[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2018:1695-1 -- SLES libecpg6, libpq5, postgresql96

ID: oval:org.secpod.oval:def:89043688Date: (C)2021-03-05   (M)2022-12-07
Class: PATCHFamily: unix




PostgreSQL was updated to 9.6.9 fixing bugs and security issues: Release notes: - https://www.postgresql.org/about/news/1851/ - https://www.postgresql.org/docs/current/static/release-9-6-9.html A dump/restore is not required for those running 9.6.X. However, if you use the adminpack extension, you should update it as per the first changelog entry below. Also, if the function marking mistakes mentioned in the second and third changelog entries below affect you, you will want to take steps to correct your database catalogs. Security issue fixed: - CVE-2018-1115: Remove public execute privilege from contrib/adminpack"s pg_logfile_rotate function pg_logfile_rotate is a deprecated wrapper for the core function pg_rotate_logfile. When that function was changed to rely on SQL privileges for access control rather than a hard-coded superuser check, pg_logfile_rotate should have been updated as well, but the need for this was missed. Hence, if adminpack is installed, any user could request a logfile rotation, creating a minor security issue. After installing this update, administrators should update adminpack by performing ALTER EXTENSION adminpack UPDATE in each database in which adminpack is installed

Platform:
SUSE Linux Enterprise Server 12 SP3
Product:
libecpg6
libpq5
postgresql96
Reference:
SUSE-SU-2018:1695-1
CVE-2018-1115
CVE    1
CVE-2018-1115

© SecPod Technologies