<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for postgresql94</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2017:2258-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2017-08-25T13:17:12Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2017-08-25T13:17:12Z</InitialReleaseDate>
    <CurrentReleaseDate>2017-08-25T13:17:12Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for postgresql94</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">Postgresql94 was updated to 9.4.13 to fix the following issues:

* CVE-2017-7547: Further restrict visibility of pg_user_mappings.umoptions, to protect passwords stored as user mapping options. (bsc#1051685)
* CVE-2017-7546: Disallow empty passwords in all password-based authentication methods. (bsc#1051684)
* CVE-2017-7548: lo_put() function ignores ACLs. (bsc#1053259)

The changelog for this release is here:
	https://www.postgresql.org/docs/9.4/static/release-9-4-13.html

</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">sdksp4-postgresql94-13247,sleposp3-postgresql94-13247,slessp3-postgresql94-13247,slessp4-postgresql94-13247</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2017/suse-su-20172258-1/</URL>
      <Description>Link for SUSE-SU-2017:2258-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2017-August/003158.html</URL>
      <Description>E-Mail link for SUSE-SU-2017:2258-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1051684</URL>
      <Description>SUSE Bug 1051684</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1051685</URL>
      <Description>SUSE Bug 1051685</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1053259</URL>
      <Description>SUSE Bug 1053259</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-7546/</URL>
      <Description>SUSE CVE CVE-2017-7546 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-7547/</URL>
      <Description>SUSE CVE CVE-2017-7547 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-7548/</URL>
      <Description>SUSE CVE CVE-2017-7548 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Point of Sale 11 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Point of Sale 11 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Point of Sale 11 SP3" CPE="cpe:/o:suse:sle-pos:11:sp3">SUSE Linux Enterprise Point of Sale 11 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 11 SP3-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 11 SP3-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-LTSS" CPE="cpe:/o:suse:suse_sles_ltss:11:sp3">SUSE Linux Enterprise Server 11 SP3-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 11 SP3-TERADATA">
        <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA" CPE="cpe:/o:suse:sles:11:sp3:teradata">SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 11 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 11 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4" CPE="cpe:/o:suse:suse_sles:11:sp4">SUSE Linux Enterprise Server 11 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 11 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 11 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP4" CPE="cpe:/o:suse:sles_sap:11:sp4">SUSE Linux Enterprise Server for SAP Applications 11 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Software Development Kit 11 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Software Development Kit 11 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 11 SP4" CPE="cpe:/a:suse:sle-sdk:11:sp4">SUSE Linux Enterprise Software Development Kit 11 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="postgresql94-devel-9.4.13-0.23.5.1">
      <FullProductName ProductID="postgresql94-devel-9.4.13-0.23.5.1">postgresql94-devel-9.4.13-0.23.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libecpg6-9.4.13-0.23.5.1">
      <FullProductName ProductID="libecpg6-9.4.13-0.23.5.1">libecpg6-9.4.13-0.23.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpq5-9.4.13-0.23.5.1">
      <FullProductName ProductID="libpq5-9.4.13-0.23.5.1">libpq5-9.4.13-0.23.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql94-9.4.13-0.23.5.1">
      <FullProductName ProductID="postgresql94-9.4.13-0.23.5.1">postgresql94-9.4.13-0.23.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql94-contrib-9.4.13-0.23.5.1">
      <FullProductName ProductID="postgresql94-contrib-9.4.13-0.23.5.1">postgresql94-contrib-9.4.13-0.23.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql94-docs-9.4.13-0.23.5.1">
      <FullProductName ProductID="postgresql94-docs-9.4.13-0.23.5.1">postgresql94-docs-9.4.13-0.23.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="postgresql94-server-9.4.13-0.23.5.1">
      <FullProductName ProductID="postgresql94-server-9.4.13-0.23.5.1">postgresql94-server-9.4.13-0.23.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpq5-32bit-9.4.13-0.23.5.1">
      <FullProductName ProductID="libpq5-32bit-9.4.13-0.23.5.1">libpq5-32bit-9.4.13-0.23.5.1</FullProductName>
    </Branch>
    <Relationship ProductReference="libecpg6-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Point of Sale 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Point of Sale 11 SP3:libecpg6-9.4.13-0.23.5.1">libecpg6-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Point of Sale 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpq5-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Point of Sale 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Point of Sale 11 SP3:libpq5-9.4.13-0.23.5.1">libpq5-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Point of Sale 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Point of Sale 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Point of Sale 11 SP3:postgresql94-9.4.13-0.23.5.1">postgresql94-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Point of Sale 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-contrib-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Point of Sale 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Point of Sale 11 SP3:postgresql94-contrib-9.4.13-0.23.5.1">postgresql94-contrib-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Point of Sale 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-docs-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Point of Sale 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Point of Sale 11 SP3:postgresql94-docs-9.4.13-0.23.5.1">postgresql94-docs-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Point of Sale 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-server-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Point of Sale 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Point of Sale 11 SP3:postgresql94-server-9.4.13-0.23.5.1">postgresql94-server-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Point of Sale 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libecpg6-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-LTSS:libecpg6-9.4.13-0.23.5.1">libecpg6-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpq5-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-LTSS:libpq5-9.4.13-0.23.5.1">libpq5-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpq5-32bit-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-LTSS:libpq5-32bit-9.4.13-0.23.5.1">libpq5-32bit-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-LTSS:postgresql94-9.4.13-0.23.5.1">postgresql94-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-contrib-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-LTSS:postgresql94-contrib-9.4.13-0.23.5.1">postgresql94-contrib-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-docs-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-LTSS:postgresql94-docs-9.4.13-0.23.5.1">postgresql94-docs-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-server-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-LTSS:postgresql94-server-9.4.13-0.23.5.1">postgresql94-server-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libecpg6-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:libecpg6-9.4.13-0.23.5.1">libecpg6-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpq5-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:libpq5-9.4.13-0.23.5.1">libpq5-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpq5-32bit-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:libpq5-32bit-9.4.13-0.23.5.1">libpq5-32bit-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:postgresql94-9.4.13-0.23.5.1">postgresql94-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-contrib-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:postgresql94-contrib-9.4.13-0.23.5.1">postgresql94-contrib-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-docs-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:postgresql94-docs-9.4.13-0.23.5.1">postgresql94-docs-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-server-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:postgresql94-server-9.4.13-0.23.5.1">postgresql94-server-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="libecpg6-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4:libecpg6-9.4.13-0.23.5.1">libecpg6-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpq5-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4:libpq5-9.4.13-0.23.5.1">libpq5-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpq5-32bit-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4:libpq5-32bit-9.4.13-0.23.5.1">libpq5-32bit-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4:postgresql94-9.4.13-0.23.5.1">postgresql94-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-contrib-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4:postgresql94-contrib-9.4.13-0.23.5.1">postgresql94-contrib-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-docs-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4:postgresql94-docs-9.4.13-0.23.5.1">postgresql94-docs-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-server-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4:postgresql94-server-9.4.13-0.23.5.1">postgresql94-server-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server 11 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libecpg6-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP4:libecpg6-9.4.13-0.23.5.1">libecpg6-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpq5-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP4:libpq5-9.4.13-0.23.5.1">libpq5-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpq5-32bit-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP4:libpq5-32bit-9.4.13-0.23.5.1">libpq5-32bit-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP4:postgresql94-9.4.13-0.23.5.1">postgresql94-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-contrib-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP4:postgresql94-contrib-9.4.13-0.23.5.1">postgresql94-contrib-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-docs-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP4:postgresql94-docs-9.4.13-0.23.5.1">postgresql94-docs-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-server-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP4:postgresql94-server-9.4.13-0.23.5.1">postgresql94-server-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="postgresql94-devel-9.4.13-0.23.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 11 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 11 SP4:postgresql94-devel-9.4.13-0.23.5.1">postgresql94-devel-9.4.13-0.23.5.1 as a component of SUSE Linux Enterprise Software Development Kit 11 SP4</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.</Note>
    </Notes>
    <CVE>CVE-2017-7546</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Point of Sale 11 SP3:libecpg6-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Point of Sale 11 SP3:libpq5-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Point of Sale 11 SP3:postgresql94-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Point of Sale 11 SP3:postgresql94-contrib-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Point of Sale 11 SP3:postgresql94-docs-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Point of Sale 11 SP3:postgresql94-server-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:libecpg6-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:libpq5-32bit-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:libpq5-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:postgresql94-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:postgresql94-contrib-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:postgresql94-docs-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:postgresql94-server-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:libecpg6-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:libpq5-32bit-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:libpq5-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:postgresql94-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:postgresql94-contrib-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:postgresql94-docs-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:postgresql94-server-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:libecpg6-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:libpq5-32bit-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:libpq5-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:postgresql94-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:postgresql94-contrib-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:postgresql94-docs-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:postgresql94-server-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:libecpg6-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:libpq5-32bit-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:libpq5-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:postgresql94-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:postgresql94-contrib-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:postgresql94-docs-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:postgresql94-server-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP4:postgresql94-devel-9.4.13-0.23.5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.4</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2017/suse-su-20172258-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7546.html</URL>
        <Description>CVE-2017-7546</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1051684</URL>
        <Description>SUSE Bug 1051684</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1054365</URL>
        <Description>SUSE Bug 1054365</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1140876</URL>
        <Description>SUSE Bug 1140876</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers to retrieve passwords from the user mappings defined by the foreign server owners without actually having the privileges to do so.</Note>
    </Notes>
    <CVE>CVE-2017-7547</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Point of Sale 11 SP3:libecpg6-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Point of Sale 11 SP3:libpq5-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Point of Sale 11 SP3:postgresql94-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Point of Sale 11 SP3:postgresql94-contrib-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Point of Sale 11 SP3:postgresql94-docs-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Point of Sale 11 SP3:postgresql94-server-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:libecpg6-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:libpq5-32bit-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:libpq5-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:postgresql94-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:postgresql94-contrib-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:postgresql94-docs-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:postgresql94-server-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:libecpg6-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:libpq5-32bit-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:libpq5-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:postgresql94-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:postgresql94-contrib-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:postgresql94-docs-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:postgresql94-server-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:libecpg6-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:libpq5-32bit-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:libpq5-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:postgresql94-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:postgresql94-contrib-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:postgresql94-docs-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:postgresql94-server-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:libecpg6-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:libpq5-32bit-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:libpq5-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:postgresql94-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:postgresql94-contrib-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:postgresql94-docs-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:postgresql94-server-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP4:postgresql94-devel-9.4.13-0.23.5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.9</BaseScore>
        <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:N</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2017/suse-su-20172258-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7547.html</URL>
        <Description>CVE-2017-7547</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1051685</URL>
        <Description>SUSE Bug 1051685</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1054365</URL>
        <Description>SUSE Bug 1054365</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1140876</URL>
        <Description>SUSE Bug 1140876</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on a large object to overwrite the entire contents of the object, resulting in a denial of service.</Note>
    </Notes>
    <CVE>CVE-2017-7548</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Point of Sale 11 SP3:libecpg6-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Point of Sale 11 SP3:libpq5-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Point of Sale 11 SP3:postgresql94-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Point of Sale 11 SP3:postgresql94-contrib-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Point of Sale 11 SP3:postgresql94-docs-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Point of Sale 11 SP3:postgresql94-server-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:libecpg6-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:libpq5-32bit-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:libpq5-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:postgresql94-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:postgresql94-contrib-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:postgresql94-docs-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:postgresql94-server-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:libecpg6-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:libpq5-32bit-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:libpq5-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:postgresql94-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:postgresql94-contrib-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:postgresql94-docs-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:postgresql94-server-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:libecpg6-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:libpq5-32bit-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:libpq5-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:postgresql94-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:postgresql94-contrib-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:postgresql94-docs-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:postgresql94-server-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:libecpg6-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:libpq5-32bit-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:libpq5-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:postgresql94-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:postgresql94-contrib-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:postgresql94-docs-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP4:postgresql94-server-9.4.13-0.23.5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 11 SP4:postgresql94-devel-9.4.13-0.23.5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>8.5</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:C/I:C/A:N</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2017/suse-su-20172258-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7548.html</URL>
        <Description>CVE-2017-7548</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1053259</URL>
        <Description>SUSE Bug 1053259</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1054365</URL>
        <Description>SUSE Bug 1054365</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1140876</URL>
        <Description>SUSE Bug 1140876</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
