From 4a60a0530a12b0034ae70ca13c3f9efea99489b32b7aa75bce9b15cf8f75bae1 Mon Sep 17 00:00:00 2001 From: Reinhard Max Date: Thu, 10 Aug 2023 13:25:30 +0000 Subject: [PATCH] - Update to 15.4: * bsc#1214059, CVE-2023-39417: Disallow substituting a schema or owner name into an extension script if the name contains a quote, backslash, or dollar sign. * bsc#1214061, CVE-2023-39418: Fix MERGE to enforce row security policies properly. * https://www.postgresql.org/docs/15/release-15-4.html OBS-URL: https://build.opensuse.org/package/show/server:database:postgresql/postgresql15?expand=0&rev=33 --- postgresql-15.3.tar.bz2 | 3 --- postgresql-15.3.tar.bz2.sha256 | 1 - postgresql-15.4.tar.bz2 | 3 +++ postgresql-15.4.tar.bz2.sha256 | 1 + postgresql15.changes | 11 +++++++++++ postgresql15.spec | 4 ++-- 6 files changed, 17 insertions(+), 6 deletions(-) delete mode 100644 postgresql-15.3.tar.bz2 delete mode 100644 postgresql-15.3.tar.bz2.sha256 create mode 100644 postgresql-15.4.tar.bz2 create mode 100644 postgresql-15.4.tar.bz2.sha256 diff --git a/postgresql-15.3.tar.bz2 b/postgresql-15.3.tar.bz2 deleted file mode 100644 index f7bf8b2..0000000 --- a/postgresql-15.3.tar.bz2 +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:ffc7d4891f00ffbf5c3f4eab7fbbced8460b8c0ee63c5a5167133b9e6599d932 -size 22819107 diff --git a/postgresql-15.3.tar.bz2.sha256 b/postgresql-15.3.tar.bz2.sha256 deleted file mode 100644 index c764168..0000000 --- a/postgresql-15.3.tar.bz2.sha256 +++ /dev/null @@ -1 +0,0 @@ -ffc7d4891f00ffbf5c3f4eab7fbbced8460b8c0ee63c5a5167133b9e6599d932 postgresql-15.3.tar.bz2 diff --git a/postgresql-15.4.tar.bz2 b/postgresql-15.4.tar.bz2 new file mode 100644 index 0000000..8409bfb --- /dev/null +++ b/postgresql-15.4.tar.bz2 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:baec5a4bdc4437336653b6cb5d9ed89be5bd5c0c58b94e0becee0a999e63c8f9 +size 22850355 diff --git a/postgresql-15.4.tar.bz2.sha256 b/postgresql-15.4.tar.bz2.sha256 new file mode 100644 index 0000000..0038621 --- /dev/null +++ b/postgresql-15.4.tar.bz2.sha256 @@ -0,0 +1 @@ +baec5a4bdc4437336653b6cb5d9ed89be5bd5c0c58b94e0becee0a999e63c8f9 postgresql-15.4.tar.bz2 diff --git a/postgresql15.changes b/postgresql15.changes index cf318a8..36ed14c 100644 --- a/postgresql15.changes +++ b/postgresql15.changes @@ -1,3 +1,14 @@ +------------------------------------------------------------------- +Wed Aug 9 09:14:59 UTC 2023 - Reinhard Max + +- Update to 15.4: + * bsc#1214059, CVE-2023-39417: Disallow substituting a schema or + owner name into an extension script if the name contains a + quote, backslash, or dollar sign. + * bsc#1214061, CVE-2023-39418: Fix MERGE to enforce row security + policies properly. + * https://www.postgresql.org/docs/15/release-15-4.html + ------------------------------------------------------------------- Fri May 26 11:48:38 UTC 2023 - Reinhard Max diff --git a/postgresql15.spec b/postgresql15.spec index 34354bc..e760223 100644 --- a/postgresql15.spec +++ b/postgresql15.spec @@ -16,9 +16,9 @@ # -%define pgversion 15.3 +%define pgversion 15.4 %define pgmajor 15 -%define buildlibs 0 +%define buildlibs 1 %define tarversion %{pgversion} %define latest_supported_llvm_ver 15