openSUSE-SU-2021:1785-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:1785-1
openSUSE-SU-2021:1785-1
Summary: Security update for postgresql13
Details: This update for postgresql13 fixes the following issues: - Upgrade to version 13.3: - CVE-2021-32027: Fixed integer overflows in array subscripting calculations (bsc#1185924). - CVE-2021-32028: Fixed mishandling of junk columns in INSERT ... ON CONFLICT ... UPDATE target lists (bsc#1185925). - CVE-2021-32029: Fixed possibly-incorrect computation of UPDATE ... RETURNING outputs for joined cross-partition updates (bsc#1185926). - Don't use %_stop_on_removal, because it was meant to be private and got removed from openSUSE. %_restart_on_update is also private, but still supported and needed for now (bsc#1183168). - Re-enable build of the llvmjit subpackage on SLE, but it will only be delivered on PackageHub for now (bsc#1183118). - Disable icu for PostgreSQL 10 (and older) on TW (bsc#1179945).
References: https://lists.opensuse.org/archives/list/[email protected]/thread/YKAEBUWSUHMGHAQQGZGGJL4XNRQXGZEZ/, https://bugzilla.suse.com/1179945, https://bugzilla.suse.com/1183118, https://bugzilla.suse.com/1183168, https://bugzilla.suse.com/1185924, https://bugzilla.suse.com/1185925, https://bugzilla.suse.com/1185926, https://www.suse.com/security/cve/CVE-2021-32027, https://www.suse.com/security/cve/CVE-2021-32028, https://www.suse.com/security/cve/CVE-2021-32029
Affected packages
Package
Name: postgresql13
Purl: pkg:rpm/opensuse/postgresql13&distro=openSUSE%20Leap%2015.3
Affected ranges
Type: ECOSYSTEM
Events:
