp150.3.3.1

postgresql10-devel-10.5-lp150.3.3.1

postgresql10-devel-debuginfo-10.5-lp150.3.3.1

postgresql10-plperl-10.5-lp150.3.3.1

postgresql10-plperl-debuginfo-10.5-lp150.3.3.1

postgresql10-plpython-10.5-lp150.3.3.1

postgresql10-plpython-debuginfo-10.5-lp150.3.3.1

postgresql10-pltcl-10.5-lp150.3.3.1

postgresql10-pltcl-debuginfo-10.5-lp150.3.3.1

postgresql10-server-10.5-lp150.3.3.1

postgresql10-server-debuginfo-10.5-lp150.3.3.1

postgresql10-test-10.5-lp150.3.3.1

- openSUSE Leap 15.0 (x86_64):

libecpg6-32bit-10.5-lp150.3.3.1

libecpg6-32bit-debuginfo-10.5-lp150.3.3.1

libpq5-32bit-10.5-lp150.3.3.1

libpq5-32bit-debuginfo-10.5-lp150.3.3.1

- openSUSE Leap 15.0 (noarch):

postgresql10...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2018-10915.html

https://www.suse.com/security/cve/CVE-2018-10925.html

https://www.suse.com/security/cve/CVE-2018-1115.html

https://bugzilla.suse.com/1091610

https://bugzilla.suse.com/1104199

https://bugzilla.suse.com/1104202

--

Announcement ID: openSUSE-SU-2018:2599-1
Rating: moderate
Affected Products: openSUSE Leap 15.0

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here