gpp_maybe Security update for postgresql94
SUSE-SLE-SERVER-12-2018-2779


This update for postgresql94 to 9.4.19 fixes the following security issue: - CVE-2018-10915: libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could have bypassed client-side connection security features, obtain access to higher privileged connections or potentially cause other impact SQL injection, by causing the PQescape() functions to malfunction (bsc#1104199). A dump/restore is not required for this update unless you use the functions query_to_xml, cursor_to_xml, cursor_to_xmlschema, query_to_xmlschema, and query_to_xml_and_xmlschema. In this case please see the first entry of https://www.postgresql.org/docs/9.4/static/release-9-4-18.html

  • Release Date
    Nov 26 2018
  • References
    Bugzilla: 1104199
    CVEs: CVE-2018-10915
  • Type
    security
  • Severity
    important

cloud_download Downloads

SUSE Linux Enterprise Server LTSS 12 s390x
  • Packages
    postgresql94
    Basic Clients and Utilities for PostgreSQL
    9.4.19-21.22.7 lock rpm lock src
    postgresql94-contrib
    Contributed Extensions and Additions to PostgreSQL
    9.4.19-21.22.7 lock rpm
    postgresql94-docs
    HTML Documentation for PostgreSQL
    9.4.19-21.22.7 lock rpm
    postgresql94-server
    The Programs Needed to Create and Run a PostgreSQL Server
    9.4.19-21.22.7 lock rpm
SUSE Linux Enterprise Server LTSS 12 x86_64
  • Packages
    postgresql94
    Basic Clients and Utilities for PostgreSQL
    9.4.19-21.22.7 lock rpm lock src
    postgresql94-contrib
    Contributed Extensions and Additions to PostgreSQL
    9.4.19-21.22.7 lock rpm
    postgresql94-docs
    HTML Documentation for PostgreSQL
    9.4.19-21.22.7 lock rpm
    postgresql94-server
    The Programs Needed to Create and Run a PostgreSQL Server
    9.4.19-21.22.7 lock rpm