-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 15:24:37 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: i386 Version: 15.8-0+deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.8-0+deb12u1) bookworm-security; urgency=medium . * New upstream version. . + Prevent unauthorized code execution during pg_dump (Masahiko Sawada) . An attacker able to create and drop non-temporary objects could inject SQL code that would be executed by a concurrent pg_dump session with the privileges of the role running pg_dump (which is often a superuser). The attack involves replacing a sequence or similar object with a view or foreign table that will execute malicious code. To prevent this, introduce a new server parameter restrict_nonsystem_relation_kind that can disable expansion of non-builtin views as well as access to foreign tables, and teach pg_dump to set it when available. Note that the attack is prevented only if both pg_dump and the server it is dumping from are new enough to have this fix. . The PostgreSQL Project thanks Noah Misch for reporting this problem. (CVE-2024-7348) . * Refresh debian/patches/focal-arm64-outline-atomics. Checksums-Sha1: 2e1d5cbba1792f5623c942c2d4dd3ede0862966f 34596 libecpg-compat3-dbgsym_15.8-0+deb12u1_i386.deb 9aaae7cd0b4f938c7f325ebaeee02a94cd631d4e 23248 libecpg-compat3_15.8-0+deb12u1_i386.deb c9f5ecc608283bde6291d785cc519d4b0b9d5b4f 270496 libecpg-dev-dbgsym_15.8-0+deb12u1_i386.deb b862b12285ed3781c048d5a53dea85f59e719ac7 305776 libecpg-dev_15.8-0+deb12u1_i386.deb 7d81012754805e6e9f268903094b5d1e4163e1ad 101800 libecpg6-dbgsym_15.8-0+deb12u1_i386.deb 8165e5426b3eb8a743364f5aa7cb0f9fc9afe1cc 64548 libecpg6_15.8-0+deb12u1_i386.deb 49b3ba4628f541cb741ca3a7da72e3de03da88ec 80800 libpgtypes3-dbgsym_15.8-0+deb12u1_i386.deb 1b531c2b8fd314a481f1cf4ab6545e3528ffcf80 46364 libpgtypes3_15.8-0+deb12u1_i386.deb ef777dc4021c629344ef7e737b335977368dc184 152868 libpq-dev_15.8-0+deb12u1_i386.deb 967b704dd89d4b684b6aeaddf7d6b91d854684cd 241384 libpq5-dbgsym_15.8-0+deb12u1_i386.deb 6d084b9f67d987dc0a74588cf075fa3392f09e92 195552 libpq5_15.8-0+deb12u1_i386.deb a97134f70dba3775ba37eb162389efe0a8b2fa48 15273400 postgresql-15-dbgsym_15.8-0+deb12u1_i386.deb b2cbf00333ad59b661b9b13aa868201de81c83d1 16831 postgresql-15_15.8-0+deb12u1_i386-buildd.buildinfo e9f6cb9de84e57f29d1aa4ae37d85528e7650108 17027296 postgresql-15_15.8-0+deb12u1_i386.deb 422a32ce92beef95a42e1eb6e53d73cd7f392d8f 2061516 postgresql-client-15-dbgsym_15.8-0+deb12u1_i386.deb cc3f4492369ebf75761d51e971fd03a3ed081b29 1725020 postgresql-client-15_15.8-0+deb12u1_i386.deb 87c6e14465debeaedb87925813111f0bf0a13293 173708 postgresql-plperl-15-dbgsym_15.8-0+deb12u1_i386.deb 220dca51f68b790bb89b2d1b07ee837e4314244a 92960 postgresql-plperl-15_15.8-0+deb12u1_i386.deb 92e7072e3a7ad6b614ca62ab35450bc3036960a9 163464 postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_i386.deb 8fa8a68b9ee3ba1040b66307829755fa91b960bb 113720 postgresql-plpython3-15_15.8-0+deb12u1_i386.deb 97e9c1ca3f38435907dc04e69bd9383f6348cea9 74084 postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_i386.deb fcc1f46b04f6e95f7ae820c31777cb8f68518ba6 43092 postgresql-pltcl-15_15.8-0+deb12u1_i386.deb 818ec6519de03b9fd067209adc23900ffcd12ca9 1158100 postgresql-server-dev-15_15.8-0+deb12u1_i386.deb Checksums-Sha256: 17a6198442a5386edca5aa11eff3806c40a8e4c63288dd156ff141a54007dd20 34596 libecpg-compat3-dbgsym_15.8-0+deb12u1_i386.deb a104e597afcba1e06ae6743b141a9a947bd7a9c65deea5097824361292231cb4 23248 libecpg-compat3_15.8-0+deb12u1_i386.deb 225bd0e4b539693e22ba840f1a4cfc6ce5d3ea23a17a10ec9426432eacc46f6f 270496 libecpg-dev-dbgsym_15.8-0+deb12u1_i386.deb 241ac64e2e2a6de1d3c72dda737ac452e0599e34eadb8106bce18e233d79677b 305776 libecpg-dev_15.8-0+deb12u1_i386.deb 8e4d8181f41da1ac378155a56a1509a70f77aee6867a0f8ad405a17df0f5610e 101800 libecpg6-dbgsym_15.8-0+deb12u1_i386.deb d67fed0d934ef56ed17826b490a3e9022fbcdc6c7c41e820178de6a1e03065dc 64548 libecpg6_15.8-0+deb12u1_i386.deb 121a185722d18d25fd6c78bae32cf8ad05de66609380995ed24a6cbfab120408 80800 libpgtypes3-dbgsym_15.8-0+deb12u1_i386.deb 5fe4339f3b2dc3dd8efd41eefd66ffac394c1f1f0367357fc50fc446a72b56fb 46364 libpgtypes3_15.8-0+deb12u1_i386.deb 2ea2b627e260195593e55a596890e6e2af18fd815df017b88b06a1cf02369f57 152868 libpq-dev_15.8-0+deb12u1_i386.deb 6799f0b687f96a51fcfe5253368a92f4f770f606917a31fa3696bfdd749469ec 241384 libpq5-dbgsym_15.8-0+deb12u1_i386.deb 30cec0579f7ecd7e1ededb8c8f15cf598dde30777ad4f6a1e618a7177fce17db 195552 libpq5_15.8-0+deb12u1_i386.deb 25b014ab135e363033ba41ecc2fd4f4209b9608b616e0e7abc8a899d74486c9e 15273400 postgresql-15-dbgsym_15.8-0+deb12u1_i386.deb ad5ef1b4322892fcff363ee07e668809368d81eae5f8d0418541917fec82f0eb 16831 postgresql-15_15.8-0+deb12u1_i386-buildd.buildinfo a46fb374086709bc4d12254ec2b010d1767c913c078b27c06dbc421fc75c3731 17027296 postgresql-15_15.8-0+deb12u1_i386.deb 07ef834659c9666e7eb1bb64cce55ac3532df25095ee0bd8c0c46e86a4811db9 2061516 postgresql-client-15-dbgsym_15.8-0+deb12u1_i386.deb a032607dde7e4b54d7ca7f551e00e42b37796adc0f282d602a8c81dee09702ad 1725020 postgresql-client-15_15.8-0+deb12u1_i386.deb 3d47aefdd62fa9cae5dd4903f949faee963e263534dc06522148c174a306dd68 173708 postgresql-plperl-15-dbgsym_15.8-0+deb12u1_i386.deb 9ee9aaefd5b4fe232d094771b21e15b5c3d899f129ca091baae1a99d97fbd2a2 92960 postgresql-plperl-15_15.8-0+deb12u1_i386.deb d028fb10bcb8992e707a6a23cf26b93ef8d71724eb97f86299f4a33d1ac67b1e 163464 postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_i386.deb e3f18afaff8186bfa5413fa5d423ef11b93a00a8132b32e58ae9dc2b97ce90cf 113720 postgresql-plpython3-15_15.8-0+deb12u1_i386.deb 29841bd2dab32c2275bf89467fea744c34b15b783e8a82788561fa93272ce820 74084 postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_i386.deb 0cce6f0ec6aa2ee1fff715271d9040c6acb362bb684518bd8e3f0e705165aada 43092 postgresql-pltcl-15_15.8-0+deb12u1_i386.deb c146201bff6f049891865f7c506796631f7ed647c980f45cbe2425fa75606c91 1158100 postgresql-server-dev-15_15.8-0+deb12u1_i386.deb Files: c11d0ea651a82ef80b8e489d99d0ec3a 34596 debug optional libecpg-compat3-dbgsym_15.8-0+deb12u1_i386.deb 7e07ad30257a582cb32abd7a3e9f3245 23248 libs optional libecpg-compat3_15.8-0+deb12u1_i386.deb 26cdfa51fcb116c7c7832d749a7b481c 270496 debug optional libecpg-dev-dbgsym_15.8-0+deb12u1_i386.deb 4c3c565330bca758e6b32d9d64144819 305776 libdevel optional libecpg-dev_15.8-0+deb12u1_i386.deb 1634f7e0db75316d137e86a52bb69102 101800 debug optional libecpg6-dbgsym_15.8-0+deb12u1_i386.deb a7f492e09a0fd23e5091c40332e84d4d 64548 libs optional libecpg6_15.8-0+deb12u1_i386.deb a68b49185842d535a2b37d3dbeab4bac 80800 debug optional libpgtypes3-dbgsym_15.8-0+deb12u1_i386.deb dd694efa6f814442174412686a6090c6 46364 libs optional libpgtypes3_15.8-0+deb12u1_i386.deb d067220e07304e5a379dfd114abdc138 152868 libdevel optional libpq-dev_15.8-0+deb12u1_i386.deb 59b6be060b284b2d3cbdd0dddc87a60e 241384 debug optional libpq5-dbgsym_15.8-0+deb12u1_i386.deb 81b76133ab6c076b49d0e3943a5ac441 195552 libs optional libpq5_15.8-0+deb12u1_i386.deb 47c80dea557e98171ee4cd6e68b01b6f 15273400 debug optional postgresql-15-dbgsym_15.8-0+deb12u1_i386.deb c272abfc2f795a09e741344f53144662 16831 database optional postgresql-15_15.8-0+deb12u1_i386-buildd.buildinfo b7ec05331bc99750214231c499737017 17027296 database optional postgresql-15_15.8-0+deb12u1_i386.deb c8c4498b3f9a2921b67bcf386b62fac5 2061516 debug optional postgresql-client-15-dbgsym_15.8-0+deb12u1_i386.deb 2588610ef74ed030df10900d2ffb0e72 1725020 database optional postgresql-client-15_15.8-0+deb12u1_i386.deb 0c4096b516658c43b491e8f33a9a5307 173708 debug optional postgresql-plperl-15-dbgsym_15.8-0+deb12u1_i386.deb fd1bdc9561a29c3303aa434f3c821849 92960 database optional postgresql-plperl-15_15.8-0+deb12u1_i386.deb c096e28c9a413a60b4968412fb6b078c 163464 debug optional postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_i386.deb d0c0a69548d4781c0c3d1789848ceef0 113720 database optional postgresql-plpython3-15_15.8-0+deb12u1_i386.deb 9ae5d49a63a8c046efb9a943a31ca486 74084 debug optional postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_i386.deb 7fbd932b1aa76298f2edf8b9fb1c8493 43092 database optional postgresql-pltcl-15_15.8-0+deb12u1_i386.deb d1fc499913402a66118f26732dfe22fa 1158100 libdevel optional postgresql-server-dev-15_15.8-0+deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEgdRoRGwEM09wlaMzOni7ZmUpKEcFAma04Y0ACgkQOni7ZmUp KEcMQg/5AVcp23Hpip3je9XxsZdo917Cg8lz/ZEa2wfZR/lnZ8CiK+c3HrDLg5VJ sONHoHqWiXOpm5d1h01+jghlhb9gWU4SVN41v8ddpH7/aVcLYZwEegxZpPL5DafQ nLTK4abwFAQ/C0CvOUPNZzMFf4Ap78cjdzs3+gQPiRp3uAWselsYOzEwm9RpO4k2 vxIw3i1DzwoiFz+I8PXgWJT1ynh2C1rUKQjGATHfX8dxnPI+sEvhu4IknD+/v/kT Vbuq2Pmg6wLw7d39XuoSdIA1Ja55hk3kG5y+bYgXx7AQBDsyNPbC8alcm4jZkcps R3pe4eL/AMcY1a2ksZjq6dCqskIGJK7dJp8TjUWLX110U+OoQ3yYfGMS13RtlHpC lb/8ipq2z3FYftGgfkpVvD9qw2W4jZn2OT/CECANIIsIAArNGiOdBSSEBNX329aO uQuWADT7mRczEG3Tklc4xy+c2Q1Uer9Lm0sOI1izfAbMRA/PHecYVwH83WQGL2g8 +au/qBDkInTpUOHRlmxF84GTJn4wTDt9MvlAfi4LwF1BPXlqgvx9RR673AOs1/yL 7KAqjRZFzk/BXdIqAc63vOggrNsuxqujOvkF5qUiUpMWBmPOElMer/1jNUfJK+MU RgZLI9LSnqz2qDhwrdzOxwkkgefto60F29QRW2PHCINb9CBaPL8= =25km -----END PGP SIGNATURE-----