{"id":"SUSE-SU-2020:3463-1","summary":"Security update for postgresql12","details":"This update for postgresql12 fixes the following issues:\n\n- Upgrade to version 12.5:\n  * CVE-2020-25695, bsc#1178666: Block DECLARE CURSOR ... WITH HOLD\n    and firing of deferred triggers within index expressions and\n    materialized view queries.\n  * CVE-2020-25694, bsc#1178667:\n    a) Fix usage of complex connection-string parameters in pg_dump,\n    pg_restore, clusterdb, reindexdb, and vacuumdb.\n    b) When psql's \\connect command re-uses connection parameters,\n    ensure that all non-overridden parameters from a previous\n    connection string are re-used.\n  * CVE-2020-25696, bsc#1178668: Prevent psql's \\gset command from\n    modifying specially-treated variables.\n  * Fix recently-added timetz test case so it works when the USA\n    is not observing daylight savings time.\n  * https://www.postgresql.org/about/news/2111/\n  * https://www.postgresql.org/docs/12/release-12-5.html\n\n- Stop building the mini and lib packages as they are now coming\n  from postgresql13.\n","modified":"2026-03-11T07:15:51.450928Z","published":"2020-11-20T12:50:11Z","related":["CVE-2020-25694","CVE-2020-25695","CVE-2020-25696"],"upstream":["CVE-2020-25694","CVE-2020-25695","CVE-2020-25696"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2020/suse-su-20203463-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178666"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178667"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178668"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25694"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25695"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25696"}],"affected":[{"package":{"name":"postgresql12","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP2","purl":"pkg:rpm/suse/postgresql12&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.5-8.10.1"}]}],"ecosystem_specific":{"binaries":[{"libpq5":"12.5-8.10.1","postgresql12":"12.5-8.10.1","libpq5-32bit":"12.5-8.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:3463-1.json"}},{"package":{"name":"postgresql12","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP2","purl":"pkg:rpm/suse/postgresql12&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.5-8.10.1"}]}],"ecosystem_specific":{"binaries":[{"postgresql12-contrib":"12.5-8.10.1","postgresql12-devel":"12.5-8.10.1","postgresql12-plperl":"12.5-8.10.1","postgresql12-plpython":"12.5-8.10.1","postgresql12-pltcl":"12.5-8.10.1","postgresql12-server-devel":"12.5-8.10.1","libecpg6":"12.5-8.10.1","postgresql12-docs":"12.5-8.10.1","postgresql12-server":"12.5-8.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:3463-1.json"}}],"schema_version":"1.7.5"}