<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="59650c03a8bc5ae310cd7898bd106ad2"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sdk-postgresql-2276"
    timestamp="1163582926"
    engine="1.0">
  <yum:name>sdk-postgresql</yum:name>
  <summary lang="en">Security update for PostgreSQL</summary>
  <summary lang="de">Security update for PostgreSQL</summary>
  <description lang="en">The SQL Server PostgreSQL has been updated to fix the
following security problems:

CVE-2006-5540: backend/parser/analyze.c in PostgreSQL 8.1.x
allowed remote authenticated users to cause a denial of
service (daemon crash) via certain aggregate functions in
an UPDATE statement, which are not properly handled during
a &quot;MIN/MAX index optimization.&quot;

CVE-2006-5541: backend/parser/parse_coerce.c in PostgreSQL
7.4.1 through 7.4.14, 8.0.x before 8.0.9, and 8.1.x before
8.1.5 allows remote authenticated users to cause a denial
of service (daemon crash) via a coercion of an unknown
element to ANYARRAY.

CVE-2006-5542: backend/tcop/postgres.c in PostgreSQL 8.1.x
before 8.1.5 allows remote authenticated users to cause a
denial of service (daemon crash) related to duration
logging of V3-protocol Execute messages for (1) COMMIT and
(2) ROLLBACK SQL statements.
</description>
  <description lang="de">The SQL Server PostgreSQL has been updated to fix the
following security problems:

CVE-2006-5540: backend/parser/analyze.c in PostgreSQL 8.1.x
allowed remote authenticated users to cause a denial of
service (daemon crash) via certain aggregate functions in
an UPDATE statement, which are not properly handled during
a &quot;MIN/MAX index optimization.&quot;

CVE-2006-5541: backend/parser/parse_coerce.c in PostgreSQL
7.4.1 through 7.4.14, 8.0.x before 8.0.9, and 8.1.x before
8.1.5 allows remote authenticated users to cause a denial
of service (daemon crash) via a coercion of an unknown
element to ANYARRAY.

CVE-2006-5542: backend/tcop/postgres.c in PostgreSQL 8.1.x
before 8.1.5 allows remote authenticated users to cause a
denial of service (daemon crash) related to duration
logging of V3-protocol Execute messages for (1) COMMIT and
(2) ROLLBACK SQL statements.
</description>
  <yum:version ver="2276" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="postgresql" epoch="0" ver="8.1.4" rel="1.6" flags="EQ"/>
    <rpm:entry kind="atom" name="postgresql-devel" epoch="0" ver="8.1.4" rel="1.6" flags="EQ"/>
    <rpm:entry kind="atom" name="postgresql-server" epoch="0" ver="8.1.4" rel="1.6" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>postgresql</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="8.1.4" rel="1.6"/>
      <checksum type="sha" pkgid="YES">7c7477ff1d4e54d50522f716f3398c002445bb97</checksum>
      <time file="1163634363" build="1163582926"/>
      <size package="1078924" installed="3729355" archive="3759376"/>
      <location xml:base="media://#1" href="suse/x86_64/postgresql-8.1.9-1.2.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="postgresql" epoch="0" ver="8.1.4" rel="1.6" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="postgresql"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>postgresql-devel</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="8.1.4" rel="1.6"/>
      <checksum type="sha" pkgid="YES">cdfd270d39e0d0b97368f9c2595f03ab59af9024</checksum>
      <time file="1163634365" build="1163582926"/>
      <size package="728638" installed="2996069" archive="3065340"/>
      <location xml:base="media://#1" href="suse/x86_64/postgresql-devel-8.1.9-1.2.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="postgresql-devel" epoch="0" ver="8.1.4" rel="1.6" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="postgresql-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>postgresql-server</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="8.1.4" rel="1.6"/>
      <checksum type="sha" pkgid="YES">59bbf24498f0279f4c1c7cd3a16f3bf7ccc1c4bc</checksum>
      <time file="1163634365" build="1163582926"/>
      <size package="3831872" installed="10913476" archive="11029352"/>
      <location xml:base="media://#1" href="suse/x86_64/postgresql-server-8.1.9-1.2.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="postgresql-server" epoch="0" ver="8.1.4" rel="1.6" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="postgresql-server"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
