File _patchinfo of Package patchinfo.14323
<patchinfo incident="14323">
<issue tracker="bnc" id="1167541">python-psycopg2 (python bindings for postgresql) need updating after postgresql update</issue>
<issue tracker="bnc" id="1151591">postgrsql contains still SuSEfirewall2 configuration file and directory</issue>
<issue tracker="bnc" id="1153168">server:database:postgresql/postgresql: Environment broken</issue>
<issue tracker="bnc" id="1138034">VUL-0: CVE-2019-10164: postgresql10: Stack-based buffer overflow via setting a password</issue>
<issue tracker="bnc" id="1163985">VUL-1: CVE-2020-1720: postgresql94,postgresql96,postgresql,postgresql10: postgresql: ALTER ... DEPENDS ON EXTENSION is missing authorization checks</issue>
<issue tracker="cve" id="2019-10164"/>
<issue tracker="jsc" id="ECO-923"/>
<issue tracker="jsc" id="SLE-11077"/>
<issue tracker="jsc" id="SLE-11078"/>
<issue tracker="jsc" id="PM-1472"/>
<issue tracker="cve" id="2020-1720"/>
<packager>rmax</packager>
<rating>moderate</rating>
<category>recommended</category>
<summary>Recommended update for postgresql, postgresql10, postgresql12</summary>
<description>This update for postgresql, postgresql10, postgresql12 fixes the following issues:
Changes in the postgresql wrapper package:
- Sync ownership of /run/postgresql in the file list with tmpfiles.
- Use the correct content for .bash_profile (bsc#1153168).
- Stop shipping SUSEfirewall2 config files (bsc#1151591).
- Use /run/postgresql instead of /var/run/postgresql in %ghost and
postgresql-tmpfiles.conf to avoid rpmlint warnings and errors.
- add /var/run/postgresql to the filelist. as %ghost for systemd
systems and directly for non systemd systems
Changes in postgresql10:
- packaging changed to no longer build the libraries,
these now come from postgresql12.
Changes in postgresql12:
Initial package for the postgresql 12 branch
https://www.postgresql.org/about/news/1976/
- Update to 12.2 (CVE-2020-1720)
https://www.postgresql.org/about/news/2011/
https://www.postgresql.org/docs/12/release-12-2.html
- Avoid the dependency from the devel package to the main package.
devel packages are exclusive, thus ecpg does not require
update-alternatives.
- Remove unused build dependencies from the client libs package:
LVM, icu, selinux, systemd.
- Update to 12.1
https://www.postgresql.org/docs/12/release-12-1.html
https://www.postgresql.org/about/news/1994/
- add requires to the server-devel package for the libs that are
returned by pg_config --libs
python-psycopg2 was updated to 2.8.4 to allow working with postgresql12.
</description>
</patchinfo>