SUSE-SU-2016:0539-1

Source
https://www.suse.com/support/update/announcement/2016/suse-su-20160539-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2016:0539-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2016:0539-1
Related
Published
2016-02-22T10:07:15Z
Modified
2016-02-22T10:07:15Z
Summary
Security update for postgresql93
Details

This update for postgresql93 fixes the following issues:

  • Security and bugfix release 9.3.11:
    • Fix infinite loops and buffer-overrun problems in regular expressions (CVE-2016-0773, bsc#966436).
    • Fix regular-expression compiler to handle loops of constraint arcs (CVE-2007-4772).
    • Prevent certain PL/Java parameters from being set by non-superusers (CVE-2016-0766, bsc#966435).
    • Fix many issues in pgdump with specific object types
    • Prevent over-eager pushdown of HAVING clauses for GROUPING SETS
    • Fix deparsing error with ON CONFLICT ... WHERE clauses
    • Fix tableoid errors for postgresfdw
    • Prevent floating-point exceptions in pgbench
    • Make \det search Foreign Table names consistently
    • Fix quoting of domain constraint names in pgdump
    • Prevent putting expanded objects into Const nodes
    • Allow compile of PL/Java on Windows
    • Fix 'unresolved symbol' errors in PL/Python execution
    • Allow Python2 and Python3 to be used in the same database
    • Add support for Python 3.5 in PL/Python
    • Fix issue with subdirectory creation during initdb
    • Make pgctl report status correctly on Windows
    • Suppress confusing error when using pgreceivexlog with older servers
    • Multiple documentation corrections and additions
    • Fix erroneous hash calculations in ginextractjsonbpath()
  • For the full release notse, see: http://www.postgresql.org/docs/9.3/static/release-9-3-11.html
References

Affected packages

SUSE:Linux Enterprise Desktop 12 / postgresql93

Package

Name
postgresql93
Purl
pkg:rpm/suse/postgresql93&distro=SUSE%20Linux%20Enterprise%20Desktop%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.3.11-14.2

Ecosystem specific

{
    "binaries": [
        {
            "postgresql93": "9.3.11-14.2"
        }
    ]
}

SUSE:Linux Enterprise Software Development Kit 12 / postgresql93-libs

Package

Name
postgresql93-libs
Purl
pkg:rpm/suse/postgresql93-libs&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.3.11-14.1

Ecosystem specific

{
    "binaries": [
        {
            "postgresql93-devel": "9.3.11-14.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 / postgresql93

Package

Name
postgresql93
Purl
pkg:rpm/suse/postgresql93&distro=SUSE%20Linux%20Enterprise%20Server%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.3.11-14.2

Ecosystem specific

{
    "binaries": [
        {
            "postgresql93-contrib": "9.3.11-14.2",
            "postgresql93": "9.3.11-14.2",
            "postgresql93-server": "9.3.11-14.2",
            "postgresql93-docs": "9.3.11-14.2"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 / postgresql93

Package

Name
postgresql93
Purl
pkg:rpm/suse/postgresql93&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.3.11-14.2

Ecosystem specific

{
    "binaries": [
        {
            "postgresql93-contrib": "9.3.11-14.2",
            "postgresql93": "9.3.11-14.2",
            "postgresql93-server": "9.3.11-14.2",
            "postgresql93-docs": "9.3.11-14.2"
        }
    ]
}