Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

SUSE 11-SP4: 2016:0678-1 Critical: MySQL Denial Of Service

suse
Calendar Grey March 7, 2016
Dist Suse Esm H88
A significant enhancement has been released to tackle vital vulnerabilities within postgresql94 for openSUSE configurations. Upgrade promptly to protect your server.
An update that fixes 5 vulnerabilities is now available

Summary

This update for postgresql94 fixes the following issues: - Security and bugfix release 9.4.6: * *** IMPORTANT *** Users of version 9.4 will need to reindex any jsonb_path_ops indexes they have created, in order to fix a persistent issue with missing index entries. * Fix infinite loops and buffer-overrun problems in regular expressions (CVE-2016-0773, bsc#966436). * Fix regular-expression compiler to handle loops of constraint arcs (CVE-2007-4772). * Prevent certain PL/Java parameters from being set by non-superusers (CVE-2016-0766, bsc#966435). * Fix many issues in pg_dump with specific object types * Prevent over-eager pushdown of HAVING clauses for GROUPING SETS * Fix deparsing error with ON CONFLICT ... WHERE clauses * Fix tableoid errors for postgres_fdw * Prevent floating-point exceptions in pgbench

References

#949669 #949670 #966435 #966436

Cross- CVE-2007-4772 CVE-2015-5288 CVE-2015-5289

CVE-2016-0766 CVE-2016-0773

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Desktop 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2007-4772.html

https://www.suse.com/security/cve/CVE-2015-5288.html

https://www.suse.com/security/cve/CVE-2015-5289.html

https://www.suse.com/security/cve/CVE-2016-0766.html

https://www.suse.com/security/cve/CVE-2016-0773.html

https://bugzilla.suse.com/949669

https://bugzilla.suse.com/949670

https://bugzilla.suse.com/966435

https://bugzilla.suse.com/966436

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0677-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here