File _patchinfo of Package patchinfo.6324
<patchinfo incident="6324">
<issue id="1067844" tracker="bnc">VUL-0: CVE-2017-15098: postgresql94,postgresql96: Memory disclosure in JSON functions</issue>
<issue id="1062538" tracker="bnc">VUL-0: CVE-2017-12172: postgresql: Start scripts permit database administrator to modify root-owned files</issue>
<issue id="2017-12172" tracker="cve" />
<issue id="2017-15098" tracker="cve" />
<category>security</category>
<rating>moderate</rating>
<packager>rmax</packager>
<description>This update for postgresql94 fixes the following issues:
Security issues fixed:
- CVE-2017-15098: Fix crash due to rowtype mismatch in json{b}_populate_recordset() (bsc#1067844).
- CVE-2017-12172: Start scripts permit database administrator to modify root-owned files. This issue did not affect SUSE (bsc#1062538).
Bug fixes:
- Update to version 9.4.15
* https://www.postgresql.org/docs/9.4/static/release-9-4-15.html
* https://www.postgresql.org/docs/9.4/static/release-9-4-14.html
</description>
<summary>Security update for postgresql94</summary>
</patchinfo>