SUSE-SU-2021:3755-1
Dashboard / Vulnerabilities / SUSE-SU-2021:3755-1
SUSE-SU-2021:3755-1
Summary: Security update for postgresql, postgresql13, postgresql14
Details: This update for postgresql, postgresql13 and postgresql14 fixes the following issues: Security issues fixed: - CVE-2021-23214: Make the server reject extraneous data after an SSL or GSS encryption handshake (bsc#1192516). - CVE-2021-23222: Make libpq reject extraneous data after an SSL or GSS encryption handshake (bsc#1192516). This update also ships postgresql14 to SUSE Linux Enterprise 12 SP5. (jsc#SLE-22673) On older service packs only libpq5 and libecpg6 are being replaced by the postgresql14 variants. Feature changes in postgresql14: - https://www.postgresql.org/about/news/postgresql-14-released-2318/ - https://www.postgresql.org/docs/14/release-14.html
References: https://www.suse.com/support/update/announcement/2021/suse-su-20213755-1/, https://bugzilla.suse.com/1192516, https://www.suse.com/security/cve/CVE-2021-23214, https://www.suse.com/security/cve/CVE-2021-23222
Affected packages
Package
Name: postgresql
Purl: pkg:rpm/suse/postgresql&distro=HPE%20Helion%20OpenStack%208
Affected ranges
Type: ECOSYSTEM
Events:
