Description:
The libpq package provides the PostgreSQL client library, which allows client programs to connect to PostgreSQL servers.
The following packages have been upgraded to a later upstream version: libpq (12.5). (BZ#1898228, BZ#1901558)
Security Fix(es):
* postgresql: Reconnection can downgrade connection security settings (CVE-2020-25694)
* postgresql: psql's \gset allows overwriting specially treated variables (CVE-2020-25696)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages:
-
libpq-12.5-1.el8_3.i686.rpm
-
libpq-12.5-1.el8_3.x86_64.rpm
-
libpq-devel-12.5-1.el8_3.i686.rpm
-
libpq-devel-12.5-1.el8_3.x86_64.rpm