Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package postgresql15 for openSUSE:Factory 
checked in at 2023-11-10 12:29:02
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/postgresql15 (Old)
 and      /work/SRC/openSUSE:Factory/.postgresql15.new.17445 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "postgresql15"

Fri Nov 10 12:29:02 2023 rev:13 rq:1124708 version:15.5

Changes:
--------
--- /work/SRC/openSUSE:Factory/postgresql15/postgresql15.changes        
2023-11-02 20:20:39.710051644 +0100
+++ /work/SRC/openSUSE:Factory/.postgresql15.new.17445/postgresql15.changes     
2023-11-10 12:29:10.199303483 +0100
@@ -1,0 +2,32 @@
+Wed Nov  8 14:26:51 UTC 2023 - Reinhard Max <[email protected]>
+
+- Upgrade to 15.5:
+  * bsc#1216962, CVE-2023-5868: Fix handling of unknown-type
+    arguments in DISTINCT "any" aggregate functions. This error led
+    to a text-type value being interpreted as an unknown-type value
+    (that is, a zero-terminated string) at runtime. This could
+    result in disclosure of server memory following the text value.
+  * bsc#1216961, CVE-2023-5869: Detect integer overflow while
+    computing new array dimensions. When assigning new elements to
+    array subscripts that are outside the current array bounds, an
+    undetected integer overflow could occur in edge cases. Memory
+    stomps that are potentially exploitable for arbitrary code
+    execution are possible, and so is disclosure of server memory.
+  * bsc#1216960, CVE-2023-5870: Prevent the pg_signal_backend role
+    from signalling background workers and autovacuum processes.
+    The documentation says that pg_signal_backend cannot issue
+    signals to superuser-owned processes. It was able to signal
+    these background  processes, though, because they advertise a
+    role OID of zero. Treat that as indicating superuser ownership.
+    The security implications of cancelling one of these process
+    types are fairly small so far as the core code goes (we'll just
+    start another one), but extensions might add background workers
+    that are more vulnerable.
+    Also ensure that the is_superuser parameter is set correctly in
+    such processes. No specific security consequences are known for
+    that oversight, but it might be significant for some extensions.
+  * Add support for LLVM 16 and 17
+  * https://www.postgresql.org/about/news/2749
+  * https://www.postgresql.org/docs/15/release-15-5.html
+ 
+-------------------------------------------------------------------

Old:
----
  postgresql-15.4.tar.bz2
  postgresql-15.4.tar.bz2.sha256

New:
----
  postgresql-15.5.tar.bz2
  postgresql-15.5.tar.bz2.sha256

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ postgresql15.spec ++++++
--- /var/tmp/diff_new_pack.XBNWAI/_old  2023-11-10 12:29:11.279343100 +0100
+++ /var/tmp/diff_new_pack.XBNWAI/_new  2023-11-10 12:29:11.279343100 +0100
@@ -16,11 +16,11 @@
 #
 
 
-%define pgversion 15.4
+%define pgversion 15.5
 %define pgmajor 15
 %define buildlibs 0
 %define tarversion %{pgversion}
-%define latest_supported_llvm_ver 15
+%define latest_supported_llvm_ver 17
 
 ### CUT HERE ###
 %define pgname postgresql%pgmajor
@@ -797,11 +797,9 @@
 
 %post -n %pgname-%devel
 /sbin/ldconfig
-/usr/share/postgresql/install-alternatives %pgmajor
 
 %postun -n %pgname-%devel
 /sbin/ldconfig
-/usr/share/postgresql/install-alternatives %pgmajor
 
 %if %{with server_devel}
 %post server-devel

++++++ postgresql-15.4.tar.bz2 -> postgresql-15.5.tar.bz2 ++++++
/work/SRC/openSUSE:Factory/postgresql15/postgresql-15.4.tar.bz2 
/work/SRC/openSUSE:Factory/.postgresql15.new.17445/postgresql-15.5.tar.bz2 
differ: char 11, line 1

++++++ postgresql-15.4.tar.bz2.sha256 -> postgresql-15.5.tar.bz2.sha256 ++++++
--- /work/SRC/openSUSE:Factory/postgresql15/postgresql-15.4.tar.bz2.sha256      
2023-08-15 16:39:25.470749013 +0200
+++ 
/work/SRC/openSUSE:Factory/.postgresql15.new.17445/postgresql-15.5.tar.bz2.sha256
   2023-11-10 12:29:10.187303043 +0100
@@ -1 +1 @@
-baec5a4bdc4437336653b6cb5d9ed89be5bd5c0c58b94e0becee0a999e63c8f9  
postgresql-15.4.tar.bz2
+8f53aa95d78eb8e82536ea46b68187793b42bba3b4f65aa342f540b23c9b10a6  
postgresql-15.5.tar.bz2

Reply via email to