SUSE-SU-2018:1695-1

Source
https://www.suse.com/support/update/announcement/2018/suse-su-20181695-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:1695-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2018:1695-1
Upstream
Related
Published
2018-06-14T14:42:42Z
Modified
2026-03-11T06:48:09Z
Summary
Security update for postgresql96
Details

PostgreSQL was updated to 9.6.9 fixing bugs and security issues:

Release notes:

Security issue fixed:

  • CVE-2018-1115: Remove public execute privilege from contrib/adminpack's pg_logfile_rotate() function pg_logfile_rotate() is a deprecated wrapper for the core function pg_rotate_logfile(). When that function was changed to rely on SQL privileges for access control rather than a hard-coded superuser check, pg_logfile_rotate() should have been updated as well, but the need for this was missed. Hence, if adminpack is installed, any user could request a logfile rotation, creating a minor security issue. After installing this update, administrators should update adminpack by performing ALTER EXTENSION adminpack UPDATE in each database in which adminpack is installed. (bsc#1091610)
References

Affected packages

SUSE:Linux Enterprise Desktop 12 SP3
postgresql96

Package

Name
postgresql96
Purl
pkg:rpm/suse/postgresql96&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.6.9-3.19.1

Ecosystem specific

{
    "binaries":  [
        {
            "libecpg6":  "9.6.9-3.19.1",
            "libpq5":  "9.6.9-3.19.1",
            "libpq5-32bit":  "9.6.9-3.19.1",
            "postgresql96":  "9.6.9-3.19.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:1695-1.json"
postgresql96-libs

Package

Name
postgresql96-libs
Purl
pkg:rpm/suse/postgresql96-libs&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.6.9-3.19.1

Ecosystem specific

{
    "binaries":  [
        {
            "libecpg6":  "9.6.9-3.19.1",
            "libpq5":  "9.6.9-3.19.1",
            "libpq5-32bit":  "9.6.9-3.19.1",
            "postgresql96":  "9.6.9-3.19.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:1695-1.json"
SUSE:Linux Enterprise Server 12 SP3
postgresql96

Package

Name
postgresql96
Purl
pkg:rpm/suse/postgresql96&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.6.9-3.19.1

Ecosystem specific

{
    "binaries":  [
        {
            "libecpg6":  "9.6.9-3.19.1",
            "libpq5":  "9.6.9-3.19.1",
            "libpq5-32bit":  "9.6.9-3.19.1",
            "postgresql96":  "9.6.9-3.19.1",
            "postgresql96-contrib":  "9.6.9-3.19.1",
            "postgresql96-docs":  "9.6.9-3.19.1",
            "postgresql96-server":  "9.6.9-3.19.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:1695-1.json"
postgresql96-libs

Package

Name
postgresql96-libs
Purl
pkg:rpm/suse/postgresql96-libs&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.6.9-3.19.1

Ecosystem specific

{
    "binaries":  [
        {
            "libecpg6":  "9.6.9-3.19.1",
            "libpq5":  "9.6.9-3.19.1",
            "libpq5-32bit":  "9.6.9-3.19.1",
            "postgresql96":  "9.6.9-3.19.1",
            "postgresql96-contrib":  "9.6.9-3.19.1",
            "postgresql96-docs":  "9.6.9-3.19.1",
            "postgresql96-server":  "9.6.9-3.19.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:1695-1.json"
SUSE:Linux Enterprise Server for SAP Applications 12 SP3
postgresql96

Package

Name
postgresql96
Purl
pkg:rpm/suse/postgresql96&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.6.9-3.19.1

Ecosystem specific

{
    "binaries":  [
        {
            "libecpg6":  "9.6.9-3.19.1",
            "libpq5":  "9.6.9-3.19.1",
            "libpq5-32bit":  "9.6.9-3.19.1",
            "postgresql96":  "9.6.9-3.19.1",
            "postgresql96-contrib":  "9.6.9-3.19.1",
            "postgresql96-docs":  "9.6.9-3.19.1",
            "postgresql96-server":  "9.6.9-3.19.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:1695-1.json"
postgresql96-libs

Package

Name
postgresql96-libs
Purl
pkg:rpm/suse/postgresql96-libs&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.6.9-3.19.1

Ecosystem specific

{
    "binaries":  [
        {
            "libecpg6":  "9.6.9-3.19.1",
            "libpq5":  "9.6.9-3.19.1",
            "libpq5-32bit":  "9.6.9-3.19.1",
            "postgresql96":  "9.6.9-3.19.1",
            "postgresql96-contrib":  "9.6.9-3.19.1",
            "postgresql96-docs":  "9.6.9-3.19.1",
            "postgresql96-server":  "9.6.9-3.19.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:1695-1.json"
SUSE:Linux Enterprise Software Development Kit 12 SP3
postgresql96-libs

Package

Name
postgresql96-libs
Purl
pkg:rpm/suse/postgresql96-libs&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.6.9-3.19.1

Ecosystem specific

{
    "binaries":  [
        {
            "postgresql96-devel":  "9.6.9-3.19.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:1695-1.json"