{"affected":[{"ecosystem_specific":{"binaries":[{"postgresql93":"9.3.10-11.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12","name":"postgresql93","purl":"pkg:rpm/suse/postgresql93&distro=SUSE%20Linux%20Enterprise%20Desktop%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.3.10-11.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"postgresql93":"9.3.10-11.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12","name":"postgresql93-libs","purl":"pkg:rpm/suse/postgresql93-libs&distro=SUSE%20Linux%20Enterprise%20Desktop%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.3.10-11.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"postgresql93-devel":"9.3.10-11.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 12","name":"postgresql93-libs","purl":"pkg:rpm/suse/postgresql93-libs&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.3.10-11.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"postgresql93":"9.3.10-11.1","postgresql93-contrib":"9.3.10-11.1","postgresql93-docs":"9.3.10-11.1","postgresql93-server":"9.3.10-11.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12","name":"postgresql93","purl":"pkg:rpm/suse/postgresql93&distro=SUSE%20Linux%20Enterprise%20Server%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.3.10-11.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"postgresql93":"9.3.10-11.1","postgresql93-contrib":"9.3.10-11.1","postgresql93-docs":"9.3.10-11.1","postgresql93-server":"9.3.10-11.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12","name":"postgresql93-libs","purl":"pkg:rpm/suse/postgresql93-libs&distro=SUSE%20Linux%20Enterprise%20Server%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.3.10-11.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"postgresql93":"9.3.10-11.1","postgresql93-contrib":"9.3.10-11.1","postgresql93-docs":"9.3.10-11.1","postgresql93-server":"9.3.10-11.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12","name":"postgresql93","purl":"pkg:rpm/suse/postgresql93&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.3.10-11.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"postgresql93":"9.3.10-11.1","postgresql93-contrib":"9.3.10-11.1","postgresql93-docs":"9.3.10-11.1","postgresql93-server":"9.3.10-11.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12","name":"postgresql93-libs","purl":"pkg:rpm/suse/postgresql93-libs&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.3.10-11.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\nThe PostreSQL database postgresql93 was updated to the bugfix release 9.3.10:\n\nSecurity issues fixed:\n- CVE-2015-5289, bsc#949670: json or jsonb input values\n  constructed from arbitrary user input can crash the PostgreSQL\n  server and cause a denial of service.\n- CVE-2015-5288, bsc#949669: The crypt() function included with\n  the optional pgCrypto extension could be exploited to read a\n  few additional bytes of memory. No working exploit for this\n  issue has been developed.\n\nFor the full release notes, see:\n  http://www.postgresql.org/docs/current/static/release-9-3-10.html\n\nOther bugs fixed:\n* Move systemd related stuff and user creation to postgresql-init.\n* Remove some obsolete %suse_version conditionals.\n* Relax dependency on libpq to major version.\n* Fix possible failure to recover from an inconsistent database state. See full release notes for details.\n* Fix rare failure to invalidate relation cache init file.\n* Avoid deadlock between incoming sessions and CREATE/DROP DATABASE.\n* Improve planner's cost estimates for semi-joins and anti-joins with inner indexscans\n* For the full release notes for 9.3.9 see: http://www.postgresql.org/docs/9.3/static/release-9-3-9.html\n  ","id":"SUSE-SU-2015:1821-1","modified":"2015-10-20T15:54:16Z","published":"2015-10-20T15:54:16Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20151821-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/949669"},{"type":"REPORT","url":"https://bugzilla.suse.com/949670"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-5288"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-5289"}],"related":["CVE-2015-5288","CVE-2015-5289"],"summary":"Security update for postgresql93","upstream":["CVE-2015-5288","CVE-2015-5289"]}