Important: postgresql:15 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:10787", "synopsis": "Important: postgresql:15 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for module.pgaudit, module.postgres-decoderbufs, postgres-decoderbufs, pgaudit.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "PostgreSQL is an advanced object-relational database management system (DBMS).\n\nSecurity Fix(es):\n\n* postgresql: PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID (CVE-2024-10978)\n\n* postgresql: PostgreSQL PL/Perl environment variable changes execute arbitrary code (CVE-2024-10979)\n\n* postgresql: PostgreSQL row security below e.g. subqueries disregards user ID changes (CVE-2024-10976)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2326251", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2326251", "description": ""}, {"ticket": "2326253", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2326253", "description": ""}, {"ticket": "2326263", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2326263", "description": ""}], "cves": [{"name": "CVE-2024-10976", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-10976", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-10978", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-10978", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-10979", "sourceBy": "MITRE","sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-10979", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-12-19T04:19:20.875733Z", "rpms": {"Rocky Linux 9": {"nvras": ["pgaudit-0:1.7.0-1.module+el9.4.0+25512+c6b50a48.aarch64.rpm", "pgaudit-0:1.7.0-1.module+el9.4.0+25512+c6b50a48.ppc64le.rpm", "pgaudit-0:1.7.0-1.module+el9.4.0+25512+c6b50a48.s390x.rpm", "pgaudit-0:1.7.0-1.module+el9.4.0+25512+c6b50a48.src.rpm", "pgaudit-0:1.7.0-1.module+el9.4.0+25512+c6b50a48.x86_64.rpm", "pgaudit-debuginfo-0:1.7.0-1.module+el9.4.0+25512+c6b50a48.aarch64.rpm", "pgaudit-debuginfo-0:1.7.0-1.module+el9.4.0+25512+c6b50a48.ppc64le.rpm", "pgaudit-debuginfo-0:1.7.0-1.module+el9.4.0+25512+c6b50a48.s390x.rpm", "pgaudit-debuginfo-0:1.7.0-1.module+el9.4.0+25512+c6b50a48.x86_64.rpm", "pgaudit-debugsource-0:1.7.0-1.module+el9.4.0+25512+c6b50a48.aarch64.rpm", "pgaudit-debugsource-0:1.7.0-1.module+el9.4.0+25512+c6b50a48.ppc64le.rpm", "pgaudit-debugsource-0:1.7.0-1.module+el9.4.0+25512+c6b50a48.s390x.rpm", "pgaudit-debugsource-0:1.7.0-1.module+el9.4.0+25512+c6b50a48.x86_64.rpm", "postgres-decoderbufs-0:1.9.7-1.Final.module+el9.4.0+25512+c6b50a48.aarch64.rpm", "postgres-decoderbufs-0:1.9.7-1.Final.module+el9.4.0+25512+c6b50a48.ppc64le.rpm", "postgres-decoderbufs-0:1.9.7-1.Final.module+el9.4.0+25512+c6b50a48.s390x.rpm", "postgres-decoderbufs-0:1.9.7-1.Final.module+el9.4.0+25512+c6b50a48.src.rpm", "postgres-decoderbufs-0:1.9.7-1.Final.module+el9.4.0+25512+c6b50a48.x86_64.rpm", "postgres-decoderbufs-debuginfo-0:1.9.7-1.Final.module+el9.4.0+25512+c6b50a48.aarch64.rpm", "postgres-decoderbufs-debuginfo-0:1.9.7-1.Final.module+el9.4.0+25512+c6b50a48.ppc64le.rpm", "postgres-decoderbufs-debuginfo-0:1.9.7-1.Final.module+el9.4.0+25512+c6b50a48.s390x.rpm", "postgres-decoderbufs-debuginfo-0:1.9.7-1.Final.module+el9.4.0+25512+c6b50a48.x86_64.rpm", "postgres-decoderbufs-debugsource-0:1.9.7-1.Final.module+el9.4.0+25512+c6b50a48.aarch64.rpm","postgres-decoderbufs-debugsource-0:1.9.7-1.Final.module+el9.4.0+25512+c6b50a48.ppc64le.rpm", "postgres-decoderbufs-debugsource-0:1.9.7-1.Final.module+el9.4.0+25512+c6b50a48.s390x.rpm", "postgres-decoderbufs-debugsource-0:1.9.7-1.Final.module+el9.4.0+25512+c6b50a48.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important enhancements for PostgreSQL on Rocky Linux 9 focusing on security vulnerabilities. Safeguard your systems appropriately.. PostgreSQL Security, Rocky Linux 9, Security Update. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-6020 http://linux.oracle.com/errata/ELSA-2024-6020.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: pgaudit-1.7.0-1.module+el9.2.0+21134+ceb95ed9.x86_64.rpm pg_repack-1.4.8-1.module+el9.2.0+21134+ceb95ed9.x86_64.rpm postgres-decoderbufs-1.9.7-1.Final.module+el9.2.0+21134+ceb95ed9.x86_64.rpm postgresql-15.8-1.module+el9.4.0+90399+63b2ad7b.x86_64.rpm postgresql-contrib-15.8-1.module+el9.4.0+90399+63b2ad7b.x86_64.rpm postgresql-docs-15.8-1.module+el9.4.0+90399+63b2ad7b.x86_64.rpm postgresql-plperl-15.8-1.module+el9.4.0+90399+63b2ad7b.x86_64.rpm postgresql-plpython3-15.8-1.module+el9.4.0+90399+63b2ad7b.x86_64.rpm postgresql-pltcl-15.8-1.module+el9.4.0+90399+63b2ad7b.x86_64.rpm postgresql-private-devel-15.8-1.module+el9.4.0+90399+63b2ad7b.x86_64.rpm postgresql-private-libs-15.8-1.module+el9.4.0+90399+63b2ad7b.x86_64.rpm postgresql-server-15.8-1.module+el9.4.0+90399+63b2ad7b.x86_64.rpm postgresql-server-devel-15.8-1.module+el9.4.0+90399+63b2ad7b.x86_64.rpm postgresql-static-15.8-1.module+el9.4.0+90399+63b2ad7b.x86_64.rpm postgresql-test-15.8-1.module+el9.4.0+90399+63b2ad7b.x86_64.rpm postgresql-test-rpm-macros-15.8-1.module+el9.4.0+90399+63b2ad7b.noarch.rpm postgresql-upgrade-15.8-1.module+el9.4.0+90399+63b2ad7b.x86_64.rpm postgresql-upgrade-devel-15.8-1.module+el9.4.0+90399+63b2ad7b.x86_64.rpm aarch64: pgaudit-1.7.0-1.module+el9.2.0+21134+ceb95ed9.aarch64.rpm pg_repack-1.4.8-1.module+el9.2.0+21134+ceb95ed9.aarch64.rpm postgres-decoderbufs-1.9.7-1.Final.module+el9.2.0+21134+ceb95ed9.aarch64.rpm postgresql-15.8-1.module+el9.4.0+90399+63b2ad7b.aarch64.rpm postgresql-contrib-15.8-1.module+el9.4.0+90399+63b2ad7b.aarch64.rpm postgresql-docs-15.8-1.module+el9.4.0+90399+63b2ad7b.aarch64.rpm postgresql-plperl-15.8-1.module+el9.4.0+90399+63b2ad7b.aarch64.rpm postgresql-plpython3-15.8-1.module+el9.4.0+90399+63b2ad7b.aarch64.rpm postgresql-pltcl-15.8-1.module+el9.4.0+90399+63b2ad7b.aarch64.rpm postgresql-private-devel-15.8-1.module+el9.4.0+90399+63b2ad7b.aarch64.rpm postgresql-private-libs-15.8-1.module+el9.4.0+90399+63b2ad7b.aarch64.rpm postgresql-server-15.8-1.module+el9.4.0+90399+63b2ad7b.aarch64.rpm postgresql-server-devel-15.8-1.module+el9.4.0+90399+63b2ad7b.aarch64.rpm postgresql-static-15.8-1.module+el9.4.0+90399+63b2ad7b.aarch64.rpm postgresql-test-15.8-1.module+el9.4.0+90399+63b2ad7b.aarch64.rpm postgresql-test-rpm-macros-15.8-1.module+el9.4.0+90399+63b2ad7b.noarch.rpm postgresql-upgrade-15.8-1.module+el9.4.0+90399+63b2ad7b.aarch64.rpm postgresql-upgrade-devel-15.8-1.module+el9.4.0+90399+63b2ad7b.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//pgaudit-1.7.0-1.module+el9.2.0+21134+ceb95ed9.src.rpm http://oss.oracle.com/ol9/SRPMS-updates//pg_repack-1.4.8-1.module+el9.2.0+21134+ceb95ed9.src.rpm http://oss.oracle.com/ol9/SRPMS-updates//postgres-decoderbufs-1.9.7-1.Final.module+el9.2.0+21134+ceb95ed9.src.rpm http://oss.oracle.com/ol9/SRPMS-updates//postgresql-15.8-1.module+el9.4.0+90399+63b2ad7b.src.rpm Related CVEs: CVE-2024-4317 CVE-2024-7348 Description of changes: pgaudit [1.7.0-1] - Initial import for postgresql 15 module - Update to 1.7.0 - Support postgresql 15 - Related: #2128410 pg_repack postgres-decoderbufs [1.9.7-1.Final] - Iitial import for postgresql 15 stream - Related: #2128410 postgresql [15.8-1] - Update to 15.8 [15.6-3] - Remove /var/run/postgresql - Related: RHEL-51271 [15.6-2] - Enable lz4 and zstd support [15.6-1] - Update to 15.6 and 13.14 - Fix CVE-2024-0985 [15.5-1] - update to 15.5 - Fixes CVE-2023-5868, CVE-2023-5869, CVE-2023-5870, CVE-2023-39417, and CVE-2023-39418 [15.3-1] - update to 15.3 - Fixes CVE-2023-2454 and CVE-2023-2455 Resolves: #2214875 [15.2-1] - update to 15.2 - Resolves: #2128410 [15.0-2] - update postgresql-setup to 8.8 [15.0-1] - Initial import for postgresql 15 - Resolves: #2128410 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-6001 http://linux.oracle.com/errata/ELSA-2024-6001.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: pgaudit-1.7.0-1.module+el8.9.0+90110+d8a562d5.x86_64.rpm pg_repack-1.4.8-1.module+el8.9.0+90110+d8a562d5.x86_64.rpm postgres-decoderbufs-1.9.7-1.Final.module+el8.9.0+90110+d8a562d5.x86_64.rpm postgresql-15.8-1.module+el8.10.0+90396+38e9dad0.x86_64.rpm postgresql-contrib-15.8-1.module+el8.10.0+90396+38e9dad0.x86_64.rpm postgresql-docs-15.8-1.module+el8.10.0+90396+38e9dad0.x86_64.rpm postgresql-plperl-15.8-1.module+el8.10.0+90396+38e9dad0.x86_64.rpm postgresql-plpython3-15.8-1.module+el8.10.0+90396+38e9dad0.x86_64.rpm postgresql-pltcl-15.8-1.module+el8.10.0+90396+38e9dad0.x86_64.rpm postgresql-private-devel-15.8-1.module+el8.10.0+90396+38e9dad0.x86_64.rpm postgresql-private-libs-15.8-1.module+el8.10.0+90396+38e9dad0.x86_64.rpm postgresql-server-15.8-1.module+el8.10.0+90396+38e9dad0.x86_64.rpm postgresql-server-devel-15.8-1.module+el8.10.0+90396+38e9dad0.x86_64.rpm postgresql-static-15.8-1.module+el8.10.0+90396+38e9dad0.x86_64.rpm postgresql-test-15.8-1.module+el8.10.0+90396+38e9dad0.x86_64.rpm postgresql-test-rpm-macros-15.8-1.module+el8.10.0+90396+38e9dad0.noarch.rpm postgresql-upgrade-15.8-1.module+el8.10.0+90396+38e9dad0.x86_64.rpm postgresql-upgrade-devel-15.8-1.module+el8.10.0+90396+38e9dad0.x86_64.rpm aarch64: pgaudit-1.7.0-1.module+el8.9.0+90110+d8a562d5.aarch64.rpm pg_repack-1.4.8-1.module+el8.9.0+90110+d8a562d5.aarch64.rpm postgres-decoderbufs-1.9.7-1.Final.module+el8.9.0+90110+d8a562d5.aarch64.rpm postgresql-15.8-1.module+el8.10.0+90396+38e9dad0.aarch64.rpm postgresql-contrib-15.8-1.module+el8.10.0+90396+38e9dad0.aarch64.rpm postgresql-docs-15.8-1.module+el8.10.0+90396+38e9dad0.aarch64.rpm postgresql-plperl-15.8-1.module+el8.10.0+90396+38e9dad0.aarch64.rpm postgresql-plpython3-15.8-1.module+el8.10.0+90396+38e9dad0.aarch64.rpm postgresql-pltcl-15.8-1.module+el8.10.0+90396+38e9dad0.aarch64.rpm postgresql-private-devel-15.8-1.module+el8.10.0+90396+38e9dad0.aarch64.rpm postgresql-private-libs-15.8-1.module+el8.10.0+90396+38e9dad0.aarch64.rpm postgresql-server-15.8-1.module+el8.10.0+90396+38e9dad0.aarch64.rpm postgresql-server-devel-15.8-1.module+el8.10.0+90396+38e9dad0.aarch64.rpm postgresql-static-15.8-1.module+el8.10.0+90396+38e9dad0.aarch64.rpm postgresql-test-15.8-1.module+el8.10.0+90396+38e9dad0.aarch64.rpm postgresql-test-rpm-macros-15.8-1.module+el8.10.0+90396+38e9dad0.noarch.rpm postgresql-upgrade-15.8-1.module+el8.10.0+90396+38e9dad0.aarch64.rpm postgresql-upgrade-devel-15.8-1.module+el8.10.0+90396+38e9dad0.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//pgaudit-1.7.0-1.module+el8.9.0+90110+d8a562d5.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//pg_repack-1.4.8-1.module+el8.9.0+90110+d8a562d5.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//postgres-decoderbufs-1.9.7-1.Final.module+el8.9.0+90110+d8a562d5.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//postgresql-15.8-1.module+el8.10.0+90396+38e9dad0.src.rpm Related CVEs: CVE-2024-4317 CVE-2024-7348 Description of changes: pgaudit pg_repack postgres-decoderbufs postgresql [15.8-1] - Update to 15.8 - Fix CVE-2024-7348 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-0973 https://linux.oracle.com/errata/ELSA-2024-0973.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: pgaudit-1.7.0-1.module+el8.9.0+90110+d8a562d5.x86_64.rpm pg_repack-1.4.8-1.module+el8.9.0+90110+d8a562d5.x86_64.rpm postgres-decoderbufs-1.9.7-1.Final.module+el8.9.0+90110+d8a562d5.x86_64.rpm postgresql-15.6-1.module+el8.9.0+90160+417c9f54.x86_64.rpm postgresql-contrib-15.6-1.module+el8.9.0+90160+417c9f54.x86_64.rpm postgresql-docs-15.6-1.module+el8.9.0+90160+417c9f54.x86_64.rpm postgresql-plperl-15.6-1.module+el8.9.0+90160+417c9f54.x86_64.rpm postgresql-plpython3-15.6-1.module+el8.9.0+90160+417c9f54.x86_64.rpm postgresql-pltcl-15.6-1.module+el8.9.0+90160+417c9f54.x86_64.rpm postgresql-private-devel-15.6-1.module+el8.9.0+90160+417c9f54.x86_64.rpm postgresql-private-libs-15.6-1.module+el8.9.0+90160+417c9f54.x86_64.rpm postgresql-server-15.6-1.module+el8.9.0+90160+417c9f54.x86_64.rpm postgresql-server-devel-15.6-1.module+el8.9.0+90160+417c9f54.x86_64.rpm postgresql-static-15.6-1.module+el8.9.0+90160+417c9f54.x86_64.rpm postgresql-test-15.6-1.module+el8.9.0+90160+417c9f54.x86_64.rpm postgresql-test-rpm-macros-15.6-1.module+el8.9.0+90160+417c9f54.noarch.rpm postgresql-upgrade-15.6-1.module+el8.9.0+90160+417c9f54.x86_64.rpm postgresql-upgrade-devel-15.6-1.module+el8.9.0+90160+417c9f54.x86_64.rpm aarch64: pgaudit-1.7.0-1.module+el8.9.0+90110+d8a562d5.aarch64.rpm pg_repack-1.4.8-1.module+el8.9.0+90110+d8a562d5.aarch64.rpm postgres-decoderbufs-1.9.7-1.Final.module+el8.9.0+90110+d8a562d5.aarch64.rpm postgresql-15.6-1.module+el8.9.0+90160+417c9f54.aarch64.rpm postgresql-contrib-15.6-1.module+el8.9.0+90160+417c9f54.aarch64.rpm postgresql-docs-15.6-1.module+el8.9.0+90160+417c9f54.aarch64.rpm postgresql-plperl-15.6-1.module+el8.9.0+90160+417c9f54.aarch64.rpm postgresql-plpython3-15.6-1.module+el8.9.0+90160+417c9f54.aarch64.rpm postgresql-pltcl-15.6-1.module+el8.9.0+90160+417c9f54.aarch64.rpm postgresql-private-devel-15.6-1.module+el8.9.0+90160+417c9f54.aarch64.rpm postgresql-private-libs-15.6-1.module+el8.9.0+90160+417c9f54.aarch64.rpm postgresql-server-15.6-1.module+el8.9.0+90160+417c9f54.aarch64.rpm postgresql-server-devel-15.6-1.module+el8.9.0+90160+417c9f54.aarch64.rpm postgresql-static-15.6-1.module+el8.9.0+90160+417c9f54.aarch64.rpm postgresql-test-15.6-1.module+el8.9.0+90160+417c9f54.aarch64.rpm postgresql-test-rpm-macros-15.6-1.module+el8.9.0+90160+417c9f54.noarch.rpm postgresql-upgrade-15.6-1.module+el8.9.0+90160+417c9f54.aarch64.rpm postgresql-upgrade-devel-15.6-1.module+el8.9.0+90160+417c9f54.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//pgaudit-1.7.0-1.module+el8.9.0+90110+d8a562d5.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//pg_repack-1.4.8-1.module+el8.9.0+90110+d8a562d5.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//postgres-decoderbufs-1.9.7-1.Final.module+el8.9.0+90110+d8a562d5.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//postgresql-15.6-1.module+el8.9.0+90160+417c9f54.src.rpm Related CVEs: CVE-2024-0985 Description of changes: pgaudit [1.7.0-1] - Update to 1.7.0 - Support postgresql 15 - Related: #2128241 [1.5.0-1] - Update to version 1.5.0 Related: #1855776 pg_repack [1.4.8-1] - Update to version 1.4.8 - Postgresql 15 is supported - Related: #2128241 [1.4.6-4] - Rebuilt for IMA sigs, glibc 2.34, aarch64 flags Related: rhbz#1991688 postgres-decoderbufs [1.9.7-1.Final] - Iitial import for postgresql 15 stream - Related: #2128241 [1.4.0-4.Final] - Rebuilt for IMA sigs, glibc 2.34, aarch64 flags Related: rhbz#1991688 [1.4.0-3.Final] - Build jit based on what postgresql server does Related: #1933048 [1.4.0-2.Final] - Rebuilt for RHEL 9 BETA on Apr 15th 2021. Related: rhbz#1947937 [1.4.0-1.Final] - Update to new release 1.4.0 [1.1.0-0.6.Final] - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild [1.1.0-0.5.Final] - Rebuilt for protobuf 3.14 [1.1.0-0.4.Final] - Rebuilt for protobuf 3.13 [1.1.0-0.3.Final] - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild [1.1.0-0.2.Final] - Rebuilt for protobuf 3.12 [1.1.0-0.1.Final] - Update to 1.1.0.Final [1.0.0-0.1.Beta3] - Update to 1.0.0-Beta3 - Drop BR:postgis-devel postgresql [15.6-1] - update to 15.6 - Fixes CVE-2024-0985 _______________________________________________ El-errata mailing list
This update for postgresql15 fixes the following issues: Update to 13.12 CVE-2023-39417: Fixed potential SQL injection for trusted extensions.. # Security update for postgresql15 Announcement ID: SUSE-SU-2023:3344-1 Rating: moderate References: * #1214059 Cross-References: * CVE-2023-39417 CVSS scores: * CVE-2023-39417 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2023-39417 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * Legacy Module 15-SP4 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for postgresql15 fixes the following issues: * Update to 13.12 * CVE-2023-39417: Fixed potential SQL injection for trusted extensions. (bsc#1214059) ## Patch Instructions: To install this SUSE Moderate update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-3344=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-3344=1 * Legacy Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP4-2023-3344=1 * SUSE Manager Proxy 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-3344=1 * SUSE Manager Retail Branch Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.2-2023-3344=1 * SUSE Manager Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-3344=1 ## Package List: * openSUSE Leap15.4 (aarch64 ppc64le s390x x86_64) * postgresql13-debugsource-13.12-150200.5.43.1 * postgresql13-llvmjit-devel-13.12-150200.5.43.1 * postgresql13-plperl-13.12-150200.5.43.1 * postgresql13-pltcl-13.12-150200.5.43.1 * postgresql13-debuginfo-13.12-150200.5.43.1 * postgresql13-llvmjit-debuginfo-13.12-150200.5.43.1 * postgresql13-server-devel-debuginfo-13.12-150200.5.43.1 * postgresql13-server-devel-13.12-150200.5.43.1 * postgresql13-13.12-150200.5.43.1 * postgresql13-llvmjit-13.12-150200.5.43.1 * postgresql13-contrib-debuginfo-13.12-150200.5.43.1 * postgresql13-test-13.12-150200.5.43.1 * postgresql13-devel-13.12-150200.5.43.1 * postgresql13-plpython-debuginfo-13.12-150200.5.43.1 * postgresql13-plpython-13.12-150200.5.43.1 * postgresql13-pltcl-debuginfo-13.12-150200.5.43.1 * postgresql13-server-13.12-150200.5.43.1 * postgresql13-plperl-debuginfo-13.12-150200.5.43.1 * postgresql13-server-debuginfo-13.12-150200.5.43.1 * postgresql13-contrib-13.12-150200.5.43.1 * postgresql13-devel-debuginfo-13.12-150200.5.43.1 * openSUSE Leap 15.4 (noarch) * postgresql13-docs-13.12-150200.5.43.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * postgresql13-debugsource-13.12-150200.5.43.1 * postgresql13-llvmjit-devel-13.12-150200.5.43.1 * postgresql13-plperl-13.12-150200.5.43.1 * postgresql13-pltcl-13.12-150200.5.43.1 * postgresql13-debuginfo-13.12-150200.5.43.1 * postgresql13-llvmjit-debuginfo-13.12-150200.5.43.1 * postgresql13-server-devel-debuginfo-13.12-150200.5.43.1 * postgresql13-server-devel-13.12-150200.5.43.1 * postgresql13-13.12-150200.5.43.1 * postgresql13-llvmjit-13.12-150200.5.43.1 * postgresql13-contrib-debuginfo-13.12-150200.5.43.1 * postgresql13-test-13.12-150200.5.43.1 * postgresql13-devel-13.12-150200.5.43.1 * postgresql13-plpython-debuginfo-13.12-150200.5.43.1 * postgresql13-plpython-13.12-150200.5.43.1 * postgresql13-pltcl-debuginfo-13.12-150200.5.43.1 *postgresql13-server-13.12-150200.5.43.1 * postgresql13-plperl-debuginfo-13.12-150200.5.43.1 * postgresql13-server-debuginfo-13.12-150200.5.43.1 * postgresql13-contrib-13.12-150200.5.43.1 * postgresql13-devel-debuginfo-13.12-150200.5.43.1 * openSUSE Leap 15.5 (noarch) * postgresql13-docs-13.12-150200.5.43.1 * Legacy Module 15-SP4 (aarch64 ppc64le s390x x86_64) * postgresql13-plpython-13.12-150200.5.43.1 * postgresql13-llvmjit-13.12-150200.5.43.1 * postgresql13-pltcl-13.12-150200.5.43.1 * postgresql13-contrib-debuginfo-13.12-150200.5.43.1 * postgresql13-pltcl-debuginfo-13.12-150200.5.43.1 * postgresql13-debuginfo-13.12-150200.5.43.1 * postgresql13-debugsource-13.12-150200.5.43.1 * postgresql13-llvmjit-devel-13.12-150200.5.43.1 * postgresql13-plperl-debuginfo-13.12-150200.5.43.1 * postgresql13-server-13.12-150200.5.43.1 * postgresql13-server-debuginfo-13.12-150200.5.43.1 * postgresql13-devel-13.12-150200.5.43.1 * postgresql13-llvmjit-debuginfo-13.12-150200.5.43.1 * postgresql13-plperl-13.12-150200.5.43.1 * postgresql13-contrib-13.12-150200.5.43.1 * postgresql13-server-devel-debuginfo-13.12-150200.5.43.1 * postgresql13-server-devel-13.12-150200.5.43.1 * postgresql13-13.12-150200.5.43.1 * postgresql13-devel-debuginfo-13.12-150200.5.43.1 * postgresql13-plpython-debuginfo-13.12-150200.5.43.1 * Legacy Module 15-SP4 (noarch) * postgresql13-docs-13.12-150200.5.43.1 * SUSE Manager Proxy 4.2 (x86_64) * postgresql13-plpython-13.12-150200.5.43.1 * postgresql13-pltcl-13.12-150200.5.43.1 * postgresql13-contrib-debuginfo-13.12-150200.5.43.1 * postgresql13-pltcl-debuginfo-13.12-150200.5.43.1 * postgresql13-debuginfo-13.12-150200.5.43.1 * postgresql13-debugsource-13.12-150200.5.43.1 * postgresql13-plperl-debuginfo-13.12-150200.5.43.1 * postgresql13-server-13.12-150200.5.43.1 * postgresql13-server-debuginfo-13.12-150200.5.43.1 * postgresql13-devel-13.12-150200.5.43.1 *postgresql13-plperl-13.12-150200.5.43.1 * postgresql13-contrib-13.12-150200.5.43.1 * postgresql13-server-devel-debuginfo-13.12-150200.5.43.1 * postgresql13-server-devel-13.12-150200.5.43.1 * postgresql13-13.12-150200.5.43.1 * postgresql13-devel-debuginfo-13.12-150200.5.43.1 * postgresql13-plpython-debuginfo-13.12-150200.5.43.1 * SUSE Manager Proxy 4.2 (noarch) * postgresql13-docs-13.12-150200.5.43.1 * SUSE Manager Retail Branch Server 4.2 (x86_64) * postgresql13-plpython-13.12-150200.5.43.1 * postgresql13-pltcl-13.12-150200.5.43.1 * postgresql13-contrib-debuginfo-13.12-150200.5.43.1 * postgresql13-pltcl-debuginfo-13.12-150200.5.43.1 * postgresql13-debuginfo-13.12-150200.5.43.1 * postgresql13-debugsource-13.12-150200.5.43.1 * postgresql13-plperl-debuginfo-13.12-150200.5.43.1 * postgresql13-server-13.12-150200.5.43.1 * postgresql13-server-debuginfo-13.12-150200.5.43.1 * postgresql13-devel-13.12-150200.5.43.1 * postgresql13-plperl-13.12-150200.5.43.1 * postgresql13-contrib-13.12-150200.5.43.1 * postgresql13-server-devel-debuginfo-13.12-150200.5.43.1 * postgresql13-server-devel-13.12-150200.5.43.1 * postgresql13-13.12-150200.5.43.1 * postgresql13-devel-debuginfo-13.12-150200.5.43.1 * postgresql13-plpython-debuginfo-13.12-150200.5.43.1 * SUSE Manager Retail Branch Server 4.2 (noarch) * postgresql13-docs-13.12-150200.5.43.1 * SUSE Manager Server 4.2 (ppc64le s390x x86_64) * postgresql13-plpython-13.12-150200.5.43.1 * postgresql13-pltcl-13.12-150200.5.43.1 * postgresql13-contrib-debuginfo-13.12-150200.5.43.1 * postgresql13-pltcl-debuginfo-13.12-150200.5.43.1 * postgresql13-debuginfo-13.12-150200.5.43.1 * postgresql13-debugsource-13.12-150200.5.43.1 * postgresql13-plperl-debuginfo-13.12-150200.5.43.1 * postgresql13-server-13.12-150200.5.43.1 * postgresql13-server-debuginfo-13.12-150200.5.43.1 * postgresql13-devel-13.12-150200.5.43.1 *postgresql13-plperl-13.12-150200.5.43.1 * postgresql13-contrib-13.12-150200.5.43.1 * postgresql13-server-devel-debuginfo-13.12-150200.5.43.1 * postgresql13-server-devel-13.12-150200.5.43.1 * postgresql13-13.12-150200.5.43.1 * postgresql13-devel-debuginfo-13.12-150200.5.43.1 * postgresql13-plpython-debuginfo-13.12-150200.5.43.1 * SUSE Manager Server 4.2 (noarch) * postgresql13-docs-13.12-150200.5.43.1 ## References: * https://www.suse.com/security/cve/CVE-2023-39417.html * https://bugzilla.suse.com/show_bug.cgi?id=1214059 . The latest patch for PostgreSQL 15 resolves the SQL injection vulnerability linked to CVE-2023-39417, enhancing the security measures for openSUSE users.. Postgresql15 Update, SQL Injection Fix, openSUSE Security Advisory. . LinuxSecurity.com Team
An update for rh-postgresql12-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-postgresql12-postgresql security update Advisory ID: RHSA-2023:4313-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2023:4313 Issue date: 2023-07-27 CVE Names: CVE-2023-2454 CVE-2023-2455 ===================================================================== 1. Summary: An update for rh-postgresql12-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for RHEL Workstation(v. 7) - ppc64le, s390x, x86_64 Red Hat Software Collections for RHEL(v. 7) - x86_64 3. Description: PostgreSQL is an advanced object-relational database management system (DBMS). Security Fix(es): * postgresql: schema_element defeats protective search_path changes (CVE-2023-2454) * postgresql: row security policies disregard user ID changes after inlining. (CVE-2023-2455) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 If the postgresql service is running, it will be automaticallyrestarted after installing this update. 5. Bugs fixed (https://bugzilla.redhat.com/): 2207568 - CVE-2023-2454 postgresql: schema_element defeats protective search_path changes 2207569 - CVE-2023-2455 postgresql: row security policies disregard user ID changes after inlining. 6. Package List: Red Hat Software Collections for RHEL Workstation(v.7): Source: rh-postgresql12-postgresql-12.15-1.el7.src.rpm ppc64le: rh-postgresql12-postgresql-12.15-1.el7.ppc64le.rpm rh-postgresql12-postgresql-contrib-12.15-1.el7.ppc64le.rpm rh-postgresql12-postgresql-contrib-syspaths-12.15-1.el7.ppc64le.rpm rh-postgresql12-postgresql-debuginfo-12.15-1.el7.ppc64le.rpm rh-postgresql12-postgresql-devel-12.15-1.el7.ppc64le.rpm rh-postgresql12-postgresql-docs-12.15-1.el7.ppc64le.rpm rh-postgresql12-postgresql-libs-12.15-1.el7.ppc64le.rpm rh-postgresql12-postgresql-plperl-12.15-1.el7.ppc64le.rpm rh-postgresql12-postgresql-plpython-12.15-1.el7.ppc64le.rpm rh-postgresql12-postgresql-pltcl-12.15-1.el7.ppc64le.rpm rh-postgresql12-postgresql-server-12.15-1.el7.ppc64le.rpm rh-postgresql12-postgresql-server-syspaths-12.15-1.el7.ppc64le.rpm rh-postgresql12-postgresql-static-12.15-1.el7.ppc64le.rpm rh-postgresql12-postgresql-syspaths-12.15-1.el7.ppc64le.rpm rh-postgresql12-postgresql-test-12.15-1.el7.ppc64le.rpm s390x: rh-postgresql12-postgresql-12.15-1.el7.s390x.rpm rh-postgresql12-postgresql-contrib-12.15-1.el7.s390x.rpm rh-postgresql12-postgresql-contrib-syspaths-12.15-1.el7.s390x.rpm rh-postgresql12-postgresql-debuginfo-12.15-1.el7.s390x.rpm rh-postgresql12-postgresql-devel-12.15-1.el7.s390x.rpm rh-postgresql12-postgresql-docs-12.15-1.el7.s390x.rpm rh-postgresql12-postgresql-libs-12.15-1.el7.s390x.rpm rh-postgresql12-postgresql-plperl-12.15-1.el7.s390x.rpm rh-postgresql12-postgresql-plpython-12.15-1.el7.s390x.rpm rh-postgresql12-postgresql-pltcl-12.15-1.el7.s390x.rpm rh-postgresql12-postgresql-server-12.15-1.el7.s390x.rpm rh-postgresql12-postgresql-server-syspaths-12.15-1.el7.s390x.rpm rh-postgresql12-postgresql-static-12.15-1.el7.s390x.rpm rh-postgresql12-postgresql-syspaths-12.15-1.el7.s390x.rpm rh-postgresql12-postgresql-test-12.15-1.el7.s390x.rpm x86_64: rh-postgresql12-postgresql-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-contrib-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-contrib-syspaths-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-debuginfo-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-devel-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-docs-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-libs-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-plperl-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-plpython-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-pltcl-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-server-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-server-syspaths-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-static-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-syspaths-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-test-12.15-1.el7.x86_64.rpm Red Hat Software Collections for RHEL(v. 7): Source: rh-postgresql12-postgresql-12.15-1.el7.src.rpm x86_64: rh-postgresql12-postgresql-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-contrib-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-contrib-syspaths-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-debuginfo-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-devel-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-docs-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-libs-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-plperl-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-plpython-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-pltcl-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-server-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-server-syspaths-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-static-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-syspaths-12.15-1.el7.x86_64.rpm rh-postgresql12-postgresql-test-12.15-1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-2454 https://access.redhat.com/security/cve/CVE-2023-2455 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . Morecontact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJkwn0rAAoJENzjgjWX9erEgzoP/A7d/F+IVuddE1o169mZWEfO kOvEc4bI3fbOJRFjB3SerD6MBMigC9hD3uuuDUG6quvBf9y42WL2CoLhRbhNymTe wnQCfRhWOZEwEerdDsUg9TpC3q6cOpL4oJBN0fOe/mA7yzKK6ehWnMW3NW6QmpQE hSbhJOnU0OF6U8TzlnigP2YGxwuA37AffFSz/za92OYRZ6znOGXD1Hb03YCB8maI SHBpf3XQm5BynOStY4DneYz+H4rt/pMQxuQrj8fJs3shxPexMbdJMxTSkZg4iVcw xeTZ3hUbh/IQitjdI5qlmueN4Fg+zxkrcB8iDnyDEpei+4qP392TtEgpOJAv/OJ2 qb09FrDx49a0D+lBZ6tbQJe/nO3P3dT/cbLDtoehLK8h3HTp3QbTGxA/vvkvaYcA R4CibfDd3f70VhRAJhQQHeox/SxQy1qDRkmNFbFtLSj3/pa2RyBD6Dy7MynfUhku +YYZRqPQeMBmx7prXAHJqeXFYSwdEuTJZMrdAgqZ7qjgKD+vTq3YhD2plL5loEfh YelYqcz6nmdB+/fBW4mfAIf/+NMrv0LG4ak7CCAGaQt5e6YIHVr+X/c++zGHvOBo BZ7DFeOP+nfbDP3rKVAzCVYkLTKBh9WMoepK7zD+H34dxdLOwTWYfzZmB5uDq6js AZp3FTK9OHiJZokHj+ol =NiAD -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for rh-postgresql10-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-postgresql10-postgresql security and bug fix update Advisory ID: RHSA-2023:0160-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2023:0160 Issue date: 2023-01-12 CVE Names: CVE-2022-2625 ==================================================================== 1. Summary: An update for rh-postgresql10-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - x86_64 3. Description: PostgreSQL is an advanced object-relational database management system (DBMS). The following packages have been upgraded to a later upstream version: rh-postgresql10-postgresql (10.23). Security Fix(es): * postgresql: Extension scripts replace objects not belonging to the extension. (CVE-2022-2625) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * rh-postgresql10-postgresql: Update to the latest PostgreSQL version 10.23 (BZ#2157611) 4. Solution: For details on how to apply this update,which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 If the postgresql service is running, it will be automatically restarted after installing this update. 5. Bugs fixed (https://bugzilla.redhat.com/): 2113825 - CVE-2022-2625 postgresql: Extension scripts replace objects not belonging to the extension. 2157611 - rh-postgresql10-postgresql: Update to the latest PostgreSQL version 10.23 [rhscl-3.8.z] 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v.7): Source: rh-postgresql10-postgresql-10.23-1.el7.src.rpm ppc64le: rh-postgresql10-postgresql-10.23-1.el7.ppc64le.rpm rh-postgresql10-postgresql-contrib-10.23-1.el7.ppc64le.rpm rh-postgresql10-postgresql-contrib-syspaths-10.23-1.el7.ppc64le.rpm rh-postgresql10-postgresql-debuginfo-10.23-1.el7.ppc64le.rpm rh-postgresql10-postgresql-devel-10.23-1.el7.ppc64le.rpm rh-postgresql10-postgresql-docs-10.23-1.el7.ppc64le.rpm rh-postgresql10-postgresql-libs-10.23-1.el7.ppc64le.rpm rh-postgresql10-postgresql-plperl-10.23-1.el7.ppc64le.rpm rh-postgresql10-postgresql-plpython-10.23-1.el7.ppc64le.rpm rh-postgresql10-postgresql-pltcl-10.23-1.el7.ppc64le.rpm rh-postgresql10-postgresql-server-10.23-1.el7.ppc64le.rpm rh-postgresql10-postgresql-server-syspaths-10.23-1.el7.ppc64le.rpm rh-postgresql10-postgresql-static-10.23-1.el7.ppc64le.rpm rh-postgresql10-postgresql-syspaths-10.23-1.el7.ppc64le.rpm rh-postgresql10-postgresql-test-10.23-1.el7.ppc64le.rpm s390x: rh-postgresql10-postgresql-10.23-1.el7.s390x.rpm rh-postgresql10-postgresql-contrib-10.23-1.el7.s390x.rpm rh-postgresql10-postgresql-contrib-syspaths-10.23-1.el7.s390x.rpm rh-postgresql10-postgresql-debuginfo-10.23-1.el7.s390x.rpm rh-postgresql10-postgresql-devel-10.23-1.el7.s390x.rpm rh-postgresql10-postgresql-docs-10.23-1.el7.s390x.rpm rh-postgresql10-postgresql-libs-10.23-1.el7.s390x.rpm rh-postgresql10-postgresql-plperl-10.23-1.el7.s390x.rpm rh-postgresql10-postgresql-plpython-10.23-1.el7.s390x.rpm rh-postgresql10-postgresql-pltcl-10.23-1.el7.s390x.rpm rh-postgresql10-postgresql-server-10.23-1.el7.s390x.rpm rh-postgresql10-postgresql-server-syspaths-10.23-1.el7.s390x.rpm rh-postgresql10-postgresql-static-10.23-1.el7.s390x.rpm rh-postgresql10-postgresql-syspaths-10.23-1.el7.s390x.rpm rh-postgresql10-postgresql-test-10.23-1.el7.s390x.rpm x86_64: rh-postgresql10-postgresql-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-contrib-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-contrib-syspaths-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-debuginfo-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-devel-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-docs-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-libs-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-plperl-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-plpython-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-pltcl-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-server-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-server-syspaths-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-static-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-syspaths-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-test-10.23-1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7): Source: rh-postgresql10-postgresql-10.23-1.el7.src.rpm x86_64: rh-postgresql10-postgresql-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-contrib-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-contrib-syspaths-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-debuginfo-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-devel-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-docs-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-libs-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-plperl-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-plpython-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-pltcl-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-server-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-server-syspaths-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-static-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-syspaths-10.23-1.el7.x86_64.rpm rh-postgresql10-postgresql-test-10.23-1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-2625 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details athttps://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY8A2kNzjgjWX9erEAQjivg/+KpxDuFgmrVStMcbCKvPW3o+DOdp+COkk lD/fgU0+Q4YYeeOMm6DC9bd6hxV3SAozySBxEuvPR4Y6Mgz5XGIP+Z+10YVceK1s UcGtaZKN6PsMVqqWWDpCz8JFio9hdOPI8Gw2SbnOtb1knBbGHW8zdt+3xp+vRdg8 168L57Ng3HIXo5bPObZFYa5M//Qxs5NpqVI5M4vJbwGhMAMRxTy4ttvuQX98dp7+ GosAZSKnZRSs3Kfgv91dDBxEdAXqIwutuTmgewpgOJl2uOuRSgdf6O4Iys3gcB9P wUL3WyNnW3g056yf4qtrUHCYW8e9nryj8dv10spmSpbD/56t3gxeapTtMmUTxZoZ S0itLTdhAeUsF3kwXtOehm5N3Kn57tQpbrgWjpfuri26P5ZUylO8XpnEZVXUV6/3 Hh5EZFTNWGgdFV2EGkUDJVkpBMlqxHrAgLKBFTJvpjJ6rGvAInJUbLa51oKQPyS2 DVW+RN29ASmUMz0tEf+zxpJ21NqkogD8G+RXxzadj9dxR7h3FoO2uEGxIQ/wpBNN pvS6jHigVdTymnR2V7x4JEAxAgRkpLRKUHiCcBZw+epLiS+jUGWVRESWVq6JDpwi yYuhaSo02TMjDUkF9HEOsAAwJRU2LWzoLAy1QrusolBZP+lDP/LhT6lDwhzoUPwl BsDBF74jGFk=5LSM -----END PGP SIGNATURE----- -- RHSA-announce mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-7128 https://linux.oracle.com/errata/ELSA-2022-7128.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: pgaudit-1.4.0-5.module+el8.5.0+20333+86306fc7.x86_64.rpm pg_repack-1.4.6-3.module+el8.5.0+20333+86306fc7.x86_64.rpm postgres-decoderbufs-0.10.0-2.module+el8.5.0+20333+86306fc7.x86_64.rpm postgresql-12.12-1.module+el8.6.0+20851+edfb83f8.x86_64.rpm postgresql-contrib-12.12-1.module+el8.6.0+20851+edfb83f8.x86_64.rpm postgresql-docs-12.12-1.module+el8.6.0+20851+edfb83f8.x86_64.rpm postgresql-plperl-12.12-1.module+el8.6.0+20851+edfb83f8.x86_64.rpm postgresql-plpython3-12.12-1.module+el8.6.0+20851+edfb83f8.x86_64.rpm postgresql-pltcl-12.12-1.module+el8.6.0+20851+edfb83f8.x86_64.rpm postgresql-server-12.12-1.module+el8.6.0+20851+edfb83f8.x86_64.rpm postgresql-server-devel-12.12-1.module+el8.6.0+20851+edfb83f8.x86_64.rpm postgresql-static-12.12-1.module+el8.6.0+20851+edfb83f8.x86_64.rpm postgresql-test-12.12-1.module+el8.6.0+20851+edfb83f8.x86_64.rpm postgresql-test-rpm-macros-12.12-1.module+el8.6.0+20851+edfb83f8.noarch.rpm postgresql-upgrade-12.12-1.module+el8.6.0+20851+edfb83f8.x86_64.rpm postgresql-upgrade-devel-12.12-1.module+el8.6.0+20851+edfb83f8.x86_64.rpm aarch64: pgaudit-1.4.0-5.module+el8.5.0+20333+86306fc7.aarch64.rpm pg_repack-1.4.6-3.module+el8.5.0+20333+86306fc7.aarch64.rpm postgres-decoderbufs-0.10.0-2.module+el8.5.0+20333+86306fc7.aarch64.rpm postgresql-12.12-1.module+el8.6.0+20851+edfb83f8.aarch64.rpm postgresql-contrib-12.12-1.module+el8.6.0+20851+edfb83f8.aarch64.rpm postgresql-docs-12.12-1.module+el8.6.0+20851+edfb83f8.aarch64.rpm postgresql-plperl-12.12-1.module+el8.6.0+20851+edfb83f8.aarch64.rpm postgresql-plpython3-12.12-1.module+el8.6.0+20851+edfb83f8.aarch64.rpm postgresql-pltcl-12.12-1.module+el8.6.0+20851+edfb83f8.aarch64.rpm postgresql-server-12.12-1.module+el8.6.0+20851+edfb83f8.aarch64.rpm postgresql-server-devel-12.12-1.module+el8.6.0+20851+edfb83f8.aarch64.rpm postgresql-static-12.12-1.module+el8.6.0+20851+edfb83f8.aarch64.rpm postgresql-test-12.12-1.module+el8.6.0+20851+edfb83f8.aarch64.rpm postgresql-test-rpm-macros-12.12-1.module+el8.6.0+20851+edfb83f8.noarch.rpm postgresql-upgrade-12.12-1.module+el8.6.0+20851+edfb83f8.aarch64.rpm postgresql-upgrade-devel-12.12-1.module+el8.6.0+20851+edfb83f8.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/pgaudit-1.4.0-5.module+el8.5.0+20333+86306fc7.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates/pg_repack-1.4.6-3.module+el8.5.0+20333+86306fc7.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates/postgres-decoderbufs-0.10.0-2.module+el8.5.0+20333+86306fc7.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates/postgresql-12.12-1.module+el8.6.0+20851+edfb83f8.src.rpm Related CVEs: CVE-2022-2625 Description of changes: postgresql [12.12-1] - Resolves: #2131177 - Update to version 12.12 _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.