From b5e33915b45669f9e6538a52b44e21a7dbb613454eed0a0cc028265dd22c9546 Mon Sep 17 00:00:00 2001 From: Reinhard Max Date: Thu, 10 Aug 2023 13:28:03 +0000 Subject: [PATCH] - Update to 14.9: * bsc#1214059, CVE-2023-39417: Disallow substituting a schema or owner name into an extension script if the name contains a quote, backslash, or dollar sign. * https://www.postgresql.org/docs/14/release-14-9.html OBS-URL: https://build.opensuse.org/package/show/server:database:postgresql/postgresql14?expand=0&rev=54 --- postgresql-14.8.tar.bz2 | 3 --- postgresql-14.8.tar.bz2.sha256 | 1 - postgresql-14.9.tar.bz2 | 3 +++ postgresql-14.9.tar.bz2.sha256 | 1 + postgresql14.changes | 9 +++++++++ postgresql14.spec | 6 +++--- 6 files changed, 16 insertions(+), 7 deletions(-) delete mode 100644 postgresql-14.8.tar.bz2 delete mode 100644 postgresql-14.8.tar.bz2.sha256 create mode 100644 postgresql-14.9.tar.bz2 create mode 100644 postgresql-14.9.tar.bz2.sha256 diff --git a/postgresql-14.8.tar.bz2 b/postgresql-14.8.tar.bz2 deleted file mode 100644 index 34ac266..0000000 --- a/postgresql-14.8.tar.bz2 +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:39d38f0030737ed03835debeefee3b37d335462ce4995e2497bc38d621ebe45a -size 22204905 diff --git a/postgresql-14.8.tar.bz2.sha256 b/postgresql-14.8.tar.bz2.sha256 deleted file mode 100644 index a7bbad3..0000000 --- a/postgresql-14.8.tar.bz2.sha256 +++ /dev/null @@ -1 +0,0 @@ -39d38f0030737ed03835debeefee3b37d335462ce4995e2497bc38d621ebe45a postgresql-14.8.tar.bz2 diff --git a/postgresql-14.9.tar.bz2 b/postgresql-14.9.tar.bz2 new file mode 100644 index 0000000..566bb44 --- /dev/null +++ b/postgresql-14.9.tar.bz2 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:b1fe3ba9b1a7f3a9637dd1656dfdad2889016073fd4d35f13b50143cbbb6a8ef +size 22207374 diff --git a/postgresql-14.9.tar.bz2.sha256 b/postgresql-14.9.tar.bz2.sha256 new file mode 100644 index 0000000..9f4b0cb --- /dev/null +++ b/postgresql-14.9.tar.bz2.sha256 @@ -0,0 +1 @@ +b1fe3ba9b1a7f3a9637dd1656dfdad2889016073fd4d35f13b50143cbbb6a8ef postgresql-14.9.tar.bz2 diff --git a/postgresql14.changes b/postgresql14.changes index 6db42c4..cf6b325 100644 --- a/postgresql14.changes +++ b/postgresql14.changes @@ -1,3 +1,12 @@ +------------------------------------------------------------------- +Wed Aug 9 09:42:33 UTC 2023 - Reinhard Max + +- Update to 14.9: + * bsc#1214059, CVE-2023-39417: Disallow substituting a schema or + owner name into an extension script if the name contains a + quote, backslash, or dollar sign. + * https://www.postgresql.org/docs/14/release-14-9.html + ------------------------------------------------------------------- Fri May 26 11:48:38 UTC 2023 - Reinhard Max diff --git a/postgresql14.spec b/postgresql14.spec index b5d52f2..0233711 100644 --- a/postgresql14.spec +++ b/postgresql14.spec @@ -16,8 +16,8 @@ # -%define pgversion 14.8 -%define pgmajor 14 +%define pgversion 14.9 +%define pgmajor 15 %define buildlibs 0 %define tarversion %{pgversion} %define latest_supported_llvm_ver 15 @@ -70,7 +70,7 @@ Name: %pgname %if %mini %bcond_with selinux %if %pgmajor >= 16 -%bcond_without icu +%bcond_without icu %else %bcond_with icu %endif