SUSE-SU-2018:0077-1
Dashboard / Vulnerabilities / SUSE-SU-2018:0077-1
SUSE-SU-2018:0077-1
Summary: Security update for postgresql94
Details: This update for postgresql94 fixes the following issues: Security issues fixed: - CVE-2017-15098: Fix crash due to rowtype mismatch in json{b}_populate_recordset() (bsc#1067844). - CVE-2017-12172: Start scripts permit database administrator to modify root-owned files. This issue did not affect SUSE (bsc#1062538). Bug fixes: - Update to version 9.4.15 * https://www.postgresql.org/docs/9.4/static/release-9-4-15.html * https://www.postgresql.org/docs/9.4/static/release-9-4-14.html
References: https://www.suse.com/support/update/announcement/2018/suse-su-20180077-1/, https://bugzilla.suse.com/1062538, https://bugzilla.suse.com/1067844, https://www.suse.com/security/cve/CVE-2017-12172, https://www.suse.com/security/cve/CVE-2017-15098
Affected packages
Package
Name: postgresql94-libs
Purl: pkg:rpm/suse/postgresql94-libs&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
