-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 15:24:37 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: s390x Version: 15.8-0+deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: s390x Build Daemon (zandonai) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.8-0+deb12u1) bookworm-security; urgency=medium . * New upstream version. . + Prevent unauthorized code execution during pg_dump (Masahiko Sawada) . An attacker able to create and drop non-temporary objects could inject SQL code that would be executed by a concurrent pg_dump session with the privileges of the role running pg_dump (which is often a superuser). The attack involves replacing a sequence or similar object with a view or foreign table that will execute malicious code. To prevent this, introduce a new server parameter restrict_nonsystem_relation_kind that can disable expansion of non-builtin views as well as access to foreign tables, and teach pg_dump to set it when available. Note that the attack is prevented only if both pg_dump and the server it is dumping from are new enough to have this fix. . The PostgreSQL Project thanks Noah Misch for reporting this problem. (CVE-2024-7348) . * Refresh debian/patches/focal-arm64-outline-atomics. Checksums-Sha1: 373fcacbab6a1aab013be269317730d91516e8ae 37744 libecpg-compat3-dbgsym_15.8-0+deb12u1_s390x.deb 6ce68293f096d754aa9c28a87f7f5f26dff390c4 21840 libecpg-compat3_15.8-0+deb12u1_s390x.deb 5e8780deae9ca0360a58b907824c6652d29f4692 214564 libecpg-dev-dbgsym_15.8-0+deb12u1_s390x.deb 454b1d24f8344f74ca316948e6ad94b9975b78cc 279212 libecpg-dev_15.8-0+deb12u1_s390x.deb 2b8b7d50c069fc9ac52652d06eefa22c3a5d43a2 112308 libecpg6-dbgsym_15.8-0+deb12u1_s390x.deb 74034d08dd3d29faa78f557fde8ae48ca25d5a5f 58056 libecpg6_15.8-0+deb12u1_s390x.deb aa214817f2e13bce16e4271b171afb3f27a3bbfd 88352 libpgtypes3-dbgsym_15.8-0+deb12u1_s390x.deb 662b287f9311706cb432a8cac47e22431f7732b3 43108 libpgtypes3_15.8-0+deb12u1_s390x.deb cd84193098a1e445156f7bba6772387cd616b7dd 136984 libpq-dev_15.8-0+deb12u1_s390x.deb f38e5f003edf449a04381586f0e223b9a0953999 272648 libpq5-dbgsym_15.8-0+deb12u1_s390x.deb de71e54ca1a34f1329be5754a8511d10988d2c8e 177304 libpq5_15.8-0+deb12u1_s390x.deb 9aa278b042a4ca59db1fc203f25edb0a520fbe3c 15356408 postgresql-15-dbgsym_15.8-0+deb12u1_s390x.deb fac0cd48e1c3a88042d5c87eb98ea934708fa680 15883 postgresql-15_15.8-0+deb12u1_s390x-buildd.buildinfo 61f0463c0a26d2207e37100b54f942fc5dc21e72 5629256 postgresql-15_15.8-0+deb12u1_s390x.deb 0231003da92c9f3c7b014c141220f98d1cd0c3fe 2237844 postgresql-client-15-dbgsym_15.8-0+deb12u1_s390x.deb bf5986e36311c050cde078a4e78df85e4c4dbd29 1642248 postgresql-client-15_15.8-0+deb12u1_s390x.deb 355d7a37fa7c1d1597aa6fad2a3bf88e98893701 180456 postgresql-plperl-15-dbgsym_15.8-0+deb12u1_s390x.deb da5db088cf9ffde3a57dd30856b6b3982502258f 64416 postgresql-plperl-15_15.8-0+deb12u1_s390x.deb 64fff47eeef60ade358dcb408784fd194809512d 170108 postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_s390x.deb bc6e56c7392b5378b44ffd2e97238dbb28e7d965 87440 postgresql-plpython3-15_15.8-0+deb12u1_s390x.deb 73adf8d895455708ecc7bc2a44df76c470839b8f 77656 postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_s390x.deb 37f6b225b6131e522f3858607359aeb06c43bc76 40232 postgresql-pltcl-15_15.8-0+deb12u1_s390x.deb 01e4c3a7690631be54c101a2635f9cc0d9736c3a 1133988 postgresql-server-dev-15_15.8-0+deb12u1_s390x.deb Checksums-Sha256: dd20fd9fecbbad4787588ff1b87492d222e04d389a1841788adca60712ec6fc3 37744 libecpg-compat3-dbgsym_15.8-0+deb12u1_s390x.deb aac9a18ae30d924bac65c1d11c0a4cc6436f64027111d7f0c497c25c4d7feb83 21840 libecpg-compat3_15.8-0+deb12u1_s390x.deb 5f91eb2ea6deec8d7d6bf01dadbb29c35af9a70e28ca584191819c972d38d05f 214564 libecpg-dev-dbgsym_15.8-0+deb12u1_s390x.deb 0e885efcf5b12195522eb953c10a387d8b45f88287a131aaec99f01ab13e0993 279212 libecpg-dev_15.8-0+deb12u1_s390x.deb 5a1eca2e95a4fcde518e1ffab4b1b7626bc42fa0f169f50642fff2d0cfd16be2 112308 libecpg6-dbgsym_15.8-0+deb12u1_s390x.deb 6f2b04ff787be94af6d06d3e7c5a948652d636e2e0c5414a8ae4dd385d8e88dc 58056 libecpg6_15.8-0+deb12u1_s390x.deb 37f9052ad1c0adc94d023959012f298fa898f0ebd3c7b24d7c29202b34066336 88352 libpgtypes3-dbgsym_15.8-0+deb12u1_s390x.deb 57dd490afaa7cf94b0fe6ebf163490fa2483fe0c285b4f2faaa1c841966305a4 43108 libpgtypes3_15.8-0+deb12u1_s390x.deb 75ccaddf8a15e8e9f012a743a97b51a1bc1310f67d3ec680cf486203cc2cff64 136984 libpq-dev_15.8-0+deb12u1_s390x.deb 1139cbc13fd5335d514f85840ab5b85731a40f6c3385d9a332702b41aee9dc79 272648 libpq5-dbgsym_15.8-0+deb12u1_s390x.deb 98124bcd9af6df8290af00c159c3ca10e0884b7591a6635e2c75e954978daa24 177304 libpq5_15.8-0+deb12u1_s390x.deb e3b9e87d4ba1d03a811a396e0f9206afba79e4deae5f6804d69dc71bb5c7b6bd 15356408 postgresql-15-dbgsym_15.8-0+deb12u1_s390x.deb f179c849f17806ac3d5fccb686c13bf62571fcbfaeba03caec92b12bd01d95f1 15883 postgresql-15_15.8-0+deb12u1_s390x-buildd.buildinfo 1988723bc69f6b7f2ab38509127aabb87cd4aa66167db5aee678a2a7eaaa09dc 5629256 postgresql-15_15.8-0+deb12u1_s390x.deb c217644a625d04285add7a2744d23e118bc2ccb29d13c530261a1cf6bc38771f 2237844 postgresql-client-15-dbgsym_15.8-0+deb12u1_s390x.deb c403060c52ea12635018c86f5843379d2187a677f8787d8c2eaf7b86691d3e96 1642248 postgresql-client-15_15.8-0+deb12u1_s390x.deb 10b2f0392ae45bdeec355f23435eb4c587df2eb9c6decf06b75c2cf68a9bfc2c 180456 postgresql-plperl-15-dbgsym_15.8-0+deb12u1_s390x.deb 7809add8557394c78f871e22e7eb26acf96dc9445e4a9ecb9614b2a8d8b3cecf 64416 postgresql-plperl-15_15.8-0+deb12u1_s390x.deb 8f0614f80e6c67fb62d67565454b69a35fc070819d4aa389c784a335e1c9df0e 170108 postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_s390x.deb 5ddbd5ddfc8b6b9be9f53868b6cdd2011a334cf3b11a20c83f3dbb2d9bd5a676 87440 postgresql-plpython3-15_15.8-0+deb12u1_s390x.deb e66aa34b9f1ce9e7e191401d2584875fa107288d9728b8809c095f17c44431dc 77656 postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_s390x.deb 33c46bbbb61b08db2b0d7d2a60171da3c21ecf71dae15c03a3495176c886439f 40232 postgresql-pltcl-15_15.8-0+deb12u1_s390x.deb 280b448a4da461259d0d466099ba4c97684fe25c7890e92ddcc00d743df57aac 1133988 postgresql-server-dev-15_15.8-0+deb12u1_s390x.deb Files: bb2bb5e23be990d278de1ef30229301a 37744 debug optional libecpg-compat3-dbgsym_15.8-0+deb12u1_s390x.deb 41d6c06382303e79cf593d1c1c7f99c3 21840 libs optional libecpg-compat3_15.8-0+deb12u1_s390x.deb 1697c54d8cea4f74247474e3313414a4 214564 debug optional libecpg-dev-dbgsym_15.8-0+deb12u1_s390x.deb 7b030237fdd5dd5e8af4a7f8cd8529a8 279212 libdevel optional libecpg-dev_15.8-0+deb12u1_s390x.deb d9548d98b3b4aa1c17b76b8bd8d071f2 112308 debug optional libecpg6-dbgsym_15.8-0+deb12u1_s390x.deb 0bf5aa36ad0469ebae0fa03e04417f22 58056 libs optional libecpg6_15.8-0+deb12u1_s390x.deb 56f8f35d540caba5ef5ef3ef78e4db59 88352 debug optional libpgtypes3-dbgsym_15.8-0+deb12u1_s390x.deb eb10bec66a732b8060e55d598677f61f 43108 libs optional libpgtypes3_15.8-0+deb12u1_s390x.deb 626855f28e8d727dafc1df911eba6ac6 136984 libdevel optional libpq-dev_15.8-0+deb12u1_s390x.deb 5983994832eb9f00fa6be6f4eb1e6420 272648 debug optional libpq5-dbgsym_15.8-0+deb12u1_s390x.deb 330a8875e306e0e299d71a1a5bf1532d 177304 libs optional libpq5_15.8-0+deb12u1_s390x.deb 395a469be7235c85bd6c0f7bccf78538 15356408 debug optional postgresql-15-dbgsym_15.8-0+deb12u1_s390x.deb 5f6142bc077abba74bef26dc9bbee19f 15883 database optional postgresql-15_15.8-0+deb12u1_s390x-buildd.buildinfo 08a858812df219d57cbac1f104f1a101 5629256 database optional postgresql-15_15.8-0+deb12u1_s390x.deb fd9b9e3675b2484dd539d41b7ae2f267 2237844 debug optional postgresql-client-15-dbgsym_15.8-0+deb12u1_s390x.deb 22f5a2065ab1870e04f74740e116e395 1642248 database optional postgresql-client-15_15.8-0+deb12u1_s390x.deb de6bd0ee560fd7a30b8ffc88852b431b 180456 debug optional postgresql-plperl-15-dbgsym_15.8-0+deb12u1_s390x.deb d6b0d3d3e39a650f74c81111950e8289 64416 database optional postgresql-plperl-15_15.8-0+deb12u1_s390x.deb 10acaccb6dee05c7a7e5001f2a88b04b 170108 debug optional postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_s390x.deb ee595790c79c4f93bb92717e6be2f7a1 87440 database optional postgresql-plpython3-15_15.8-0+deb12u1_s390x.deb bafa138b3dd9b0aa2b498c835441f790 77656 debug optional postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_s390x.deb ebc33d56aafdf181a35d69e42cd34b01 40232 database optional postgresql-pltcl-15_15.8-0+deb12u1_s390x.deb ced025600636d00cd07c993ab1490219 1133988 libdevel optional postgresql-server-dev-15_15.8-0+deb12u1_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEctqRAwcjFMIrbct74euoNlQ3ywQFAma03LcACgkQ4euoNlQ3 ywS3rxAAmvZSnnSWUJNJjT3YSfoAV3x1qHnXKfHtFvluLByt9saBwdxRdG3tZKd0 Yg8AjsE031nfZfRzO6KV6LRBgNID73zZdvR5pVbXJsnN0AgQ7G2e7BRkkD+R50EN 63L77jc2qRLGNjGro0oxsO0oJAXoyM0cd2kiah/GMBuxH9CnyUuZzUEK33zm2Aag lFDTXQYuSr66aI3KWYVgBNTBCrWwQdRd69Dus1k9PPRugbNSY+vzCA3tOSkrD128 lO7+SBo7Nhk7Ld9lLzfVfotYacLTxveh3izjKZftqnNMXXQCSvVO5B3a/9Ea9v9s W7x7aJBWN6NYRN7cMb2TnUANrXXQyxzYdzz3309LMJ/BIh2FU6OgVVmgb6KEf1+j kED6yM1EAWfVWCWXXhdqIkqRBvG0mKsLSXBUlw4jvAS5AgHU3TvifG3oLuwmRqMP 7pJIOwxfzxyoEJPUgn7QTPQ6Gme13HG9igsBE6uXvBW+nJCf9sOVPoR5Fep8Catu SjWWjsf3it5V7oiO+c2WMmYqmTF5FKUzUxnme1aJLMTCKjCIARRpJhAF/WRoNH24 446SMD/r+j1+Z1fpWis9dxPJNBPonHRULpyxmbLeSzo0pIRkmdNjRU4O4VVLF6/D 88Toj8MvXJcZ5P2St4dqAWlWk2sx3g9yJBA/ewhtvprO6a80CQ8= =Xx6S -----END PGP SIGNATURE-----