Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE Linux 15-SP2: 2020:3463-1 Important PostgreSQL12 Security Fix

suse
Calendar Grey November 20, 2020
Dist Suse Esm H88
Crucial patches for PostgreSQL 12 addressing various vulnerabilities in SUSE Enterprise Module 15-SP2 have been rolled out.
An update that fixes three vulnerabilities is now available

Summary

This update for postgresql12 fixes the following issues: - Upgrade to version 12.5: * CVE-2020-25695, bsc#1178666: Block DECLARE CURSOR ... WITH HOLD and firing of deferred triggers within index expressions and materialized view queries. * CVE-2020-25694, bsc#1178667: a) Fix usage of complex connection-string parameters in pg_dump, pg_restore, clusterdb, reindexdb, and vacuumdb. b) When psql's \connect command re-uses connection parameters, ensure that all non-overridden parameters from a previous connection string are re-used. * CVE-2020-25696, bsc#1178668: Prevent psql's \gset command from modifying specially-treated variables. * Fix recently-added timetz test case so it works when the USA is not observing daylight savings time.

References

#1178666 #1178667 #1178668

Cross- CVE-2020-25694 CVE-2020-25695 CVE-2020-25696

Affected Products:

SUSE Linux Enterprise Module for Server Applications 15-SP2

SUSE Linux Enterprise Module for Basesystem 15-SP2

https://www.suse.com/security/cve/CVE-2020-25694.html

https://www.suse.com/security/cve/CVE-2020-25695.html

https://www.suse.com/security/cve/CVE-2020-25696.html

https://bugzilla.suse.com/1178666

https://bugzilla.suse.com/1178667

https://bugzilla.suse.com/1178668

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:3463-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here