package/postgresql: security bump to version 12.2
authorPeter Korsgaard <peter@korsgaard.com>
Fri, 14 Feb 2020 08:39:10 +0000 (09:39 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Sat, 15 Feb 2020 11:02:10 +0000 (12:02 +0100)
Fixes the following security issues:

- CVE-2020-1720: ALTER ... DEPENDS ON EXTENSION is missing authorization checks
  https://www.postgresql.org/about/news/2011/

Update the license hash for a change in copyright years:
-Portions Copyright (c) 1996-2019, PostgreSQL Global Development Group
+Portions Copyright (c) 1996-2020, PostgreSQL Global Development Group

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/postgresql/postgresql.hash
package/postgresql/postgresql.mk

index 5acdc957f26348653cb474eee24e83b9a41b76bc..7cb0c67d63180bc6bf7c1f6a12cd9365558cd78f 100644 (file)
@@ -1,7 +1,7 @@
-# From https://ftp.postgresql.org/pub/source/v12.1/postgresql-12.1.tar.bz2.md5
-md5 2ee1bd4ec5f49363a3f456f07e599b41  postgresql-12.1.tar.bz2
-# From https://ftp.postgresql.org/pub/source/v12.1/postgresql-12.1.tar.bz2.sha256
-sha256 a09bf3abbaf6763980d0f8acbb943b7629a8b20073de18d867aecdb7988483ed  postgresql-12.1.tar.bz2
+# From https://ftp.postgresql.org/pub/source/v12.2/postgresql-12.2.tar.bz2.md5
+md5  a88ceea8ecf2741307f663e4539b58b7  postgresql-12.2.tar.bz2
+# From https://ftp.postgresql.org/pub/source/v12.2/postgresql-12.2.tar.bz2.sha256
+sha256  ad1dcc4c4fc500786b745635a9e1eba950195ce20b8913f50345bb7d5369b5de  postgresql-12.2.tar.bz2
 
 # License file, Locally calculated
-sha256 c4c86d683970b22b9fab53320ee1b3a30ef4e8223122b4fb6be53ea62ecee8b3  COPYRIGHT
+sha256 739e5d454d81d31a482469338b7c856f1f5c6b4cdda1551cea6f0f6d18eef62c  COPYRIGHT
index 7d8bef643bbc232974ac57a3c8e95f56b7fe32e6..378197d33b878c926dcc9c6b3412e4897980bf36 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-POSTGRESQL_VERSION = 12.1
+POSTGRESQL_VERSION = 12.2
 POSTGRESQL_SOURCE = postgresql-$(POSTGRESQL_VERSION).tar.bz2
 POSTGRESQL_SITE = https://ftp.postgresql.org/pub/source/v$(POSTGRESQL_VERSION)
 POSTGRESQL_LICENSE = PostgreSQL