-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: rh-postgresql10-postgresql security update
Advisory ID:       RHSA-2020:0980-01
Product:           Red Hat Software Collections
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:0980
Issue date:        2020-03-26
CVE Names:         CVE-2019-10164 CVE-2020-1720 
====================================================================
1. Summary:

An update for rh-postgresql10-postgresql is now available for Red Hat
Software Collections.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - aarch64, ppc64le, s390x, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5) - ppc64le, s390x, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - ppc64le, s390x, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - ppc64le, s390x, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - x86_64

3. Description:

PostgreSQL is an advanced object-relational database management system
(DBMS).

The following packages have been upgraded to a later upstream version:
rh-postgresql10-postgresql (10.12).

Security Fix(es):

* PostgreSQL: stack-based buffer overflow via setting a password
(CVE-2019-10164)

* PostgreSQL: ALTER ... DEPENDS ON EXTENSION is missing authorization
checks (CVE-2020-1720)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

If the postgresql service is running, it will be automatically restarted
after installing this update.

5. Bugs fixed (https://bugzilla.redhat.com/):

1719698 - CVE-2019-10164 PostgreSQL: stack-based buffer overflow via setting a password
1798852 - CVE-2020-1720 PostgreSQL: ALTER ... DEPENDS ON EXTENSION is missing authorization checks
1813210 - rh-postgresql10-postgresql-devel provides  pkgconfig(libpq)
1813371 - Persistent Postgres Upgrade using Gluster File PVs fails on Socket Issue [rh-postgresql10]

6. Package List:

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):

Source:
rh-postgresql10-postgresql-10.12-2.el7.src.rpm

aarch64:
rh-postgresql10-postgresql-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-contrib-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-debuginfo-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-devel-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-docs-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-libs-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-plperl-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-plpython-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-pltcl-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-server-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-static-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-syspaths-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-test-10.12-2.el7.aarch64.rpm

ppc64le:
rh-postgresql10-postgresql-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-contrib-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-debuginfo-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-devel-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-docs-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-libs-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-plperl-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-plpython-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-pltcl-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-server-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-static-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-syspaths-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-test-10.12-2.el7.ppc64le.rpm

s390x:
rh-postgresql10-postgresql-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-contrib-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-debuginfo-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-devel-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-docs-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-libs-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-plperl-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-plpython-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-pltcl-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-server-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-static-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-syspaths-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-test-10.12-2.el7.s390x.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):

Source:
rh-postgresql10-postgresql-10.12-2.el7.src.rpm

aarch64:
rh-postgresql10-postgresql-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-contrib-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-debuginfo-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-devel-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-docs-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-libs-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-plperl-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-plpython-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-pltcl-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-server-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-static-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-syspaths-10.12-2.el7.aarch64.rpm
rh-postgresql10-postgresql-test-10.12-2.el7.aarch64.rpm

ppc64le:
rh-postgresql10-postgresql-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-contrib-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-debuginfo-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-devel-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-docs-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-libs-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-plperl-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-plpython-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-pltcl-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-server-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-static-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-syspaths-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-test-10.12-2.el7.ppc64le.rpm

s390x:
rh-postgresql10-postgresql-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-contrib-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-debuginfo-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-devel-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-docs-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-libs-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-plperl-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-plpython-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-pltcl-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-server-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-static-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-syspaths-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-test-10.12-2.el7.s390x.rpm

x86_64:
rh-postgresql10-postgresql-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-contrib-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-debuginfo-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-devel-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-docs-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-libs-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-plperl-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-plpython-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-pltcl-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-server-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-static-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-syspaths-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-test-10.12-2.el7.x86_64.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5):

Source:
rh-postgresql10-postgresql-10.12-2.el7.src.rpm

ppc64le:
rh-postgresql10-postgresql-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-contrib-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-debuginfo-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-devel-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-docs-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-libs-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-plperl-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-plpython-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-pltcl-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-server-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-static-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-syspaths-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-test-10.12-2.el7.ppc64le.rpm

s390x:
rh-postgresql10-postgresql-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-contrib-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-debuginfo-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-devel-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-docs-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-libs-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-plperl-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-plpython-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-pltcl-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-server-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-static-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-syspaths-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-test-10.12-2.el7.s390x.rpm

x86_64:
rh-postgresql10-postgresql-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-contrib-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-debuginfo-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-devel-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-docs-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-libs-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-plperl-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-plpython-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-pltcl-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-server-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-static-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-syspaths-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-test-10.12-2.el7.x86_64.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6):

Source:
rh-postgresql10-postgresql-10.12-2.el7.src.rpm

ppc64le:
rh-postgresql10-postgresql-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-contrib-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-debuginfo-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-devel-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-docs-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-libs-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-plperl-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-plpython-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-pltcl-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-server-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-static-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-syspaths-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-test-10.12-2.el7.ppc64le.rpm

s390x:
rh-postgresql10-postgresql-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-contrib-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-debuginfo-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-devel-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-docs-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-libs-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-plperl-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-plpython-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-pltcl-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-server-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-static-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-syspaths-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-test-10.12-2.el7.s390x.rpm

x86_64:
rh-postgresql10-postgresql-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-contrib-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-debuginfo-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-devel-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-docs-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-libs-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-plperl-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-plpython-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-pltcl-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-server-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-static-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-syspaths-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-test-10.12-2.el7.x86_64.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7):

Source:
rh-postgresql10-postgresql-10.12-2.el7.src.rpm

ppc64le:
rh-postgresql10-postgresql-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-contrib-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-debuginfo-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-devel-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-docs-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-libs-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-plperl-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-plpython-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-pltcl-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-server-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-static-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-syspaths-10.12-2.el7.ppc64le.rpm
rh-postgresql10-postgresql-test-10.12-2.el7.ppc64le.rpm

s390x:
rh-postgresql10-postgresql-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-contrib-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-debuginfo-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-devel-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-docs-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-libs-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-plperl-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-plpython-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-pltcl-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-server-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-static-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-syspaths-10.12-2.el7.s390x.rpm
rh-postgresql10-postgresql-test-10.12-2.el7.s390x.rpm

x86_64:
rh-postgresql10-postgresql-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-contrib-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-debuginfo-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-devel-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-docs-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-libs-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-plperl-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-plpython-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-pltcl-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-server-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-static-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-syspaths-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-test-10.12-2.el7.x86_64.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7):

Source:
rh-postgresql10-postgresql-10.12-2.el7.src.rpm

x86_64:
rh-postgresql10-postgresql-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-contrib-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-debuginfo-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-devel-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-docs-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-libs-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-plperl-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-plpython-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-pltcl-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-server-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-static-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-syspaths-10.12-2.el7.x86_64.rpm
rh-postgresql10-postgresql-test-10.12-2.el7.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2019-10164
https://access.redhat.com/security/cve/CVE-2020-1720
https://access.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXnygE9zjgjWX9erEAQjuNA/+P5cX0xtZ9ZbPCASG3ZfgsvhRl352Gzma
x+cz+WFJyhj/eyA+Z2u52obyPUP+lajq2YtZZdxk+7HsHzRwJ7lPPxwv6EVb7XSj
7H2MmTqeilcl8lqdeG6y6w0Z9HNJ5rTNAMFwrB5mNRR4U6IL7O4iSJmPQZT/iwtb
Ldk8Xbko2DL+RRCf9iaFMVkwY5qautBlGappnvpTlq2RBP2EhLsJP2n5NVL9UUNH
+8KzSr/9rPH/fQkHphNnWXBqGls2PrjnB/KrWUSVFZgYyVb6LWFG9h+IIM1/98vr
IjW+gtPzokBWnOyMKsYpsfEL7RGH0Eo+X0WWWEbBa9sjgv++PO9rHaF2bC3ZMXOq
rF2tKfwQLedIOth5JPXfSNamS7TKOw3vRwYaR8QiNdSyr+5PXiUa5FXhQbKaSuUZ
eMJXJjKb1vCCKMoJXzH4SdKXctJt12UHZ41WyYTjHWTaKEtt0ySbRq6zjwaP2jiv
TOU4xBa3nGUQp2xSrkSj7Ty6N67NmHaMj2h/+LycM5R1BvStWAtYCEeD59tHxoBY
nnzQT6X7vCbImhPvNfgd09a1tNypIqUWC5u/2ngLtccsEQ0WtGGG1WidQUWajuLg
zxCAKJiRnLSkvi/KC565I2dr5VeuUDQAp2f22v7cS26r+cFYSlfQmkuh3KqtKHrh
ZkjIvHgkYn8=LFzI
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2020-0980:01 Moderate: rh-postgresql10-postgresql security

An update for rh-postgresql10-postgresql is now available for Red Hat Software Collections

Summary

PostgreSQL is an advanced object-relational database management system (DBMS).
The following packages have been upgraded to a later upstream version: rh-postgresql10-postgresql (10.12).
Security Fix(es):
* PostgreSQL: stack-based buffer overflow via setting a password (CVE-2019-10164)
* PostgreSQL: ALTER ... DEPENDS ON EXTENSION is missing authorization checks (CVE-2020-1720)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258
If the postgresql service is running, it will be automatically restarted after installing this update.

References

https://access.redhat.com/security/cve/CVE-2019-10164 https://access.redhat.com/security/cve/CVE-2020-1720 https://access.redhat.com/security/updates/classification/#moderate

Package List

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source: rh-postgresql10-postgresql-10.12-2.el7.src.rpm
aarch64: rh-postgresql10-postgresql-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-contrib-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-debuginfo-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-devel-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-docs-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-libs-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-plperl-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-plpython-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-pltcl-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-server-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-static-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-syspaths-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-test-10.12-2.el7.aarch64.rpm
ppc64le: rh-postgresql10-postgresql-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-contrib-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-debuginfo-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-devel-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-docs-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-libs-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-plperl-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-plpython-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-pltcl-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-server-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-static-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-syspaths-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-test-10.12-2.el7.ppc64le.rpm
s390x: rh-postgresql10-postgresql-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-contrib-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-debuginfo-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-devel-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-docs-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-libs-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-plperl-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-plpython-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-pltcl-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-server-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-static-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-syspaths-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-test-10.12-2.el7.s390x.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source: rh-postgresql10-postgresql-10.12-2.el7.src.rpm
aarch64: rh-postgresql10-postgresql-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-contrib-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-debuginfo-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-devel-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-docs-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-libs-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-plperl-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-plpython-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-pltcl-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-server-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-static-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-syspaths-10.12-2.el7.aarch64.rpm rh-postgresql10-postgresql-test-10.12-2.el7.aarch64.rpm
ppc64le: rh-postgresql10-postgresql-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-contrib-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-debuginfo-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-devel-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-docs-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-libs-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-plperl-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-plpython-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-pltcl-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-server-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-static-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-syspaths-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-test-10.12-2.el7.ppc64le.rpm
s390x: rh-postgresql10-postgresql-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-contrib-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-debuginfo-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-devel-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-docs-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-libs-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-plperl-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-plpython-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-pltcl-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-server-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-static-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-syspaths-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-test-10.12-2.el7.s390x.rpm
x86_64: rh-postgresql10-postgresql-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-contrib-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-debuginfo-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-devel-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-docs-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-libs-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-plperl-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-plpython-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-pltcl-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-server-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-static-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-syspaths-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-test-10.12-2.el7.x86_64.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5):
Source: rh-postgresql10-postgresql-10.12-2.el7.src.rpm
ppc64le: rh-postgresql10-postgresql-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-contrib-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-debuginfo-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-devel-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-docs-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-libs-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-plperl-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-plpython-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-pltcl-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-server-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-static-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-syspaths-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-test-10.12-2.el7.ppc64le.rpm
s390x: rh-postgresql10-postgresql-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-contrib-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-debuginfo-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-devel-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-docs-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-libs-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-plperl-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-plpython-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-pltcl-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-server-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-static-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-syspaths-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-test-10.12-2.el7.s390x.rpm
x86_64: rh-postgresql10-postgresql-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-contrib-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-debuginfo-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-devel-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-docs-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-libs-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-plperl-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-plpython-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-pltcl-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-server-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-static-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-syspaths-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-test-10.12-2.el7.x86_64.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6):
Source: rh-postgresql10-postgresql-10.12-2.el7.src.rpm
ppc64le: rh-postgresql10-postgresql-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-contrib-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-debuginfo-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-devel-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-docs-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-libs-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-plperl-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-plpython-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-pltcl-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-server-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-static-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-syspaths-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-test-10.12-2.el7.ppc64le.rpm
s390x: rh-postgresql10-postgresql-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-contrib-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-debuginfo-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-devel-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-docs-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-libs-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-plperl-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-plpython-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-pltcl-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-server-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-static-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-syspaths-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-test-10.12-2.el7.s390x.rpm
x86_64: rh-postgresql10-postgresql-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-contrib-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-debuginfo-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-devel-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-docs-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-libs-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-plperl-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-plpython-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-pltcl-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-server-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-static-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-syspaths-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-test-10.12-2.el7.x86_64.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7):
Source: rh-postgresql10-postgresql-10.12-2.el7.src.rpm
ppc64le: rh-postgresql10-postgresql-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-contrib-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-debuginfo-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-devel-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-docs-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-libs-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-plperl-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-plpython-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-pltcl-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-server-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-static-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-syspaths-10.12-2.el7.ppc64le.rpm rh-postgresql10-postgresql-test-10.12-2.el7.ppc64le.rpm
s390x: rh-postgresql10-postgresql-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-contrib-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-debuginfo-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-devel-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-docs-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-libs-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-plperl-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-plpython-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-pltcl-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-server-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-static-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-syspaths-10.12-2.el7.s390x.rpm rh-postgresql10-postgresql-test-10.12-2.el7.s390x.rpm
x86_64: rh-postgresql10-postgresql-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-contrib-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-debuginfo-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-devel-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-docs-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-libs-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-plperl-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-plpython-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-pltcl-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-server-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-static-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-syspaths-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-test-10.12-2.el7.x86_64.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7):
Source: rh-postgresql10-postgresql-10.12-2.el7.src.rpm
x86_64: rh-postgresql10-postgresql-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-contrib-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-contrib-syspaths-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-debuginfo-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-devel-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-docs-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-libs-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-plperl-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-plpython-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-pltcl-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-server-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-server-syspaths-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-static-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-syspaths-10.12-2.el7.x86_64.rpm rh-postgresql10-postgresql-test-10.12-2.el7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2020:0980-01
Product: Red Hat Software Collections
Advisory URL: https://access.redhat.com/errata/RHSA-2020:0980
Issued Date: : 2020-03-26
CVE Names: CVE-2019-10164 CVE-2020-1720

Topic

An update for rh-postgresql10-postgresql is now available for Red HatSoftware Collections.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - aarch64, ppc64le, s390x, x86_64

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5) - ppc64le, s390x, x86_64

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - ppc64le, s390x, x86_64

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - ppc64le, s390x, x86_64

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - x86_64


Bugs Fixed

1719698 - CVE-2019-10164 PostgreSQL: stack-based buffer overflow via setting a password

1798852 - CVE-2020-1720 PostgreSQL: ALTER ... DEPENDS ON EXTENSION is missing authorization checks

1813210 - rh-postgresql10-postgresql-devel provides pkgconfig(libpq)

1813371 - Persistent Postgres Upgrade using Gluster File PVs fails on Socket Issue [rh-postgresql10]


Related News