{"id":"openSUSE-SU-2021:0337-1","summary":"Security update for postgresql, postgresql13","details":"This update for postgresql, postgresql13 fixes the following issues:\n\nThis update ships postgresql13.\n\nUpgrade to version 13.1:\n\n* CVE-2020-25695, bsc#1178666: Block DECLARE CURSOR ... WITH HOLD\n  and firing of deferred triggers within index expressions and\n  materialized view queries.\n* CVE-2020-25694, bsc#1178667:\n  a) Fix usage of complex connection-string parameters in pg_dump,\n  pg_restore, clusterdb, reindexdb, and vacuumdb.\n  b) When psql's \\connect command re-uses connection parameters,\n  ensure that all non-overridden parameters from a previous\n  connection string are re-used.\n* CVE-2020-25696, bsc#1178668: Prevent psql's \\gset command from\n  modifying specially-treated variables.\n* Fix recently-added timetz test case so it works when the USA\n  is not observing daylight savings time.\n  (obsoletes postgresql-timetz.patch)\n* https://www.postgresql.org/about/news/2111/\n* https://www.postgresql.org/docs/13/release-13-1.html\n\nInitial packaging of PostgreSQL 13:\n\n* https://www.postgresql.org/about/news/2077/\n* https://www.postgresql.org/docs/13/release-13.html\n\n- bsc#1178961: %ghost the symlinks to pg_config and ecpg.\n\nChanges in postgresql wrapper package:\n\n- Bump major version to 13.\n- We also transfer PostgreSQL 9.4.26 to the new package layout in\n  SLE12-SP2 and newer. Reflect this in the conflict with\n  postgresql94.\n- Also conflict with PostgreSQL versions before 9.\n- Conflicting with older versions is not limited to SLE.\n\nThis update was imported from the SUSE:SLE-15-SP2:Update update project.","modified":"2026-03-11T07:32:56.741901Z","published":"2021-02-24T17:05:14Z","related":["CVE-2020-25694","CVE-2020-25695","CVE-2020-25696"],"upstream":["CVE-2020-25694","CVE-2020-25695","CVE-2020-25696"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IQQBNVIVAXDZCJPFZE43ZEZ3C6DSC3WG/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178666"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178667"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178668"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178961"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25694"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25695"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25696"}],"affected":[{"package":{"name":"postgresql","ecosystem":"openSUSE:Leap 15.2","purl":"pkg:rpm/opensuse/postgresql&distro=openSUSE%20Leap%2015.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"13-lp152.3.6.1"}]}],"ecosystem_specific":{"binaries":[{"postgresql-test":"13-lp152.3.6.1","postgresql-docs":"13-lp152.3.6.1","postgresql-plperl":"13-lp152.3.6.1","postgresql":"13-lp152.3.6.1","postgresql-contrib":"13-lp152.3.6.1","postgresql-devel":"13-lp152.3.6.1","postgresql-llvmjit":"13-lp152.3.6.1","postgresql-plpython":"13-lp152.3.6.1","postgresql-pltcl":"13-lp152.3.6.1","postgresql-server-devel":"13-lp152.3.6.1","postgresql-server":"13-lp152.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:0337-1.json"}}],"schema_version":"1.7.5"}