Hello community, here is the log from the commit of package postgresql96 for openSUSE:Factory checked in at 2017-12-12 21:18:22 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/postgresql96 (Old) and /work/SRC/openSUSE:Factory/.postgresql96.new (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "postgresql96" Tue Dec 12 21:18:22 2017 rev:7 rq:554740 version:9.6.6 Changes: -------- --- /work/SRC/openSUSE:Factory/postgresql96/postgresql96.changes 2017-11-26 10:33:32.913946162 +0100 +++ /work/SRC/openSUSE:Factory/.postgresql96.new/postgresql96.changes 2017-12-12 21:18:32.303262304 +0100 @@ -1,0 +2,23 @@ +Tue Dec 5 15:25:24 UTC 2017 - [email protected] + +- Update to version 9.6.6: + * https://www.postgresql.org/docs/9.6/static/release-9-6-6.html + * Security Issues + - CVE-2017-15098, bsc#1067844: + Memory disclosure in JSON functions + - CVE-2017-15099, bsc#1067841: INSERT ... ON CONFLICT DO UPDATE + fails to enforce SELECT privileges + + Prior to this release, the "INSERT ... ON CONFLICT DO UPDATE" + would not check to see if the executing user had permission + to perform a "SELECT" on the index performing the conflicting + check. Additionally, in a table with row-level security + enabled, the "INSERT ... ON CONFLICT DO UPDATE" would not + check the SELECT policies for that table before performing + the update. + + This fix ensures that "INSERT ... ON CONFLICT DO UPDATE" + checks against table permissions and RLS policies before + executing. + +------------------------------------------------------------------- Old: ---- postgresql-9.6.5.tar.bz2 New: ---- postgresql-9.6.6.tar.bz2 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ postgresql96.spec ++++++ --- /var/tmp/diff_new_pack.6n0eA3/_old 2017-12-12 21:18:34.287166532 +0100 +++ /var/tmp/diff_new_pack.6n0eA3/_new 2017-12-12 21:18:34.287166532 +0100 @@ -80,7 +80,7 @@ Summary: Basic Clients and Utilities for PostgreSQL License: PostgreSQL Group: Productivity/Databases/Tools -Version: 9.6.5 +Version: 9.6.6 Release: 0 Source0: https://ftp.postgresql.org/pub/source/v%{version}/postgresql-%{version}.tar.bz2 Source1: baselibs.conf ++++++ postgresql-9.6.5.tar.bz2 -> postgresql-9.6.6.tar.bz2 ++++++ /work/SRC/openSUSE:Factory/postgresql96/postgresql-9.6.5.tar.bz2 /work/SRC/openSUSE:Factory/.postgresql96.new/postgresql-9.6.6.tar.bz2 differ: char 11, line 1
