From 554b93a424fd6f7cafebbbce365319abbc4209156942dd031a7f695217e6262a Mon Sep 17 00:00:00 2001 From: Reinhard Max Date: Thu, 10 Aug 2023 13:36:21 +0000 Subject: [PATCH] - Update to 13.12: * bsc#1214059, CVE-2023-39417: Disallow substituting a schema or owner name into an extension script if the name contains a quote, backslash, or dollar sign. * https://www.postgresql.org/docs/13/release-13-12.html OBS-URL: https://build.opensuse.org/package/show/server:database:postgresql/postgresql13?expand=0&rev=72 --- postgresql-13.11.tar.bz2 | 3 --- postgresql-13.11.tar.bz2.sha256 | 1 - postgresql-13.12.tar.bz2 | 3 +++ postgresql-13.12.tar.bz2.sha256 | 1 + postgresql13.changes | 9 +++++++++ postgresql13.spec | 2 +- 6 files changed, 14 insertions(+), 5 deletions(-) delete mode 100644 postgresql-13.11.tar.bz2 delete mode 100644 postgresql-13.11.tar.bz2.sha256 create mode 100644 postgresql-13.12.tar.bz2 create mode 100644 postgresql-13.12.tar.bz2.sha256 diff --git a/postgresql-13.11.tar.bz2 b/postgresql-13.11.tar.bz2 deleted file mode 100644 index bf28abc..0000000 --- a/postgresql-13.11.tar.bz2 +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:4992ff647203566b670d4e54dc5317499a26856c93576d0ea951bdf6bee50bfb -size 21519655 diff --git a/postgresql-13.11.tar.bz2.sha256 b/postgresql-13.11.tar.bz2.sha256 deleted file mode 100644 index bdd019b..0000000 --- a/postgresql-13.11.tar.bz2.sha256 +++ /dev/null @@ -1 +0,0 @@ -4992ff647203566b670d4e54dc5317499a26856c93576d0ea951bdf6bee50bfb postgresql-13.11.tar.bz2 diff --git a/postgresql-13.12.tar.bz2 b/postgresql-13.12.tar.bz2 new file mode 100644 index 0000000..3e5ea4b --- /dev/null +++ b/postgresql-13.12.tar.bz2 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:0da1edcee3514b7bc7ba6dbaf0c00499e8ac1590668e8789c50253a6249f218b +size 21542293 diff --git a/postgresql-13.12.tar.bz2.sha256 b/postgresql-13.12.tar.bz2.sha256 new file mode 100644 index 0000000..67587e6 --- /dev/null +++ b/postgresql-13.12.tar.bz2.sha256 @@ -0,0 +1 @@ +0da1edcee3514b7bc7ba6dbaf0c00499e8ac1590668e8789c50253a6249f218b postgresql-13.12.tar.bz2 diff --git a/postgresql13.changes b/postgresql13.changes index 5b61b2b..06afefc 100644 --- a/postgresql13.changes +++ b/postgresql13.changes @@ -1,3 +1,12 @@ +------------------------------------------------------------------- +Wed Aug 9 09:55:59 UTC 2023 - Reinhard Max + +- Update to 13.12: + * bsc#1214059, CVE-2023-39417: Disallow substituting a schema or + owner name into an extension script if the name contains a + quote, backslash, or dollar sign. + * https://www.postgresql.org/docs/13/release-13-12.html + ------------------------------------------------------------------- Fri May 26 11:48:38 UTC 2023 - Reinhard Max diff --git a/postgresql13.spec b/postgresql13.spec index e1057db..cf480ec 100644 --- a/postgresql13.spec +++ b/postgresql13.spec @@ -16,7 +16,7 @@ # -%define pgversion 13.11 +%define pgversion 13.12 %define pgmajor 13 %define buildlibs 0 %define tarversion %{pgversion}