<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for postgresql93</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2016:2425-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2016-09-30T13:09:17Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2016-09-30T13:09:17Z</InitialReleaseDate>
    <CurrentReleaseDate>2016-09-30T13:09:17Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for postgresql93</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
The postgresql server postgresql93 was updated to 9.3.14 fixes the following issues:

Update to version 9.3.14:
* Fix possible mis-evaluation of nested CASE-WHEN expressions
  (CVE-2016-5423, boo#993454)
* Fix client programs' handling of special characters in database
  and role names (CVE-2016-5424, boo#993453)
* Fix corner-case misbehaviors for IS NULL/IS NOT NULL applied
  to nested composite values
* Make the inet and cidr data types properly reject IPv6
  addresses with too many colon-separated fields
* Prevent crash in close_ps() (the point ## lseg operator) for
  NaN input coordinates
* Fix several one-byte buffer over-reads in to_number()
* Avoid unsafe intermediate state during expensive paths through
  heap_update()
* For the other bug fixes, see the release notes:
  https://www.postgresql.org/docs/9.3/static/release-9-3-14.html

Update to version 9.3.13:

This update fixes several problems which caused downtime for
users, including:
- Clearing the OpenSSL error queue before OpenSSL calls,
  preventing errors in SSL connections, particularly when using
  the Python, Ruby or PHP OpenSSL wrappers
- Fixed the &amp;quot;failed to build N-way joins&amp;quot; planner error
- Fixed incorrect handling of equivalence in multilevel nestloop
  query plans, which could emit rows which didn't match the WHERE
  clause.
- Prevented two memory leaks with using GIN indexes, including a
  potential index corruption risk.
The release also includes many other bug fixes for reported
issues, many of which affect all supported versions:
- Fix corner-case parser failures occurring when
  operator_precedence_warning is turned on
- Prevent possible misbehavior of TH, th, and Y,YYY format codes
  in to_timestamp()
- Correct dumping of VIEWs and RULEs which use ANY (array) in a
  subselect
- Disallow newlines in ALTER SYSTEM parameter values
- Avoid possible misbehavior after failing to remove a tablespace
  symlink
- Fix crash in logical decoding on alignment-picky platforms
- Avoid repeated requests for feedback from receiver while
  shutting down walsender
- Multiple fixes for pg_upgrade
- Support building with Visual Studio 2015
- This update also contains tzdata release 2016d, with updates
  for Russia, Venezuela, Kirov, and Tomsk.
http://www.postgresql.org/docs/current/static/release-9-3-13.html

Update to version 9.3.12:

- Fix two bugs in indexed ROW() comparisons
- Avoid data loss due to renaming files
- Prevent an error in rechecking rows in SELECT FOR UPDATE/SHARE
- Fix bugs in multiple json_ and jsonb_ functions
- Log lock waits for INSERT ON CONFLICT correctly
- Ignore recovery_min_apply_delay until reaching a consistent
  state
- Fix issue with pg_subtrans XID wraparound
- Fix assorted bugs in Logical Decoding
- Fix planner error with nested security barrier views
- Prevent memory leak in GIN indexes
- Fix two issues with ispell dictionaries
- Avoid a crash on old Windows versions
- Skip creating an erroneous delete script in pg_upgrade
- Correctly translate empty arrays into PL/Perl
- Make PL/Python cope with identifier names

For the full release notes, see:
  http://www.postgresql.org/docs/9.4/static/release-9-3-12.html
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00037.html</URL>
      <Description>E-Mail link for openSUSE-SU-2016:2425-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE 13.2">
      <Branch Type="Product Name" Name="openSUSE 13.2">
        <FullProductName ProductID="openSUSE 13.2">openSUSE 13.2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="libecpg6-9.3.14-2.13.1">
      <FullProductName ProductID="libecpg6-9.3.14-2.13.1">libecpg6-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libecpg6-32bit-9.3.14-2.13.1">
      <FullProductName ProductID="libecpg6-32bit-9.3.14-2.13.1">libecpg6-32bit-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libecpg6-debuginfo-9.3.14-2.13.1">
      <FullProductName ProductID="libecpg6-debuginfo-9.3.14-2.13.1">libecpg6-debuginfo-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libecpg6-debuginfo-32bit-9.3.14-2.13.1">
      <FullProductName ProductID="libecpg6-debuginfo-32bit-9.3.14-2.13.1">libecpg6-debuginfo-32bit-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpq5-9.3.14-2.13.1">
      <FullProductName ProductID="libpq5-9.3.14-2.13.1">libpq5-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpq5-32bit-9.3.14-2.13.1">
      <FullProductName ProductID="libpq5-32bit-9.3.14-2.13.1">libpq5-32bit-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpq5-debuginfo-9.3.14-2.13.1">
      <FullProductName ProductID="libpq5-debuginfo-9.3.14-2.13.1">libpq5-debuginfo-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpq5-debuginfo-32bit-9.3.14-2.13.1">
      <FullProductName ProductID="libpq5-debuginfo-32bit-9.3.14-2.13.1">libpq5-debuginfo-32bit-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-9.3.14-2.13.1">postgresql93-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-contrib-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-contrib-9.3.14-2.13.1">postgresql93-contrib-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-contrib-debuginfo-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-contrib-debuginfo-9.3.14-2.13.1">postgresql93-contrib-debuginfo-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-debuginfo-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-debuginfo-9.3.14-2.13.1">postgresql93-debuginfo-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-debugsource-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-debugsource-9.3.14-2.13.1">postgresql93-debugsource-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-devel-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-devel-9.3.14-2.13.1">postgresql93-devel-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-devel-debuginfo-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-devel-debuginfo-9.3.14-2.13.1">postgresql93-devel-debuginfo-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-docs-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-docs-9.3.14-2.13.1">postgresql93-docs-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-libs-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-libs-9.3.14-2.13.1">postgresql93-libs-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-libs-debugsource-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-libs-debugsource-9.3.14-2.13.1">postgresql93-libs-debugsource-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-plperl-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-plperl-9.3.14-2.13.1">postgresql93-plperl-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-plperl-debuginfo-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-plperl-debuginfo-9.3.14-2.13.1">postgresql93-plperl-debuginfo-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-plpython-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-plpython-9.3.14-2.13.1">postgresql93-plpython-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-plpython-debuginfo-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-plpython-debuginfo-9.3.14-2.13.1">postgresql93-plpython-debuginfo-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-pltcl-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-pltcl-9.3.14-2.13.1">postgresql93-pltcl-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-pltcl-debuginfo-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-pltcl-debuginfo-9.3.14-2.13.1">postgresql93-pltcl-debuginfo-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-server-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-server-9.3.14-2.13.1">postgresql93-server-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-server-debuginfo-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-server-debuginfo-9.3.14-2.13.1">postgresql93-server-debuginfo-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql93-test-9.3.14-2.13.1">
      <FullProductName ProductID="postgresql93-test-9.3.14-2.13.1">postgresql93-test-9.3.14-2.13.1</FullProductName>
    </Branch>
    <Relationship ProductReference="libecpg6-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libecpg6-9.3.14-2.13.1">libecpg6-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libecpg6-32bit-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libecpg6-32bit-9.3.14-2.13.1">libecpg6-32bit-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libecpg6-debuginfo-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libecpg6-debuginfo-9.3.14-2.13.1">libecpg6-debuginfo-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libecpg6-debuginfo-32bit-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libecpg6-debuginfo-32bit-9.3.14-2.13.1">libecpg6-debuginfo-32bit-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpq5-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpq5-9.3.14-2.13.1">libpq5-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpq5-32bit-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpq5-32bit-9.3.14-2.13.1">libpq5-32bit-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpq5-debuginfo-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpq5-debuginfo-9.3.14-2.13.1">libpq5-debuginfo-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpq5-debuginfo-32bit-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpq5-debuginfo-32bit-9.3.14-2.13.1">libpq5-debuginfo-32bit-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-9.3.14-2.13.1">postgresql93-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-contrib-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-contrib-9.3.14-2.13.1">postgresql93-contrib-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-contrib-debuginfo-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-contrib-debuginfo-9.3.14-2.13.1">postgresql93-contrib-debuginfo-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-debuginfo-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-debuginfo-9.3.14-2.13.1">postgresql93-debuginfo-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-debugsource-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-debugsource-9.3.14-2.13.1">postgresql93-debugsource-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-devel-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-devel-9.3.14-2.13.1">postgresql93-devel-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-devel-debuginfo-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-devel-debuginfo-9.3.14-2.13.1">postgresql93-devel-debuginfo-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-docs-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-docs-9.3.14-2.13.1">postgresql93-docs-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-libs-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-libs-9.3.14-2.13.1">postgresql93-libs-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-libs-debugsource-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-libs-debugsource-9.3.14-2.13.1">postgresql93-libs-debugsource-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-plperl-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-plperl-9.3.14-2.13.1">postgresql93-plperl-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-plperl-debuginfo-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-plperl-debuginfo-9.3.14-2.13.1">postgresql93-plperl-debuginfo-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-plpython-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-plpython-9.3.14-2.13.1">postgresql93-plpython-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-plpython-debuginfo-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-plpython-debuginfo-9.3.14-2.13.1">postgresql93-plpython-debuginfo-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-pltcl-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-pltcl-9.3.14-2.13.1">postgresql93-pltcl-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-pltcl-debuginfo-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-pltcl-debuginfo-9.3.14-2.13.1">postgresql93-pltcl-debuginfo-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-server-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-server-9.3.14-2.13.1">postgresql93-server-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-server-debuginfo-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-server-debuginfo-9.3.14-2.13.1">postgresql93-server-debuginfo-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql93-test-9.3.14-2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:postgresql93-test-9.3.14-2.13.1">postgresql93-test-9.3.14-2.13.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated users to cause a denial of service (NULL pointer dereference and server crash), obtain sensitive memory information, or possibly execute arbitrary code via (1) a CASE expression within the test value subexpression of another CASE or (2) inlining of an SQL function that implements the equality operator used for a CASE expression involving values of different types.</Note>
    </Notes>
    <CVE>CVE-2016-5423</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.2:libecpg6-32bit-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:libecpg6-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:libecpg6-debuginfo-32bit-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:libecpg6-debuginfo-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:libpq5-32bit-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:libpq5-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:libpq5-debuginfo-32bit-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:libpq5-debuginfo-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-contrib-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-contrib-debuginfo-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-debuginfo-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-debugsource-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-devel-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-devel-debuginfo-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-docs-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-libs-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-libs-debugsource-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-plperl-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-plperl-debuginfo-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-plpython-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-plpython-debuginfo-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-pltcl-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-pltcl-debuginfo-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-server-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-server-debuginfo-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-test-9.3.14-2.13.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.5</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00037.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5423.html</URL>
        <Description>CVE-2016-5423</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1041981</URL>
        <Description>SUSE Bug 1041981</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1042497</URL>
        <Description>SUSE Bug 1042497</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/993454</URL>
        <Description>SUSE Bug 993454</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATEROLE role to gain superuser privileges via a (1) " (double quote), (2) \ (backslash), (3) carriage return, or (4) newline character in a (a) database or (b) role name that is mishandled during an administrative operation.</Note>
    </Notes>
    <CVE>CVE-2016-5424</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.2:libecpg6-32bit-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:libecpg6-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:libecpg6-debuginfo-32bit-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:libecpg6-debuginfo-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:libpq5-32bit-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:libpq5-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:libpq5-debuginfo-32bit-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:libpq5-debuginfo-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-contrib-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-contrib-debuginfo-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-debuginfo-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-debugsource-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-devel-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-devel-debuginfo-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-docs-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-libs-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-libs-debugsource-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-plperl-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-plperl-debuginfo-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-plpython-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-plpython-debuginfo-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-pltcl-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-pltcl-debuginfo-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-server-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-server-debuginfo-9.3.14-2.13.1</ProductID>
        <ProductID>openSUSE 13.2:postgresql93-test-9.3.14-2.13.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.5</BaseScore>
        <Vector>AV:L/AC:M/Au:S/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00037.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5424.html</URL>
        <Description>CVE-2016-5424</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1041981</URL>
        <Description>SUSE Bug 1041981</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1042497</URL>
        <Description>SUSE Bug 1042497</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/993453</URL>
        <Description>SUSE Bug 993453</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
