-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 16:09:15 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: i386 Version: 13.16-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-02) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.16-0+deb11u1) bullseye-security; urgency=medium . * New upstream version. . + Prevent unauthorized code execution during pg_dump (Masahiko Sawada) . An attacker able to create and drop non-temporary objects could inject SQL code that would be executed by a concurrent pg_dump session with the privileges of the role running pg_dump (which is often a superuser). The attack involves replacing a sequence or similar object with a view or foreign table that will execute malicious code. To prevent this, introduce a new server parameter restrict_nonsystem_relation_kind that can disable expansion of non-builtin views as well as access to foreign tables, and teach pg_dump to set it when available. Note that the attack is prevented only if both pg_dump and the server it is dumping from are new enough to have this fix. . The PostgreSQL Project thanks Noah Misch for reporting this problem. (CVE-2024-7348) Checksums-Sha1: 5af3f4186d0232ac31fb30a38464aa777913dc86 33388 libecpg-compat3-dbgsym_13.16-0+deb11u1_i386.deb a9d79f9ddb7563cd943cdf6ee8b207ac63f07911 28288 libecpg-compat3_13.16-0+deb11u1_i386.deb 00f6d8541b47060650be342369a66088349ef696 227288 libecpg-dev-dbgsym_13.16-0+deb11u1_i386.deb 11f7cc808f66567674d79635bba86530562cab46 298752 libecpg-dev_13.16-0+deb11u1_i386.deb c240719c024c2252df3a00db5b7e84f547af3fc3 97256 libecpg6-dbgsym_13.16-0+deb11u1_i386.deb 91471ea8d337c37f2f06db7c2436bc323c625a52 67164 libecpg6_13.16-0+deb11u1_i386.deb f8b8a53e0cd8de3026d5b4c8186f4cc6b694a077 80316 libpgtypes3-dbgsym_13.16-0+deb11u1_i386.deb 58c3072329a74164f8d6cd30178938f54d04619c 52168 libpgtypes3_13.16-0+deb11u1_i386.deb 1cd6721f0697b1f5dd7d53dccb22ed8426c951d7 151848 libpq-dev_13.16-0+deb11u1_i386.deb 1cea732f4c488dbd443f68004117c5673c401101 218324 libpq5-dbgsym_13.16-0+deb11u1_i386.deb 4e3cb088e5f4c6f5c0ec1ab0f5029e87ffef2fd4 190596 libpq5_13.16-0+deb11u1_i386.deb b448be2fdfe8d5c9f26e814ad5414a4af4e291b9 13598832 postgresql-13-dbgsym_13.16-0+deb11u1_i386.deb 9eb6d26f901fd24fbb260e74ccd1fb79ec9e39ae 16312 postgresql-13_13.16-0+deb11u1_i386-buildd.buildinfo 472f15248bf826e2bb57691f072e4cec56d38acb 15392128 postgresql-13_13.16-0+deb11u1_i386.deb 6889f9660e89cb633a01e31b3bec263985a3b537 1552100 postgresql-client-13-dbgsym_13.16-0+deb11u1_i386.deb a1db087da52dd31ce8f14ab8738358180e5bb83a 1540276 postgresql-client-13_13.16-0+deb11u1_i386.deb d8c0757a579b5ef51a12624bac1de5b9fa8106b7 143440 postgresql-plperl-13-dbgsym_13.16-0+deb11u1_i386.deb a9a05eb43da3984396470ef1c95f911a3945f362 93320 postgresql-plperl-13_13.16-0+deb11u1_i386.deb 32a0fcf422a317f713cf00e6368774b2fc9262b8 143804 postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_i386.deb a7201b22b45d103fc7ba6a7ee5f85c981f86239f 113056 postgresql-plpython3-13_13.16-0+deb11u1_i386.deb 92f73a8ca5a3833cec5afb60ab4cc5d2ac6b910d 68424 postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_i386.deb 2cff0094efb010f82e5fc3d3f939d160e0258e21 45192 postgresql-pltcl-13_13.16-0+deb11u1_i386.deb af4f73338a7a7fbf79f02513d456cbf8c389890a 1055300 postgresql-server-dev-13_13.16-0+deb11u1_i386.deb Checksums-Sha256: ede7e87430489314ca229546f7d01aec516b2f9348d7f3fc9751e446f71fa89e 33388 libecpg-compat3-dbgsym_13.16-0+deb11u1_i386.deb 5034b77b57f4fc243ecc93fe9688fcab7b5ffbd4d7fbbf8bca3ace51df4cd1ba 28288 libecpg-compat3_13.16-0+deb11u1_i386.deb 59474b7455fb5918c4980307669e637ef1492a7870b8a560f07d3f37a34bf26d 227288 libecpg-dev-dbgsym_13.16-0+deb11u1_i386.deb a915813b42594c2b2dad66be0fbfa0f538b530f67f97d8afd4b6082a485da66f 298752 libecpg-dev_13.16-0+deb11u1_i386.deb e7e40e9c98166665ffb9df55f60d4e00e7ccfe51b344409e85cda4592bdd82c3 97256 libecpg6-dbgsym_13.16-0+deb11u1_i386.deb c3313b7c2b29bd103cd7de378afd6dedb3b3e7ebdfe22d1af47a7ab45c738a07 67164 libecpg6_13.16-0+deb11u1_i386.deb a4dc4f143bc5c6b55e9ec4fe6a3e5a5e68748284643de7e2cb98be9258cf14e7 80316 libpgtypes3-dbgsym_13.16-0+deb11u1_i386.deb 3930f7b48c248a27393098e7106c28b10d0edaea207e1a07f87d88b2f0990559 52168 libpgtypes3_13.16-0+deb11u1_i386.deb 89c9dd21530bf2c1da5ef4332783e78d09d5e524afeb0242286501e7949761a2 151848 libpq-dev_13.16-0+deb11u1_i386.deb 9e67811a0c8516f8b43047ebfa2baf04abee3ff8eb36266a6c784af550cd0e28 218324 libpq5-dbgsym_13.16-0+deb11u1_i386.deb 1729bf417098cf24042b68393511076222849bd1ca4a9d3a2170f192a85a5090 190596 libpq5_13.16-0+deb11u1_i386.deb 142018fd04f655e211bb344f2977cf211a5b922bc4b97b8a1dda776dff1447f6 13598832 postgresql-13-dbgsym_13.16-0+deb11u1_i386.deb d56359d8d4120f7d38ba70116d3d1aa9ed3558cd84c714516f6609e003d77d3e 16312 postgresql-13_13.16-0+deb11u1_i386-buildd.buildinfo 1a29b9a7278018e84dc44163ddfcf3f10359cbc561219734dbb66263944fec30 15392128 postgresql-13_13.16-0+deb11u1_i386.deb aea39a416bfe2691bd2101416ff400e672e05512bb3df00ed0802fe94bab52b4 1552100 postgresql-client-13-dbgsym_13.16-0+deb11u1_i386.deb c261c4359964f942748bc1cff7faca206c93f686479a6c61ffd44319694df59b 1540276 postgresql-client-13_13.16-0+deb11u1_i386.deb db10389eb65a7a14bcb587c4d5f8d75d6762f7cc5fff389073e2bd608159df6b 143440 postgresql-plperl-13-dbgsym_13.16-0+deb11u1_i386.deb f3ccc7ee3be6ae74d5ae7524556aa59bfd6b12560fa9b5baaecce62af239b7c8 93320 postgresql-plperl-13_13.16-0+deb11u1_i386.deb 45c44edc98d46e15c256cc3166966409c11955a6816bf83b7d16cf9854efea96 143804 postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_i386.deb 46ed5f9dd16d160546cbe374a17ba839965d409cfdd7170d637d24cb1f83229e 113056 postgresql-plpython3-13_13.16-0+deb11u1_i386.deb e38dddecb9d14794285445463ee3f011999040b72a03da208a181fc358187980 68424 postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_i386.deb 139bac791c7f2ace0bb4a112b162846a3eaf98c34ffd3a5dc7c65c610cf88f65 45192 postgresql-pltcl-13_13.16-0+deb11u1_i386.deb 5421314a25129e4fd0d32810374bb3df7eb7fb92efb1b5fd1ea5b51e5d4407d5 1055300 postgresql-server-dev-13_13.16-0+deb11u1_i386.deb Files: 338c6bec257093df3b8ec11a7840e656 33388 debug optional libecpg-compat3-dbgsym_13.16-0+deb11u1_i386.deb cfcd1a071c0736c1046247ba1d63e4f9 28288 libs optional libecpg-compat3_13.16-0+deb11u1_i386.deb 90930a19dc619601c8db47f7bee3de78 227288 debug optional libecpg-dev-dbgsym_13.16-0+deb11u1_i386.deb ec445a4eab329c1c7fa31dd1da6a3a96 298752 libdevel optional libecpg-dev_13.16-0+deb11u1_i386.deb 4eba1004db8f9cdb7568913baa993131 97256 debug optional libecpg6-dbgsym_13.16-0+deb11u1_i386.deb 1f318f9bd1219ecc24ca59371408562e 67164 libs optional libecpg6_13.16-0+deb11u1_i386.deb 44b9b4a8ceda319b15023a3ce862d560 80316 debug optional libpgtypes3-dbgsym_13.16-0+deb11u1_i386.deb 3b5bf6f1bf96f43ba630805e53a36034 52168 libs optional libpgtypes3_13.16-0+deb11u1_i386.deb 49547067a75fc735a317ed541291b782 151848 libdevel optional libpq-dev_13.16-0+deb11u1_i386.deb 63128ca5ccca91ac9703e473f59e2545 218324 debug optional libpq5-dbgsym_13.16-0+deb11u1_i386.deb 880425a7cddca49cb07aecd4971ca26f 190596 libs optional libpq5_13.16-0+deb11u1_i386.deb 672f24272de27a38c64e7a6c44405ea0 13598832 debug optional postgresql-13-dbgsym_13.16-0+deb11u1_i386.deb 291ae7840deb50ec5d7a48025ff6bbf9 16312 database optional postgresql-13_13.16-0+deb11u1_i386-buildd.buildinfo 5efccf9a0bbb05ce633b8ec967077b1b 15392128 database optional postgresql-13_13.16-0+deb11u1_i386.deb f460f63e892e04cc02d8034df076948c 1552100 debug optional postgresql-client-13-dbgsym_13.16-0+deb11u1_i386.deb 781406665d5f5fbdd5f9f498deb3bb48 1540276 database optional postgresql-client-13_13.16-0+deb11u1_i386.deb ed4db21a2e88691fedf55b64ff2c08c8 143440 debug optional postgresql-plperl-13-dbgsym_13.16-0+deb11u1_i386.deb 4cf9ee2a94e87ba0b5e17154b563a6b2 93320 database optional postgresql-plperl-13_13.16-0+deb11u1_i386.deb 13eb519a5a1aafea74e51b6df283eba4 143804 debug optional postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_i386.deb 68a68561ae6c7fd87c103bed904c931b 113056 database optional postgresql-plpython3-13_13.16-0+deb11u1_i386.deb 1565b25c084df7cd3bc6a83adfb93dfc 68424 debug optional postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_i386.deb 2ccb6b9268f67531451cd5af10b68483 45192 database optional postgresql-pltcl-13_13.16-0+deb11u1_i386.deb 84e6dcf3a6ac6503bcf5d4ce7b903252 1055300 libdevel optional postgresql-server-dev-13_13.16-0+deb11u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEErEDrIdpJkzFMm6K+PyQET5WCY90FAma05UoACgkQPyQET5WC Y91jcQ/+PcdZLWrEESA1gms7cuwLYUluuLoU/UgsqSgBjfnyRY0CMUT6j/aKDhLf tNnCp6hWlg3N0QPvVf5LsrFfcZdMSSfd428IqYRiDz1T0aSMiRNAMHaI6GCU4ROt r/1njFYQbSGt0PKVvfidVwDuGjOXfE5BHv+mFlnIrvKR+5vvn36l1mx6zuqPCy31 3380gYdFFBnMqsofBKHYOt2WiKLN3AQnkp2du9am/WsvXNjeP2alXEXxSRMCRmhC 1/k7dZRXu/JGZCwscj+r+uF3Uu2L1gsYH//HhU7ZoiDVodrwh1fSRwOrQKAnky3C +WDsuj/pVfdiheTML35sUXLcDwir9DyqK/kclVbNCj+n6nxM5m994tvvcoJb/IDh 4yNwOdKZG7ohZrBTj6DwgJfQJlQh3h00PUPS0pnQxG2iR7QxFYpr6oJT1DSYfrNG BEbV3F2M1pYSeXHzmZvYM6gR5N/9d0N2R90BbnYNjbbSSp9obnfE0uf9ve/Ub8z1 ldnng2FGusdJRU6h2QM/WX4aTIObnPEgEDE3w+fEGIdfSzIb5ayP2iTVVHpJSiZi sxJy7eBzDS1WmjS1x0yYtgywsPvl9mLEoBLieqEEyoBNtaNxuCHZXr/H9+RCgiZo CcIhtCLw0BV2yuhTv0RVbwHY9yb7cOv91JvhSDhsfqIUITgDhtw= =TFAW -----END PGP SIGNATURE-----