-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 15:24:37 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: arm64 Version: 15.8-0+deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: arm Build Daemon (arm-conova-04) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.8-0+deb12u1) bookworm-security; urgency=medium . * New upstream version. . + Prevent unauthorized code execution during pg_dump (Masahiko Sawada) . An attacker able to create and drop non-temporary objects could inject SQL code that would be executed by a concurrent pg_dump session with the privileges of the role running pg_dump (which is often a superuser). The attack involves replacing a sequence or similar object with a view or foreign table that will execute malicious code. To prevent this, introduce a new server parameter restrict_nonsystem_relation_kind that can disable expansion of non-builtin views as well as access to foreign tables, and teach pg_dump to set it when available. Note that the attack is prevented only if both pg_dump and the server it is dumping from are new enough to have this fix. . The PostgreSQL Project thanks Noah Misch for reporting this problem. (CVE-2024-7348) . * Refresh debian/patches/focal-arm64-outline-atomics. Checksums-Sha1: fe08d7cdf3331609cf81a53ada339bfef57fe8c5 38648 libecpg-compat3-dbgsym_15.8-0+deb12u1_arm64.deb 0de83deec564ee8631c54dd936efd536a9033865 21948 libecpg-compat3_15.8-0+deb12u1_arm64.deb e653c846460414799afe9a248a0d24734db0e7a9 273268 libecpg-dev-dbgsym_15.8-0+deb12u1_arm64.deb cd1342269b7093942d5176c656fa5a0aee2b5391 279272 libecpg-dev_15.8-0+deb12u1_arm64.deb c80e83c1e2cdcefcfc484cf90cc55943d752b611 113280 libecpg6-dbgsym_15.8-0+deb12u1_arm64.deb a889ec5348d13e315df88b8ca62b5643e0ac5ae8 57932 libecpg6_15.8-0+deb12u1_arm64.deb 9adc412c82f3580c7a990cf6926618fb3dcc0188 87292 libpgtypes3-dbgsym_15.8-0+deb12u1_arm64.deb 97101f377446e3500de5055d5f33fb03da398482 41920 libpgtypes3_15.8-0+deb12u1_arm64.deb 97934b4af080c36becfc28fcd3b6f1b0d9a45846 139884 libpq-dev_15.8-0+deb12u1_arm64.deb 1e65c030df4f03223c0206bd49991a0d04d8a339 274348 libpq5-dbgsym_15.8-0+deb12u1_arm64.deb d5efb1718bce790aa584c1a374a4fdbe7da0f935 179168 libpq5_15.8-0+deb12u1_arm64.deb 984e087dbf995f62af62631c667ab2eb3af1c387 16444764 postgresql-15-dbgsym_15.8-0+deb12u1_arm64.deb c3dad217b5f96123346e8cee41ed427ed6469fb8 16928 postgresql-15_15.8-0+deb12u1_arm64-buildd.buildinfo 35387ee787c049e8b85024f31e07abdd0752329a 16329540 postgresql-15_15.8-0+deb12u1_arm64.deb f4c5829539b1eec4f94d4baf32dbf2c99e7a9744 2426528 postgresql-client-15-dbgsym_15.8-0+deb12u1_arm64.deb 5e4bd630c61b29cae43220b9b93f610028c67053 1652244 postgresql-client-15_15.8-0+deb12u1_arm64.deb d534b6aa228e65865b0fe610dd018a0d02543420 183352 postgresql-plperl-15-dbgsym_15.8-0+deb12u1_arm64.deb ff7a555c15eab3cda0dfea016d65200cfb622b53 86184 postgresql-plperl-15_15.8-0+deb12u1_arm64.deb 89e768a76c6bf9494c68eddfe5f6c4a88c2a18c6 175548 postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_arm64.deb ea1285bfcfceef77f79cd68c7bf0b70e6ce08dc3 106636 postgresql-plpython3-15_15.8-0+deb12u1_arm64.deb b37bd92885111591732a60d355ec983190265fa0 79240 postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_arm64.deb 1ab8ab2cf482436080def0392402484dad619596 40012 postgresql-pltcl-15_15.8-0+deb12u1_arm64.deb 1512bc55c410a027805a5ea55022e147ba93d5c9 1137172 postgresql-server-dev-15_15.8-0+deb12u1_arm64.deb Checksums-Sha256: 6ea50aa552ff9d0d988d192ad17d8218fd63d9ba81b726d047504bcca863a4cf 38648 libecpg-compat3-dbgsym_15.8-0+deb12u1_arm64.deb 75225146fe7d3c1f6035160b46d600454fe887c65b437eb9f076d509c220b15b 21948 libecpg-compat3_15.8-0+deb12u1_arm64.deb 9999225aa2d5af34b68de96d04c13ecebde5be92cfb56617c31f17f9ae37d3e8 273268 libecpg-dev-dbgsym_15.8-0+deb12u1_arm64.deb ccb571967bc7e1570a772029a05b5c59962f09029d2be816cc7317cd1a80cb98 279272 libecpg-dev_15.8-0+deb12u1_arm64.deb 6b92091ab316b0a3b55e8c4b91c470933f87e13be935b9a6ad5cc1f972fbcabe 113280 libecpg6-dbgsym_15.8-0+deb12u1_arm64.deb 2679977772473a260bdb97791145d079036d9b7cee8a95c75d7cc3f37ded68f6 57932 libecpg6_15.8-0+deb12u1_arm64.deb cd10e4e157eb46566d7dbf66ceb12f542931b3d324f0e342758623e23008e615 87292 libpgtypes3-dbgsym_15.8-0+deb12u1_arm64.deb 002ffd97e450d8af14ba707697c7bab86c1b246c98ee717b49b87220530c740b 41920 libpgtypes3_15.8-0+deb12u1_arm64.deb 36c2a8c7e9469ca2403f0e6f458085e32f71371844104c4a148758bed6520286 139884 libpq-dev_15.8-0+deb12u1_arm64.deb e89e76bd1894815f67ba97e61e9b98196c686d4d262514377c291dc5331e1cca 274348 libpq5-dbgsym_15.8-0+deb12u1_arm64.deb 1b1d0ab06180d9c038325d973a762a426223fb1d19a2d6396e325aae32ed743d 179168 libpq5_15.8-0+deb12u1_arm64.deb 8baf560d14bba1730962796140da542f4dfed643d5bb1a29eea545767eca1163 16444764 postgresql-15-dbgsym_15.8-0+deb12u1_arm64.deb f03f748dee748674796a1a10683eec5f2f556779931de1b0791e38dce904b022 16928 postgresql-15_15.8-0+deb12u1_arm64-buildd.buildinfo 597544c1602ea177c540aff381cb19a9a4cd84f6961c7835280f86b569d4a771 16329540 postgresql-15_15.8-0+deb12u1_arm64.deb 5eb891e759facf325b2e920da2e21f679bd0868e278562b41e42a61b698e915e 2426528 postgresql-client-15-dbgsym_15.8-0+deb12u1_arm64.deb cddbbf13a3a210d706215bbbffa2973ef9fd8388063cf6db17759bc9e4bb7d2e 1652244 postgresql-client-15_15.8-0+deb12u1_arm64.deb 607b4242f04852cc3883d8c8afcc2db12c4718afb7c611414728b21d2fc91f7f 183352 postgresql-plperl-15-dbgsym_15.8-0+deb12u1_arm64.deb d9fd10dfdd2f3a16d5be623b30ed566a9f05e7bfff821058325aa082fa0ecac0 86184 postgresql-plperl-15_15.8-0+deb12u1_arm64.deb 6871ab7eb84e54c53477ee3d451dd91a94ee9f7d23270ab6fcba2531ea3f3676 175548 postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_arm64.deb 57807bf4e264a0bb64b4037e2d22ebb3ce1223829ef8d08962f200357fca1cca 106636 postgresql-plpython3-15_15.8-0+deb12u1_arm64.deb b0c8916c7ab911d7ce371034a4d983db7532092ce6fcdc8d9d6d8e939bca0f82 79240 postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_arm64.deb 3adf591d013697ab602c2d72a1258cf8ded97c3be47ab583512a9047da21a9ad 40012 postgresql-pltcl-15_15.8-0+deb12u1_arm64.deb 2b246a9ef69aed572efbfbb38207a84ddd89390119441ab9b9dc0eecefe40653 1137172 postgresql-server-dev-15_15.8-0+deb12u1_arm64.deb Files: 22e6a3e5bb8c8569bfdaf735c382310b 38648 debug optional libecpg-compat3-dbgsym_15.8-0+deb12u1_arm64.deb 9d9d4bde47814a6807961a3774b106ed 21948 libs optional libecpg-compat3_15.8-0+deb12u1_arm64.deb 4c4843957d3b14f780ee017052119137 273268 debug optional libecpg-dev-dbgsym_15.8-0+deb12u1_arm64.deb dd99627428780c8c79b0958a029dbcc7 279272 libdevel optional libecpg-dev_15.8-0+deb12u1_arm64.deb f1802bf6fa23cd15c755f98cdc40aa9b 113280 debug optional libecpg6-dbgsym_15.8-0+deb12u1_arm64.deb d00b66d33255df2dad9e6c6cebde3316 57932 libs optional libecpg6_15.8-0+deb12u1_arm64.deb 0465563efc4bfe643b767167e413e07f 87292 debug optional libpgtypes3-dbgsym_15.8-0+deb12u1_arm64.deb 4432eab7ccb8a923f12a7c1503aa1deb 41920 libs optional libpgtypes3_15.8-0+deb12u1_arm64.deb 1b8e196446582d53962ceade34fc386b 139884 libdevel optional libpq-dev_15.8-0+deb12u1_arm64.deb c6a6dda8c3ea5294018c593178f22fcf 274348 debug optional libpq5-dbgsym_15.8-0+deb12u1_arm64.deb 63e6a0be6fecb3981f93ef0a1e0ef3e0 179168 libs optional libpq5_15.8-0+deb12u1_arm64.deb 4110beb11d7536327ebdb676e370a09b 16444764 debug optional postgresql-15-dbgsym_15.8-0+deb12u1_arm64.deb 3f844e758aed05e599e4a0228b4cb1e6 16928 database optional postgresql-15_15.8-0+deb12u1_arm64-buildd.buildinfo baaa403208047c775a7c75c249d9534c 16329540 database optional postgresql-15_15.8-0+deb12u1_arm64.deb 5a8c2d91220b8698104bb4c4a7801941 2426528 debug optional postgresql-client-15-dbgsym_15.8-0+deb12u1_arm64.deb 09ad29895239869f2aa0cb0c6ebbf08a 1652244 database optional postgresql-client-15_15.8-0+deb12u1_arm64.deb 2d37446fe4929f0a67eb5a76d3d350d6 183352 debug optional postgresql-plperl-15-dbgsym_15.8-0+deb12u1_arm64.deb 7a264037eb1fcf98ad157b5f819337c0 86184 database optional postgresql-plperl-15_15.8-0+deb12u1_arm64.deb 388a8ca7188182efce8ae0404a4eeadf 175548 debug optional postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_arm64.deb d70d8ac60660d883f2511f66ad892196 106636 database optional postgresql-plpython3-15_15.8-0+deb12u1_arm64.deb 2b706532fa2c2bc217cbe481454ac006 79240 debug optional postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_arm64.deb 25a3ff24c1932d622b93f7c328e97712 40012 database optional postgresql-pltcl-15_15.8-0+deb12u1_arm64.deb dd2d3fbfbd7fb950bc053beb076c953f 1137172 libdevel optional postgresql-server-dev-15_15.8-0+deb12u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEElif5H+pIB11ZS5Aay8vyjiVDuNYFAma03roACgkQy8vyjiVD uNbgaxAAqTZRNa1PzMJNSu4b0W+mZqi5dwswwIXw49J9qKkvjGcRtpwDHZyc9L0W r1kz8BJREvrZoM/EnNSdixsIprOZYIVKXZASL9qDMDpmctNlt85mfap/q7yiQqva tGcgce87w3v7fWCyttPhBtr2EkIj6xq9tdGdSibe0ySn42qUe3fceJS+l/uQ7CCX LdCoXNZujln/hWuuLB6FMwvinWQohVS3ir8p+qLoiu2k+E4tAgmhFrTYqrecba7D JDaWaPzu5aq+ybdpzrkAasZa60+U82T/tNNMKOSeJX7qe+739EpFJLUEhqgZKlS4 RC2oWvsZ4mF1FShJHmKRwEUjIOYXpI9v3vAcDhHj3J+pDG0DUvSY9Xsp7ObLTdRu 1jzZo0SIQZDyrTCGlUMJePxaORXo/1IhvzSYTnEfPIEwTRMnNtnQJzciWg6WAw13 VZ/G09viZp9IX2N/NTygKR7nJbi3cc1C8AmZ1lt+VvynceruB+TR7D4cuh72oMKk qPh/tqg2I8raoa0n1sQokzm7LWZ5rYVJMsxgE8xBZbTn/+IxIlzL/jurSqxEeIXI Y7jBkCA00kvdn3Ja7mIzTUDYdCAvToGtTpwPzlhLd56f8mTXRnzQPlBUvvdTf6gV hNQRjCXCEQTzTngcfDk45zdoPmMw+YT5rAJudoagO22RGi2tMJo= =O9+r -----END PGP SIGNATURE-----