SUSE-SU-2015:1264-1
Dashboard / Vulnerabilities / SUSE-SU-2015:1264-1
SUSE-SU-2015:1264-1
Summary: Security update for postgresql93
Details: PostgreSQL was updated to the security and bugfix release 9.3.8 including 9.3.7. Security issues fixed: * CVE-2015-3165, bsc#931972: Avoid possible crash when client disconnects just before the authentication timeout expires. * CVE-2015-3166, bsc#931973: Consistently check for failure of the printf() family of functions. * CVE-2015-3167, bsc#931974: In contrib/pgcrypto, uniformly report decryption failures as 'Wrong key or corrupt data' Bugs fixed: * Protect against wraparound of multixact member IDs. * Avoid failures while fsync'ing data directory during crash restart. * Fix pg_get_functiondef() to show functions' LEAKPROOF property, if set. * Allow libpq to use TLS protocol versions beyond v1. - For the full release notes, see the following two URLs http://www.postgresql.org/docs/9.3/static/release-9-3-8.html http://www.postgresql.org/docs/9.3/static/release-9-3-7.html
References: https://www.suse.com/support/update/announcement/2015/suse-su-20151264-1/, https://bugzilla.suse.com/931972, https://bugzilla.suse.com/931973, https://bugzilla.suse.com/931974, https://www.suse.com/security/cve/CVE-2015-3165, https://www.suse.com/security/cve/CVE-2015-3166, https://www.suse.com/security/cve/CVE-2015-3167
Affected packages
Package
Name: postgresql93
Purl: pkg:rpm/suse/postgresql93&distro=SUSE%20Linux%20Enterprise%20Desktop%2012
Affected ranges
Type: ECOSYSTEM
Events:
