suse-su-2015:1821-1
Vulnerability from csaf_suse
Published
2015-10-20 15:54
Modified
2015-10-20 15:54
Summary
Security update for postgresql93

Notes

Title of the patch
Security update for postgresql93
Description of the patch
The PostreSQL database postgresql93 was updated to the bugfix release 9.3.10: Security issues fixed: - CVE-2015-5289, bsc#949670: json or jsonb input values constructed from arbitrary user input can crash the PostgreSQL server and cause a denial of service. - CVE-2015-5288, bsc#949669: The crypt() function included with the optional pgCrypto extension could be exploited to read a few additional bytes of memory. No working exploit for this issue has been developed. For the full release notes, see: http://www.postgresql.org/docs/current/static/release-9-3-10.html Other bugs fixed: * Move systemd related stuff and user creation to postgresql-init. * Remove some obsolete %suse_version conditionals. * Relax dependency on libpq to major version. * Fix possible failure to recover from an inconsistent database state. See full release notes for details. * Fix rare failure to invalidate relation cache init file. * Avoid deadlock between incoming sessions and CREATE/DROP DATABASE. * Improve planner's cost estimates for semi-joins and anti-joins with inner indexscans * For the full release notes for 9.3.9 see: http://www.postgresql.org/docs/9.3/static/release-9-3-9.html
Patchnames
SUSE-SLE-DESKTOP-12-2015-746,SUSE-SLE-SDK-12-2015-746,SUSE-SLE-SERVER-12-2015-746
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).



{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.suse.com/support/security/rating/",
      "text": "moderate"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright 2024 SUSE LLC. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "Security update for postgresql93",
        "title": "Title of the patch"
      },
      {
        "category": "description",
        "text": "\nThe PostreSQL database postgresql93 was updated to the bugfix release 9.3.10:\n\nSecurity issues fixed:\n- CVE-2015-5289, bsc#949670: json or jsonb input values\n  constructed from arbitrary user input can crash the PostgreSQL\n  server and cause a denial of service.\n- CVE-2015-5288, bsc#949669: The crypt() function included with\n  the optional pgCrypto extension could be exploited to read a\n  few additional bytes of memory. No working exploit for this\n  issue has been developed.\n\nFor the full release notes, see:\n  http://www.postgresql.org/docs/current/static/release-9-3-10.html\n\nOther bugs fixed:\n* Move systemd related stuff and user creation to postgresql-init.\n* Remove some obsolete %suse_version conditionals.\n* Relax dependency on libpq to major version.\n* Fix possible failure to recover from an inconsistent database state. See full release notes for details.\n* Fix rare failure to invalidate relation cache init file.\n* Avoid deadlock between incoming sessions and CREATE/DROP DATABASE.\n* Improve planner\u0027s cost estimates for semi-joins and anti-joins with inner indexscans\n* For the full release notes for 9.3.9 see: http://www.postgresql.org/docs/9.3/static/release-9-3-9.html\n  ",
        "title": "Description of the patch"
      },
      {
        "category": "details",
        "text": "SUSE-SLE-DESKTOP-12-2015-746,SUSE-SLE-SDK-12-2015-746,SUSE-SLE-SERVER-12-2015-746",
        "title": "Patchnames"
      },
      {
        "category": "legal_disclaimer",
        "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
        "title": "Terms of use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://www.suse.com/support/security/contact/",
      "name": "SUSE Product Security Team",
      "namespace": "https://www.suse.com/"
    },
    "references": [
      {
        "category": "external",
        "summary": "SUSE ratings",
        "url": "https://www.suse.com/support/security/rating/"
      },
      {
        "category": "self",
        "summary": "URL of this CSAF notice",
        "url": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2015_1821-1.json"
      },
      {
        "category": "self",
        "summary": "URL for SUSE-SU-2015:1821-1",
        "url": "https://www.suse.com/support/update/announcement/2015/suse-su-20151821-1/"
      },
      {
        "category": "self",
        "summary": "E-Mail link for SUSE-SU-2015:1821-1",
        "url": "https://lists.suse.com/pipermail/sle-security-updates/2015-October/001646.html"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 949669",
        "url": "https://bugzilla.suse.com/949669"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 949670",
        "url": "https://bugzilla.suse.com/949670"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2015-5288 page",
        "url": "https://www.suse.com/security/cve/CVE-2015-5288/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2015-5289 page",
        "url": "https://www.suse.com/security/cve/CVE-2015-5289/"
      }
    ],
    "title": "Security update for postgresql93",
    "tracking": {
      "current_release_date": "2015-10-20T15:54:16Z",
      "generator": {
        "date": "2015-10-20T15:54:16Z",
        "engine": {
          "name": "cve-database.git:bin/generate-csaf.pl",
          "version": "1"
        }
      },
      "id": "SUSE-SU-2015:1821-1",
      "initial_release_date": "2015-10-20T15:54:16Z",
      "revision_history": [
        {
          "date": "2015-10-20T15:54:16Z",
          "number": "1",
          "summary": "Current version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "postgresql93-docs-9.3.10-11.1.noarch",
                "product": {
                  "name": "postgresql93-docs-9.3.10-11.1.noarch",
                  "product_id": "postgresql93-docs-9.3.10-11.1.noarch"
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "postgresql93-devel-9.3.10-11.1.ppc64le",
                "product": {
                  "name": "postgresql93-devel-9.3.10-11.1.ppc64le",
                  "product_id": "postgresql93-devel-9.3.10-11.1.ppc64le"
                }
              },
              {
                "category": "product_version",
                "name": "postgresql93-9.3.10-11.1.ppc64le",
                "product": {
                  "name": "postgresql93-9.3.10-11.1.ppc64le",
                  "product_id": "postgresql93-9.3.10-11.1.ppc64le"
                }
              },
              {
                "category": "product_version",
                "name": "postgresql93-contrib-9.3.10-11.1.ppc64le",
                "product": {
                  "name": "postgresql93-contrib-9.3.10-11.1.ppc64le",
                  "product_id": "postgresql93-contrib-9.3.10-11.1.ppc64le"
                }
              },
              {
                "category": "product_version",
                "name": "postgresql93-server-9.3.10-11.1.ppc64le",
                "product": {
                  "name": "postgresql93-server-9.3.10-11.1.ppc64le",
                  "product_id": "postgresql93-server-9.3.10-11.1.ppc64le"
                }
              }
            ],
            "category": "architecture",
            "name": "ppc64le"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "postgresql93-devel-9.3.10-11.1.s390x",
                "product": {
                  "name": "postgresql93-devel-9.3.10-11.1.s390x",
                  "product_id": "postgresql93-devel-9.3.10-11.1.s390x"
                }
              },
              {
                "category": "product_version",
                "name": "postgresql93-9.3.10-11.1.s390x",
                "product": {
                  "name": "postgresql93-9.3.10-11.1.s390x",
                  "product_id": "postgresql93-9.3.10-11.1.s390x"
                }
              },
              {
                "category": "product_version",
                "name": "postgresql93-contrib-9.3.10-11.1.s390x",
                "product": {
                  "name": "postgresql93-contrib-9.3.10-11.1.s390x",
                  "product_id": "postgresql93-contrib-9.3.10-11.1.s390x"
                }
              },
              {
                "category": "product_version",
                "name": "postgresql93-server-9.3.10-11.1.s390x",
                "product": {
                  "name": "postgresql93-server-9.3.10-11.1.s390x",
                  "product_id": "postgresql93-server-9.3.10-11.1.s390x"
                }
              }
            ],
            "category": "architecture",
            "name": "s390x"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "postgresql93-9.3.10-11.1.x86_64",
                "product": {
                  "name": "postgresql93-9.3.10-11.1.x86_64",
                  "product_id": "postgresql93-9.3.10-11.1.x86_64"
                }
              },
              {
                "category": "product_version",
                "name": "postgresql93-devel-9.3.10-11.1.x86_64",
                "product": {
                  "name": "postgresql93-devel-9.3.10-11.1.x86_64",
                  "product_id": "postgresql93-devel-9.3.10-11.1.x86_64"
                }
              },
              {
                "category": "product_version",
                "name": "postgresql93-contrib-9.3.10-11.1.x86_64",
                "product": {
                  "name": "postgresql93-contrib-9.3.10-11.1.x86_64",
                  "product_id": "postgresql93-contrib-9.3.10-11.1.x86_64"
                }
              },
              {
                "category": "product_version",
                "name": "postgresql93-server-9.3.10-11.1.x86_64",
                "product": {
                  "name": "postgresql93-server-9.3.10-11.1.x86_64",
                  "product_id": "postgresql93-server-9.3.10-11.1.x86_64"
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Desktop 12",
                "product": {
                  "name": "SUSE Linux Enterprise Desktop 12",
                  "product_id": "SUSE Linux Enterprise Desktop 12",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sled:12"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Software Development Kit 12",
                "product": {
                  "name": "SUSE Linux Enterprise Software Development Kit 12",
                  "product_id": "SUSE Linux Enterprise Software Development Kit 12",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sle-sdk:12"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Server 12",
                "product": {
                  "name": "SUSE Linux Enterprise Server 12",
                  "product_id": "SUSE Linux Enterprise Server 12",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sles:12"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Server for SAP Applications 12",
                "product": {
                  "name": "SUSE Linux Enterprise Server for SAP Applications 12",
                  "product_id": "SUSE Linux Enterprise Server for SAP Applications 12",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sles_sap:12"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "SUSE Linux Enterprise"
          }
        ],
        "category": "vendor",
        "name": "SUSE"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-9.3.10-11.1.x86_64 as component of SUSE Linux Enterprise Desktop 12",
          "product_id": "SUSE Linux Enterprise Desktop 12:postgresql93-9.3.10-11.1.x86_64"
        },
        "product_reference": "postgresql93-9.3.10-11.1.x86_64",
        "relates_to_product_reference": "SUSE Linux Enterprise Desktop 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-devel-9.3.10-11.1.ppc64le as component of SUSE Linux Enterprise Software Development Kit 12",
          "product_id": "SUSE Linux Enterprise Software Development Kit 12:postgresql93-devel-9.3.10-11.1.ppc64le"
        },
        "product_reference": "postgresql93-devel-9.3.10-11.1.ppc64le",
        "relates_to_product_reference": "SUSE Linux Enterprise Software Development Kit 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-devel-9.3.10-11.1.s390x as component of SUSE Linux Enterprise Software Development Kit 12",
          "product_id": "SUSE Linux Enterprise Software Development Kit 12:postgresql93-devel-9.3.10-11.1.s390x"
        },
        "product_reference": "postgresql93-devel-9.3.10-11.1.s390x",
        "relates_to_product_reference": "SUSE Linux Enterprise Software Development Kit 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-devel-9.3.10-11.1.x86_64 as component of SUSE Linux Enterprise Software Development Kit 12",
          "product_id": "SUSE Linux Enterprise Software Development Kit 12:postgresql93-devel-9.3.10-11.1.x86_64"
        },
        "product_reference": "postgresql93-devel-9.3.10-11.1.x86_64",
        "relates_to_product_reference": "SUSE Linux Enterprise Software Development Kit 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-9.3.10-11.1.ppc64le as component of SUSE Linux Enterprise Server 12",
          "product_id": "SUSE Linux Enterprise Server 12:postgresql93-9.3.10-11.1.ppc64le"
        },
        "product_reference": "postgresql93-9.3.10-11.1.ppc64le",
        "relates_to_product_reference": "SUSE Linux Enterprise Server 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-9.3.10-11.1.s390x as component of SUSE Linux Enterprise Server 12",
          "product_id": "SUSE Linux Enterprise Server 12:postgresql93-9.3.10-11.1.s390x"
        },
        "product_reference": "postgresql93-9.3.10-11.1.s390x",
        "relates_to_product_reference": "SUSE Linux Enterprise Server 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-9.3.10-11.1.x86_64 as component of SUSE Linux Enterprise Server 12",
          "product_id": "SUSE Linux Enterprise Server 12:postgresql93-9.3.10-11.1.x86_64"
        },
        "product_reference": "postgresql93-9.3.10-11.1.x86_64",
        "relates_to_product_reference": "SUSE Linux Enterprise Server 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-contrib-9.3.10-11.1.ppc64le as component of SUSE Linux Enterprise Server 12",
          "product_id": "SUSE Linux Enterprise Server 12:postgresql93-contrib-9.3.10-11.1.ppc64le"
        },
        "product_reference": "postgresql93-contrib-9.3.10-11.1.ppc64le",
        "relates_to_product_reference": "SUSE Linux Enterprise Server 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-contrib-9.3.10-11.1.s390x as component of SUSE Linux Enterprise Server 12",
          "product_id": "SUSE Linux Enterprise Server 12:postgresql93-contrib-9.3.10-11.1.s390x"
        },
        "product_reference": "postgresql93-contrib-9.3.10-11.1.s390x",
        "relates_to_product_reference": "SUSE Linux Enterprise Server 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-contrib-9.3.10-11.1.x86_64 as component of SUSE Linux Enterprise Server 12",
          "product_id": "SUSE Linux Enterprise Server 12:postgresql93-contrib-9.3.10-11.1.x86_64"
        },
        "product_reference": "postgresql93-contrib-9.3.10-11.1.x86_64",
        "relates_to_product_reference": "SUSE Linux Enterprise Server 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-docs-9.3.10-11.1.noarch as component of SUSE Linux Enterprise Server 12",
          "product_id": "SUSE Linux Enterprise Server 12:postgresql93-docs-9.3.10-11.1.noarch"
        },
        "product_reference": "postgresql93-docs-9.3.10-11.1.noarch",
        "relates_to_product_reference": "SUSE Linux Enterprise Server 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-server-9.3.10-11.1.ppc64le as component of SUSE Linux Enterprise Server 12",
          "product_id": "SUSE Linux Enterprise Server 12:postgresql93-server-9.3.10-11.1.ppc64le"
        },
        "product_reference": "postgresql93-server-9.3.10-11.1.ppc64le",
        "relates_to_product_reference": "SUSE Linux Enterprise Server 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-server-9.3.10-11.1.s390x as component of SUSE Linux Enterprise Server 12",
          "product_id": "SUSE Linux Enterprise Server 12:postgresql93-server-9.3.10-11.1.s390x"
        },
        "product_reference": "postgresql93-server-9.3.10-11.1.s390x",
        "relates_to_product_reference": "SUSE Linux Enterprise Server 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-server-9.3.10-11.1.x86_64 as component of SUSE Linux Enterprise Server 12",
          "product_id": "SUSE Linux Enterprise Server 12:postgresql93-server-9.3.10-11.1.x86_64"
        },
        "product_reference": "postgresql93-server-9.3.10-11.1.x86_64",
        "relates_to_product_reference": "SUSE Linux Enterprise Server 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-9.3.10-11.1.ppc64le as component of SUSE Linux Enterprise Server for SAP Applications 12",
          "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-9.3.10-11.1.ppc64le"
        },
        "product_reference": "postgresql93-9.3.10-11.1.ppc64le",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-9.3.10-11.1.s390x as component of SUSE Linux Enterprise Server for SAP Applications 12",
          "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-9.3.10-11.1.s390x"
        },
        "product_reference": "postgresql93-9.3.10-11.1.s390x",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-9.3.10-11.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12",
          "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-9.3.10-11.1.x86_64"
        },
        "product_reference": "postgresql93-9.3.10-11.1.x86_64",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-contrib-9.3.10-11.1.ppc64le as component of SUSE Linux Enterprise Server for SAP Applications 12",
          "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-contrib-9.3.10-11.1.ppc64le"
        },
        "product_reference": "postgresql93-contrib-9.3.10-11.1.ppc64le",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-contrib-9.3.10-11.1.s390x as component of SUSE Linux Enterprise Server for SAP Applications 12",
          "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-contrib-9.3.10-11.1.s390x"
        },
        "product_reference": "postgresql93-contrib-9.3.10-11.1.s390x",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-contrib-9.3.10-11.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12",
          "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-contrib-9.3.10-11.1.x86_64"
        },
        "product_reference": "postgresql93-contrib-9.3.10-11.1.x86_64",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-docs-9.3.10-11.1.noarch as component of SUSE Linux Enterprise Server for SAP Applications 12",
          "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-docs-9.3.10-11.1.noarch"
        },
        "product_reference": "postgresql93-docs-9.3.10-11.1.noarch",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-server-9.3.10-11.1.ppc64le as component of SUSE Linux Enterprise Server for SAP Applications 12",
          "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-server-9.3.10-11.1.ppc64le"
        },
        "product_reference": "postgresql93-server-9.3.10-11.1.ppc64le",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-server-9.3.10-11.1.s390x as component of SUSE Linux Enterprise Server for SAP Applications 12",
          "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-server-9.3.10-11.1.s390x"
        },
        "product_reference": "postgresql93-server-9.3.10-11.1.s390x",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "postgresql93-server-9.3.10-11.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12",
          "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-server-9.3.10-11.1.x86_64"
        },
        "product_reference": "postgresql93-server-9.3.10-11.1.x86_64",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2015-5288",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2015-5288"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9.4.5 allows attackers to cause a denial of service (server crash) or read arbitrary server memory via a \"too-short\" salt.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Desktop 12:postgresql93-9.3.10-11.1.x86_64",
          "SUSE Linux Enterprise Server 12:postgresql93-9.3.10-11.1.ppc64le",
          "SUSE Linux Enterprise Server 12:postgresql93-9.3.10-11.1.s390x",
          "SUSE Linux Enterprise Server 12:postgresql93-9.3.10-11.1.x86_64",
          "SUSE Linux Enterprise Server 12:postgresql93-contrib-9.3.10-11.1.ppc64le",
          "SUSE Linux Enterprise Server 12:postgresql93-contrib-9.3.10-11.1.s390x",
          "SUSE Linux Enterprise Server 12:postgresql93-contrib-9.3.10-11.1.x86_64",
          "SUSE Linux Enterprise Server 12:postgresql93-docs-9.3.10-11.1.noarch",
          "SUSE Linux Enterprise Server 12:postgresql93-server-9.3.10-11.1.ppc64le",
          "SUSE Linux Enterprise Server 12:postgresql93-server-9.3.10-11.1.s390x",
          "SUSE Linux Enterprise Server 12:postgresql93-server-9.3.10-11.1.x86_64",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-9.3.10-11.1.ppc64le",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-9.3.10-11.1.s390x",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-9.3.10-11.1.x86_64",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-contrib-9.3.10-11.1.ppc64le",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-contrib-9.3.10-11.1.s390x",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-contrib-9.3.10-11.1.x86_64",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-docs-9.3.10-11.1.noarch",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-server-9.3.10-11.1.ppc64le",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-server-9.3.10-11.1.s390x",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-server-9.3.10-11.1.x86_64",
          "SUSE Linux Enterprise Software Development Kit 12:postgresql93-devel-9.3.10-11.1.ppc64le",
          "SUSE Linux Enterprise Software Development Kit 12:postgresql93-devel-9.3.10-11.1.s390x",
          "SUSE Linux Enterprise Software Development Kit 12:postgresql93-devel-9.3.10-11.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2015-5288",
          "url": "https://www.suse.com/security/cve/CVE-2015-5288"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 949669 for CVE-2015-5288",
          "url": "https://bugzilla.suse.com/949669"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 949670 for CVE-2015-5288",
          "url": "https://bugzilla.suse.com/949670"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Desktop 12:postgresql93-9.3.10-11.1.x86_64",
            "SUSE Linux Enterprise Server 12:postgresql93-9.3.10-11.1.ppc64le",
            "SUSE Linux Enterprise Server 12:postgresql93-9.3.10-11.1.s390x",
            "SUSE Linux Enterprise Server 12:postgresql93-9.3.10-11.1.x86_64",
            "SUSE Linux Enterprise Server 12:postgresql93-contrib-9.3.10-11.1.ppc64le",
            "SUSE Linux Enterprise Server 12:postgresql93-contrib-9.3.10-11.1.s390x",
            "SUSE Linux Enterprise Server 12:postgresql93-contrib-9.3.10-11.1.x86_64",
            "SUSE Linux Enterprise Server 12:postgresql93-docs-9.3.10-11.1.noarch",
            "SUSE Linux Enterprise Server 12:postgresql93-server-9.3.10-11.1.ppc64le",
            "SUSE Linux Enterprise Server 12:postgresql93-server-9.3.10-11.1.s390x",
            "SUSE Linux Enterprise Server 12:postgresql93-server-9.3.10-11.1.x86_64",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-9.3.10-11.1.ppc64le",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-9.3.10-11.1.s390x",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-9.3.10-11.1.x86_64",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-contrib-9.3.10-11.1.ppc64le",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-contrib-9.3.10-11.1.s390x",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-contrib-9.3.10-11.1.x86_64",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-docs-9.3.10-11.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-server-9.3.10-11.1.ppc64le",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-server-9.3.10-11.1.s390x",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-server-9.3.10-11.1.x86_64",
            "SUSE Linux Enterprise Software Development Kit 12:postgresql93-devel-9.3.10-11.1.ppc64le",
            "SUSE Linux Enterprise Software Development Kit 12:postgresql93-devel-9.3.10-11.1.s390x",
            "SUSE Linux Enterprise Software Development Kit 12:postgresql93-devel-9.3.10-11.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2015-10-20T15:54:16Z",
          "details": "low"
        }
      ],
      "title": "CVE-2015-5288"
    },
    {
      "cve": "CVE-2015-5289",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2015-5289"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Desktop 12:postgresql93-9.3.10-11.1.x86_64",
          "SUSE Linux Enterprise Server 12:postgresql93-9.3.10-11.1.ppc64le",
          "SUSE Linux Enterprise Server 12:postgresql93-9.3.10-11.1.s390x",
          "SUSE Linux Enterprise Server 12:postgresql93-9.3.10-11.1.x86_64",
          "SUSE Linux Enterprise Server 12:postgresql93-contrib-9.3.10-11.1.ppc64le",
          "SUSE Linux Enterprise Server 12:postgresql93-contrib-9.3.10-11.1.s390x",
          "SUSE Linux Enterprise Server 12:postgresql93-contrib-9.3.10-11.1.x86_64",
          "SUSE Linux Enterprise Server 12:postgresql93-docs-9.3.10-11.1.noarch",
          "SUSE Linux Enterprise Server 12:postgresql93-server-9.3.10-11.1.ppc64le",
          "SUSE Linux Enterprise Server 12:postgresql93-server-9.3.10-11.1.s390x",
          "SUSE Linux Enterprise Server 12:postgresql93-server-9.3.10-11.1.x86_64",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-9.3.10-11.1.ppc64le",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-9.3.10-11.1.s390x",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-9.3.10-11.1.x86_64",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-contrib-9.3.10-11.1.ppc64le",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-contrib-9.3.10-11.1.s390x",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-contrib-9.3.10-11.1.x86_64",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-docs-9.3.10-11.1.noarch",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-server-9.3.10-11.1.ppc64le",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-server-9.3.10-11.1.s390x",
          "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-server-9.3.10-11.1.x86_64",
          "SUSE Linux Enterprise Software Development Kit 12:postgresql93-devel-9.3.10-11.1.ppc64le",
          "SUSE Linux Enterprise Software Development Kit 12:postgresql93-devel-9.3.10-11.1.s390x",
          "SUSE Linux Enterprise Software Development Kit 12:postgresql93-devel-9.3.10-11.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2015-5289",
          "url": "https://www.suse.com/security/cve/CVE-2015-5289"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 949669 for CVE-2015-5289",
          "url": "https://bugzilla.suse.com/949669"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 949670 for CVE-2015-5289",
          "url": "https://bugzilla.suse.com/949670"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Desktop 12:postgresql93-9.3.10-11.1.x86_64",
            "SUSE Linux Enterprise Server 12:postgresql93-9.3.10-11.1.ppc64le",
            "SUSE Linux Enterprise Server 12:postgresql93-9.3.10-11.1.s390x",
            "SUSE Linux Enterprise Server 12:postgresql93-9.3.10-11.1.x86_64",
            "SUSE Linux Enterprise Server 12:postgresql93-contrib-9.3.10-11.1.ppc64le",
            "SUSE Linux Enterprise Server 12:postgresql93-contrib-9.3.10-11.1.s390x",
            "SUSE Linux Enterprise Server 12:postgresql93-contrib-9.3.10-11.1.x86_64",
            "SUSE Linux Enterprise Server 12:postgresql93-docs-9.3.10-11.1.noarch",
            "SUSE Linux Enterprise Server 12:postgresql93-server-9.3.10-11.1.ppc64le",
            "SUSE Linux Enterprise Server 12:postgresql93-server-9.3.10-11.1.s390x",
            "SUSE Linux Enterprise Server 12:postgresql93-server-9.3.10-11.1.x86_64",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-9.3.10-11.1.ppc64le",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-9.3.10-11.1.s390x",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-9.3.10-11.1.x86_64",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-contrib-9.3.10-11.1.ppc64le",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-contrib-9.3.10-11.1.s390x",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-contrib-9.3.10-11.1.x86_64",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-docs-9.3.10-11.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-server-9.3.10-11.1.ppc64le",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-server-9.3.10-11.1.s390x",
            "SUSE Linux Enterprise Server for SAP Applications 12:postgresql93-server-9.3.10-11.1.x86_64",
            "SUSE Linux Enterprise Software Development Kit 12:postgresql93-devel-9.3.10-11.1.ppc64le",
            "SUSE Linux Enterprise Software Development Kit 12:postgresql93-devel-9.3.10-11.1.s390x",
            "SUSE Linux Enterprise Software Development Kit 12:postgresql93-devel-9.3.10-11.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2015-10-20T15:54:16Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2015-5289"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…