-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 16:09:15 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: armhf Version: 13.16-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: arm Build Daemon (arm-ubc-04) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.16-0+deb11u1) bullseye-security; urgency=medium . * New upstream version. . + Prevent unauthorized code execution during pg_dump (Masahiko Sawada) . An attacker able to create and drop non-temporary objects could inject SQL code that would be executed by a concurrent pg_dump session with the privileges of the role running pg_dump (which is often a superuser). The attack involves replacing a sequence or similar object with a view or foreign table that will execute malicious code. To prevent this, introduce a new server parameter restrict_nonsystem_relation_kind that can disable expansion of non-builtin views as well as access to foreign tables, and teach pg_dump to set it when available. Note that the attack is prevented only if both pg_dump and the server it is dumping from are new enough to have this fix. . The PostgreSQL Project thanks Noah Misch for reporting this problem. (CVE-2024-7348) Checksums-Sha1: 840d95be8b51aa321e797046e3c2812777fd3a19 37340 libecpg-compat3-dbgsym_13.16-0+deb11u1_armhf.deb 4204ca3db85523b920f8d97e6350ab960aac8632 25036 libecpg-compat3_13.16-0+deb11u1_armhf.deb 6148b5d5d74bb9c2e820615140de109831622430 214060 libecpg-dev-dbgsym_13.16-0+deb11u1_armhf.deb a14dc81fe517369b94327e28307a1039df3d103d 267996 libecpg-dev_13.16-0+deb11u1_armhf.deb 68ffd3fbbb6d15d8e163c75208b90fd775c4b4b6 108496 libecpg6-dbgsym_13.16-0+deb11u1_armhf.deb c3aa40934c5a5f332136e559c0c361aabb9630bc 55664 libecpg6_13.16-0+deb11u1_armhf.deb fad606fcf9216a5e7564fe526f3ab6399d2255e0 86488 libpgtypes3-dbgsym_13.16-0+deb11u1_armhf.deb 0ca5a248d693919b712eea617370dc3a21ed1776 44496 libpgtypes3_13.16-0+deb11u1_armhf.deb 5ef4a29eabd011e8e5a9e7924f15668d0b71bf88 131664 libpq-dev_13.16-0+deb11u1_armhf.deb 1924501a694745d070f62b0ec597b0a4a5f522c4 248068 libpq5-dbgsym_13.16-0+deb11u1_armhf.deb c12cc0bb5852d966d47529e751fb81473adba5b0 166668 libpq5_13.16-0+deb11u1_armhf.deb 10b11dce2d38a055f6260c32d34b0cb250ff9e46 14309800 postgresql-13-dbgsym_13.16-0+deb11u1_armhf.deb cab952df3c7d4abe34e471c3dd91b59a5ceeec01 16197 postgresql-13_13.16-0+deb11u1_armhf-buildd.buildinfo f662a39bb336cca382ea8e328834b6ecd5a3f036 14573552 postgresql-13_13.16-0+deb11u1_armhf.deb 3d2aaab818017cd04a9bab1c63ed7d534e39bf6f 1829984 postgresql-client-13-dbgsym_13.16-0+deb11u1_armhf.deb 460ee07bf62be0db2da02c5a7bb32d2c603b48d7 1451544 postgresql-client-13_13.16-0+deb11u1_armhf.deb 69aa35b0de0d128b8563380e8e6808e0e9c3e08b 152768 postgresql-plperl-13-dbgsym_13.16-0+deb11u1_armhf.deb 1936e7fd9ebc3d31bf12d3ed8aa5e4b7f006f37e 85872 postgresql-plperl-13_13.16-0+deb11u1_armhf.deb 15c6b761b589830a6ba089f014f6f452c7523bea 154840 postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_armhf.deb f11f1a6357a5ac7999db65ccca5f37bbd8042464 103528 postgresql-plpython3-13_13.16-0+deb11u1_armhf.deb d478b976f64b3f8c5271c1f30a695fe35bf72184 72836 postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_armhf.deb 6a836fe102a3384c5a2f9823a3542dddfdd691e7 41356 postgresql-pltcl-13_13.16-0+deb11u1_armhf.deb 6df29f42c50371a113ce57a81b3d82766998aa5d 1029812 postgresql-server-dev-13_13.16-0+deb11u1_armhf.deb Checksums-Sha256: 22e3b7b905948eac76d8534fb474006556cc0c9e19e7d7324087ae69e1f40443 37340 libecpg-compat3-dbgsym_13.16-0+deb11u1_armhf.deb c05fad3ed8cca9307ed06f759f9b06b9763ca8eed9cd1c19cdb1a779fab72327 25036 libecpg-compat3_13.16-0+deb11u1_armhf.deb ec01346c36a612bf9b22603bbe20efb1ddc00551a36752b8501672edf4d97537 214060 libecpg-dev-dbgsym_13.16-0+deb11u1_armhf.deb 4797b59efa95d420536877e90d61a7d7f8d025597f4e509ff3d72121e3dc5771 267996 libecpg-dev_13.16-0+deb11u1_armhf.deb 6a9e5b35ac54a4523a2e2d8a3bea7851bba7063afa6313e22f643b4f29950147 108496 libecpg6-dbgsym_13.16-0+deb11u1_armhf.deb 61dcff0208df47c56670d8d5e42d3c67e8246e04d45f3aecd6a3ac30fd86e16a 55664 libecpg6_13.16-0+deb11u1_armhf.deb ddf6b72076f88b2b87f0dc2150b5390b11419d0a493c62e76486cdf20476760e 86488 libpgtypes3-dbgsym_13.16-0+deb11u1_armhf.deb 0767bd00f2cdd4e9309ed2529d7cab5ec3b6eee4a168f69360b0dba3b4d9432a 44496 libpgtypes3_13.16-0+deb11u1_armhf.deb f6a5db1e100fa1f754daed79b4b8b443c2e61a19f78a5f65610f85fbd5ae3488 131664 libpq-dev_13.16-0+deb11u1_armhf.deb 32a09a466a4cfa3affd608e3ed0107972798ed0ba03b92c663fd508c8338a566 248068 libpq5-dbgsym_13.16-0+deb11u1_armhf.deb 796e8169a4e7c6bc43eb180382aa8332837ce29b16ce5ac4cc50bb26917e77b1 166668 libpq5_13.16-0+deb11u1_armhf.deb a6024470806cd313c8f695427956bfb69b14d4c005a999c0cf98b6dbff086569 14309800 postgresql-13-dbgsym_13.16-0+deb11u1_armhf.deb 239bf65bc6b8395321d6fc527f0ca848c59cf477f9ead038802c1838ee2591a9 16197 postgresql-13_13.16-0+deb11u1_armhf-buildd.buildinfo fddaa725d85b3bc5e2dd7ed7e4332b39c8fce91fb3e3735a2725644cf20086f8 14573552 postgresql-13_13.16-0+deb11u1_armhf.deb 1475264e62b8af40a0349e388d860a7aec66bb2563a800f5a597622559d18e0c 1829984 postgresql-client-13-dbgsym_13.16-0+deb11u1_armhf.deb 645ddb8af5f2fa583dbaf52354c2b03cbb63b96ab28be4ffc1f446157dbcebc4 1451544 postgresql-client-13_13.16-0+deb11u1_armhf.deb 122f6a8c9727eb413e2aecced288f75d767f0849d82b8c7790114a90a6d7063c 152768 postgresql-plperl-13-dbgsym_13.16-0+deb11u1_armhf.deb af7171bbd010c383831cd9a96c6aa40468eeb9f4a17a80a1f3610a4073dc8b63 85872 postgresql-plperl-13_13.16-0+deb11u1_armhf.deb 25712bd4f82fd47eccf0ad44133c99a02687d8844991f96407afc19840e00595 154840 postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_armhf.deb 5a6e750dc3beaa3d28b18f85ffa718b32c267b496a5353eee25fbefc5e35933f 103528 postgresql-plpython3-13_13.16-0+deb11u1_armhf.deb 3bf8efe3cb54cfecc2f5296b6cb956e4db82058d327928f3b4b6e427fc52ec83 72836 postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_armhf.deb 314b25eedf5ecddb868664d1d9b008c259c33ed57f16fd29b0a94d7d038f86b9 41356 postgresql-pltcl-13_13.16-0+deb11u1_armhf.deb 60769bc7256a1ef54ec02f6530625e12f1577e7709e0d5577a2bb10122a0f8c0 1029812 postgresql-server-dev-13_13.16-0+deb11u1_armhf.deb Files: bdfc7b8625d134c1c023f1569347ed62 37340 debug optional libecpg-compat3-dbgsym_13.16-0+deb11u1_armhf.deb efaf210fe953fd6592edc844c6ffa30d 25036 libs optional libecpg-compat3_13.16-0+deb11u1_armhf.deb ffa1f2981b97036e535cb8ca9064aa7d 214060 debug optional libecpg-dev-dbgsym_13.16-0+deb11u1_armhf.deb d51e4f7e416bf644d6038d110c2d92a6 267996 libdevel optional libecpg-dev_13.16-0+deb11u1_armhf.deb c90e84919f95f0b17d4198e9af699427 108496 debug optional libecpg6-dbgsym_13.16-0+deb11u1_armhf.deb 401f2ab7bd0e9a467dbc03c9eb8e2e8e 55664 libs optional libecpg6_13.16-0+deb11u1_armhf.deb e7a0bf6aef18899c7c21282d0a6d47d1 86488 debug optional libpgtypes3-dbgsym_13.16-0+deb11u1_armhf.deb 413355f44b581bbdfff80a4e7ad2d3cf 44496 libs optional libpgtypes3_13.16-0+deb11u1_armhf.deb 1cb729b5d339d63f17970fb8f090ba07 131664 libdevel optional libpq-dev_13.16-0+deb11u1_armhf.deb 7945c2fb8a41bb573e3658d7ef9260ae 248068 debug optional libpq5-dbgsym_13.16-0+deb11u1_armhf.deb c0995bdd6d59591373edfbdf68dc13e5 166668 libs optional libpq5_13.16-0+deb11u1_armhf.deb a50a2ba7ec690fffbfc8a262b878f643 14309800 debug optional postgresql-13-dbgsym_13.16-0+deb11u1_armhf.deb a272060f94d2c816d41568a78e73edb3 16197 database optional postgresql-13_13.16-0+deb11u1_armhf-buildd.buildinfo 808b0e0b2a045d3668abcf0774723ee7 14573552 database optional postgresql-13_13.16-0+deb11u1_armhf.deb 7032d8f65e671657d8763ee1210df01a 1829984 debug optional postgresql-client-13-dbgsym_13.16-0+deb11u1_armhf.deb 0b06c95956fbd0620d88da52d4af1b8c 1451544 database optional postgresql-client-13_13.16-0+deb11u1_armhf.deb 64da0d3ac1d51a7a1e09014b821210bc 152768 debug optional postgresql-plperl-13-dbgsym_13.16-0+deb11u1_armhf.deb 3dbe09c41546a5e4823ed1658058d87e 85872 database optional postgresql-plperl-13_13.16-0+deb11u1_armhf.deb 125fd7676d04cdc942b8d87f17eecbb8 154840 debug optional postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_armhf.deb 4fe4a58f4c66c7d62077748eefa2f69a 103528 database optional postgresql-plpython3-13_13.16-0+deb11u1_armhf.deb 34ed6441d6e17cbfa784fd0cd0622ea8 72836 debug optional postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_armhf.deb 1ece3fbf553ed893197aa70e1b50b152 41356 database optional postgresql-pltcl-13_13.16-0+deb11u1_armhf.deb dd2ef5b800b553fd47bb0b1e253f5c30 1029812 libdevel optional postgresql-server-dev-13_13.16-0+deb11u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE6s8UzO+WAx8RRAOV80lOEvgzuSsFAma08FcACgkQ80lOEvgz uSsSGg/9E76BRFCdXAaxe43cR+/zku6Wpe/XH4JpaNSceB5xqrGcHgpFVlTC7VWA xSjxWp1gJZfkw6CSl/tLPP8l2mmu//W6eBd9TO4NYZFGxjt6FKVmUvYRPhOR1zrX vOKjSviKsH70KnH8L+n7I3x3qrnxd8Hhe7WNxv5jEQMwNhavYciiDWjIm052kFst Ng8eGZvyF4ZCtfYEX2L1NuK37VUEl01nCzWO2oqQyvtX80wuH3NHeKxIEXHNrQbN WpR7FTBQA9gpD1WUmXEfe7TtqMsSkH5JnuQL3uTK4hlLFb4gy0yIBsueIdQ1ifty U5YgDZwUPi2Q4HL/n7m9nvF435qmXoH1jkS5j8/8+d9ujAvQp/AL9a86uNOC9xMf cKynEKdankM4Nmphm1/Jr1NeUiKQ8uAaUp1TzKdId5BQkzxtJxrQK5DZbF73Ucj9 9kctcTCwIN18rgzr4ao5VQpbJf9aFcPzjTW2bOHLXFIbsvOvIV3xeP3txHpTTnxJ OY/Z64kA/fnS+UOV95Kk/cjOBr5nVbwqH1tejPzwt89U+wx34bMUMQnLquLxTAUW fCHLcsPcfATHk1dSRCv73e/OPVnYyGkrMbF83XBMEAE15X6Ip+Pf0RtGFcOzDMbp Tv26wc4YCoiKh3jdPr4h2d2njFwLC60iYoAQKJllExvpXqSM54Y= =v3eZ -----END PGP SIGNATURE-----