SUSE-FU-2022:2794-1
Dashboard / Vulnerabilities / SUSE-FU-2022:2794-1
SUSE-FU-2022:2794-1
Summary: Feature update for ongres-scram, ongres-stringprep, postgresql-jdbc
Details: This feature update for ongres-scram, ongres-stringprep, postgresql-jdbc provides: ongres-scram: - Upgrade from version 1.0.0-beta.2 to version 2.1. (jsc#SLE-23994) * Add standard `SASLPrep` (bsc#1196693, jsc#SLE-23994) * Failover to bouncy castle implementation of `PBKDF2WithHmacSHA256` to support Oracle JDK 7 * Updated `saslprep` to version 1.1 to remove a build dependency coming from the `stringprep` module ongres-stringprep: - Introduce `ongres-stringprep` 1.1 as dependency of `ongres-scram`. (bsc#1196693, jsc#SLE-23994) postgresql-jdbc: - CVE-2022-26520: Fixed arbitrary File Write Vulnerability (bsc#1197356) - Upgrade postgresql-jdbc from version 42.2.16 to version 42.2.25 (jsc#SLE-23994) * Use `SASLprep` normalization for SCRAM authentication and fixes issues with spaces in passwords. (bsc#1196693)
References: https://www.suse.com/support/update/announcement/-2022-2794/suse-fu-20222794-1/, https://bugzilla.suse.com/1196693, https://bugzilla.suse.com/1197356, https://www.suse.com/security/cve/CVE-2022-26520
Affected packages
Package
Name: ongres-scram
Purl: pkg:rpm/suse/ongres-scram&distro=SUSE%20Manager%20Server%20Module%204.2
Affected ranges
Type: ECOSYSTEM
Events:
