{"id":"openSUSE-SU-2020:2018-1","summary":"Security update for postgresql12","details":"This update for postgresql12 fixes the following issues:\n\n- Upgrade to version 12.5:\n  * CVE-2020-25695, bsc#1178666: Block DECLARE CURSOR ... WITH HOLD\n    and firing of deferred triggers within index expressions and\n    materialized view queries.\n  * CVE-2020-25694, bsc#1178667:\n    a) Fix usage of complex connection-string parameters in pg_dump,\n    pg_restore, clusterdb, reindexdb, and vacuumdb.\n    b) When psql's \\connect command re-uses connection parameters,\n    ensure that all non-overridden parameters from a previous\n    connection string are re-used.\n  * CVE-2020-25696, bsc#1178668: Prevent psql's \\gset command from\n    modifying specially-treated variables.\n  * Fix recently-added timetz test case so it works when the USA\n    is not observing daylight savings time.\n  * https://www.postgresql.org/about/news/2111/\n  * https://www.postgresql.org/docs/12/release-12-5.html\n\nThis update was imported from the SUSE:SLE-15-SP1:Update update project.","modified":"2026-03-11T07:32:47.036581Z","published":"2020-11-25T20:08:45Z","related":["CVE-2020-25694","CVE-2020-25695","CVE-2020-25696"],"upstream":["CVE-2020-25694","CVE-2020-25695","CVE-2020-25696"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/POYD3IAUBQT7S6ZQCAA74X6IBDUAZLMP/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178666"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178667"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178668"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25694"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25695"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25696"}],"affected":[{"package":{"name":"postgresql12","ecosystem":"openSUSE:Leap 15.2","purl":"pkg:rpm/opensuse/postgresql12&distro=openSUSE%20Leap%2015.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.5-lp152.3.10.1"}]}],"ecosystem_specific":{"binaries":[{"libecpg6":"12.5-lp152.3.10.1","postgresql12-devel":"12.5-lp152.3.10.1","postgresql12-pltcl":"12.5-lp152.3.10.1","postgresql12":"12.5-lp152.3.10.1","libecpg6-32bit":"12.5-lp152.3.10.1","libpq5-32bit":"12.5-lp152.3.10.1","postgresql12-contrib":"12.5-lp152.3.10.1","postgresql12-docs":"12.5-lp152.3.10.1","postgresql12-plperl":"12.5-lp152.3.10.1","postgresql12-plpython":"12.5-lp152.3.10.1","libpq5":"12.5-lp152.3.10.1","postgresql12-llvmjit":"12.5-lp152.3.10.1","postgresql12-server-devel":"12.5-lp152.3.10.1","postgresql12-server":"12.5-lp152.3.10.1","postgresql12-test":"12.5-lp152.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:2018-1.json"}}],"schema_version":"1.7.5"}