SUSE SLES15 / openSUSE 15 Security Update : postgresql14 (SUSE-SU-2024:1768-1)

low Nessus Plugin ID 197891


The remote SUSE host is missing a security update.


The remote SUSE Linux SLES15 / SLES_SAP15 / openSUSE 15 host has packages installed that are affected by a vulnerability as referenced in the SUSE-SU-2024:1768-1 advisory.

PostgreSQL upgrade to version 14.12 (bsc#1224051):

- CVE-2024-4317: Fixed visibility restriction of pg_stats_ext and pg_stats_ext_exprs entries to the table owner (bsc#1224038).

Bug fixes:

- Fix incompatibility with LLVM 18.
- Prepare for PostgreSQL 17.
- Make sure all compilation and doc generation happens in %build.
- Require LLVM <= 17 for now, because LLVM 18 doesn't seem to work.
- Remove constraints file because improved memory usage for s390x
- Use %patch -P N instead of deprecated %patchN.

Release notes:


Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.


Update the affected packages.

See Also

Plugin Details

Severity: Low

ID: 197891

File Name: suse_SU-2024-1768-1.nasl

Version: 1.1

Type: local

Agent: unix

Published: 5/24/2024

Updated: 5/24/2024

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information


Risk Factor: Low

Score: 2.2


Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2024-4317


Risk Factor: Low

Base Score: 3.1

Temporal Score: 2.7

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:postgresql14-pltcl, p-cpe:/a:novell:suse_linux:postgresql14-llvmjit-devel, p-cpe:/a:novell:suse_linux:postgresql14-test, p-cpe:/a:novell:suse_linux:postgresql14-server, p-cpe:/a:novell:suse_linux:postgresql14-plperl, p-cpe:/a:novell:suse_linux:postgresql14-docs, p-cpe:/a:novell:suse_linux:postgresql14, cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:postgresql14-contrib, p-cpe:/a:novell:suse_linux:postgresql14-server-devel, p-cpe:/a:novell:suse_linux:postgresql14-devel, p-cpe:/a:novell:suse_linux:postgresql14-plpython, p-cpe:/a:novell:suse_linux:postgresql14-llvmjit

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 5/23/2024

Vulnerability Publication Date: 5/9/2024

Reference Information

CVE: CVE-2024-4317

IAVB: 2024-B-0062

SuSE: SUSE-SU-2024:1768-1