-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 16:09:15 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: ppc64el Version: 13.16-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-osuosl-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.16-0+deb11u1) bullseye-security; urgency=medium . * New upstream version. . + Prevent unauthorized code execution during pg_dump (Masahiko Sawada) . An attacker able to create and drop non-temporary objects could inject SQL code that would be executed by a concurrent pg_dump session with the privileges of the role running pg_dump (which is often a superuser). The attack involves replacing a sequence or similar object with a view or foreign table that will execute malicious code. To prevent this, introduce a new server parameter restrict_nonsystem_relation_kind that can disable expansion of non-builtin views as well as access to foreign tables, and teach pg_dump to set it when available. Note that the attack is prevented only if both pg_dump and the server it is dumping from are new enough to have this fix. . The PostgreSQL Project thanks Noah Misch for reporting this problem. (CVE-2024-7348) Checksums-Sha1: 8f15c54f8484f4756f70862e2de1a246a8dfcd84 37876 libecpg-compat3-dbgsym_13.16-0+deb11u1_ppc64el.deb d74f2969c07b0c51c7010d644a42c5d8480455db 28344 libecpg-compat3_13.16-0+deb11u1_ppc64el.deb ed7a4ee5c51304d2b6d4f208db60b60b385282a1 221420 libecpg-dev-dbgsym_13.16-0+deb11u1_ppc64el.deb 6d7b2ca9ed9a47cdcaa803de669f96dcb707cb2d 288820 libecpg-dev_13.16-0+deb11u1_ppc64el.deb b262cffd19b4fd1ac81448616ba29237d04bd212 110596 libecpg6-dbgsym_13.16-0+deb11u1_ppc64el.deb 3892f9244b60115b843ae43b3f8360fef04140fa 66660 libecpg6_13.16-0+deb11u1_ppc64el.deb e3e9c7323164558f319e83b5f7cf784f4f0f48f8 91580 libpgtypes3-dbgsym_13.16-0+deb11u1_ppc64el.deb 9aa5ce02e79d6d0a6eabcfbc665aa8b9d6b59699 53972 libpgtypes3_13.16-0+deb11u1_ppc64el.deb 435bef33807f490aafa7679dc4289b6a79bb5278 156204 libpq-dev_13.16-0+deb11u1_ppc64el.deb 78a265a5ca016e7ccc59c50c3bdfa6af8de8bcf0 262676 libpq5-dbgsym_13.16-0+deb11u1_ppc64el.deb 1d3a0b5f606b02b80acfcdc0d52879546d6381f4 195304 libpq5_13.16-0+deb11u1_ppc64el.deb 9164bfe995049a4d7ad1d3b57311fe03cdc069c3 14860244 postgresql-13-dbgsym_13.16-0+deb11u1_ppc64el.deb 8749c7bdf78a943500516054c661a8782bf484e0 16434 postgresql-13_13.16-0+deb11u1_ppc64el-buildd.buildinfo 58763ca44cc20887d09b4f01555be02f504fe812 15594552 postgresql-13_13.16-0+deb11u1_ppc64el.deb 4a1372602f25ec9efb9073988f468e22d7c411e2 1906740 postgresql-client-13-dbgsym_13.16-0+deb11u1_ppc64el.deb f62693a0c00bb8890fd9fca3127c1740d1247179 1540248 postgresql-client-13_13.16-0+deb11u1_ppc64el.deb a603be5fed7ab896a2401f7c815e0160bd026f41 157868 postgresql-plperl-13-dbgsym_13.16-0+deb11u1_ppc64el.deb d2726c117413d063ff708ef805571204fa10b018 90760 postgresql-plperl-13_13.16-0+deb11u1_ppc64el.deb 2a32a451a5e04f226ab5d9f08453f0fd71310b06 160096 postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_ppc64el.deb cbe007c90fd69b991e009131c38b635f40b0088e 110288 postgresql-plpython3-13_13.16-0+deb11u1_ppc64el.deb 7e4b811c2ee9eab4de3018c0617a22df378bad46 74720 postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_ppc64el.deb d55c6559013e4fd34e9710828fc56ab20a78fb80 44280 postgresql-pltcl-13_13.16-0+deb11u1_ppc64el.deb 92cf36defb69f8c30f0eee7f1ff7bc77418e766f 1056336 postgresql-server-dev-13_13.16-0+deb11u1_ppc64el.deb Checksums-Sha256: c8c862071dfc3709f12f6fc4df4664f5698b31e6a93b449ff198d5868ee1c1f7 37876 libecpg-compat3-dbgsym_13.16-0+deb11u1_ppc64el.deb 6f5d0966a7937e7905542e989393dd7192133fcf7fc117782efa17d20b5044bd 28344 libecpg-compat3_13.16-0+deb11u1_ppc64el.deb 33ee2fc9947151f7d27d3a052f4bbafced3e6eeb037a100f007d953d874c706c 221420 libecpg-dev-dbgsym_13.16-0+deb11u1_ppc64el.deb 5928310abe6f0a777fc186fcd3f6fd363fe283140d3b798626ea277800a331d2 288820 libecpg-dev_13.16-0+deb11u1_ppc64el.deb eae88813d103234996610c30e3a73fa1d7e7e9d1b490857ce3d036bd019aaa06 110596 libecpg6-dbgsym_13.16-0+deb11u1_ppc64el.deb 39b8403829241e1bd5d0e5685853be1f3a7edfcb38ca3158888e9fa0c58f4964 66660 libecpg6_13.16-0+deb11u1_ppc64el.deb bc97e36912e7d9787996f6a9355226147eb01db00cde58f1b1e4cf54af3728a1 91580 libpgtypes3-dbgsym_13.16-0+deb11u1_ppc64el.deb 5b5948df7ec2f906d27a2e03461edaf0e173510bea96f45f04e78dbcde089e56 53972 libpgtypes3_13.16-0+deb11u1_ppc64el.deb e28f85a9c2dd4d824af03372055e209042ef1d2c5e07767612df6bc474217947 156204 libpq-dev_13.16-0+deb11u1_ppc64el.deb d26711d06813f4cbddedafedf8bf051d83b6853f55721e79d00faa3521863c9d 262676 libpq5-dbgsym_13.16-0+deb11u1_ppc64el.deb 53e01a028cf5d1e693fa8ce685f963e19582c6e99541728924c7b23266fa41e9 195304 libpq5_13.16-0+deb11u1_ppc64el.deb f18a759f132c759987d76dacdd1e75674bcd4a21c8654b35cad4ec19cb643531 14860244 postgresql-13-dbgsym_13.16-0+deb11u1_ppc64el.deb 5a6f1d1a49234492d091e3a7e4465fadaad69f75cfd94fc64fbc968c475f7627 16434 postgresql-13_13.16-0+deb11u1_ppc64el-buildd.buildinfo 76f46f4eab73314211994b1efe0644b0d05fe62d96ae9cc97172a12d903a1c8c 15594552 postgresql-13_13.16-0+deb11u1_ppc64el.deb f952e33b2add22beb0d95b520b8b3af342ca828f5489f3af4a4421a10354767e 1906740 postgresql-client-13-dbgsym_13.16-0+deb11u1_ppc64el.deb 711f2a2a1a90f39aadba181debe02df175db57f76f270fd263ea62e89e426d64 1540248 postgresql-client-13_13.16-0+deb11u1_ppc64el.deb 6b7320f14004b25b9b9b5de0576e4254648df87c01fa9135a32b9ecfc5f785bf 157868 postgresql-plperl-13-dbgsym_13.16-0+deb11u1_ppc64el.deb 10d40072b3e2061ba8ff9d2abe22fddd5e614f3033e82141764bd83062209934 90760 postgresql-plperl-13_13.16-0+deb11u1_ppc64el.deb aa74ec574b6f9ee82b2551e69db9b96b5cc68f056a9ba879970be03bf5de7ed2 160096 postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_ppc64el.deb 0c9d376fd4fd61dc49b45ddeadc0d0f5f8745c84fc663c2420d2ab54bc30a44b 110288 postgresql-plpython3-13_13.16-0+deb11u1_ppc64el.deb 2b259f91bd7ad0ca11036736689afa94db1d5ce814089962d9a4bb3a810cd1f4 74720 postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_ppc64el.deb ad87dd96dcfb21a2e2687b3a9d812e0bcecf9269602067577c6c7a7b24a0fb4e 44280 postgresql-pltcl-13_13.16-0+deb11u1_ppc64el.deb 96956a16d41fa17850871cad2a49d2f262f0e826a6309f16ec21ad62f535a9a1 1056336 postgresql-server-dev-13_13.16-0+deb11u1_ppc64el.deb Files: 958ec38d2cd7894c2310696a41fc0682 37876 debug optional libecpg-compat3-dbgsym_13.16-0+deb11u1_ppc64el.deb 3c05ec7dafe42dec47ea4e2b8c82b064 28344 libs optional libecpg-compat3_13.16-0+deb11u1_ppc64el.deb a0bd0241bca6b9d78ef21c2f08c6b054 221420 debug optional libecpg-dev-dbgsym_13.16-0+deb11u1_ppc64el.deb 03537facff4124288b9bcd12b4709e90 288820 libdevel optional libecpg-dev_13.16-0+deb11u1_ppc64el.deb 137c70ea2178d22975beb053d55749f5 110596 debug optional libecpg6-dbgsym_13.16-0+deb11u1_ppc64el.deb 4a808af9ff64c5327dbb8bf53fbd89f2 66660 libs optional libecpg6_13.16-0+deb11u1_ppc64el.deb 9149673990d8504b861ef12ea3465428 91580 debug optional libpgtypes3-dbgsym_13.16-0+deb11u1_ppc64el.deb c4317e017e57da147815d1d524838f08 53972 libs optional libpgtypes3_13.16-0+deb11u1_ppc64el.deb 62ff1b725d519234edf092b5cc481bcd 156204 libdevel optional libpq-dev_13.16-0+deb11u1_ppc64el.deb f326192fdec4607e8f0d2b8b5bcfc3ff 262676 debug optional libpq5-dbgsym_13.16-0+deb11u1_ppc64el.deb 255dfd2dc778a462d64923835a2de5b0 195304 libs optional libpq5_13.16-0+deb11u1_ppc64el.deb a31aad20bcdfddaf048ff3a8bd73e779 14860244 debug optional postgresql-13-dbgsym_13.16-0+deb11u1_ppc64el.deb 617bfd14668bab246fe821d9ce1f777e 16434 database optional postgresql-13_13.16-0+deb11u1_ppc64el-buildd.buildinfo 6dbae8bb5ac017cf7ed0e7c1a6ccfe37 15594552 database optional postgresql-13_13.16-0+deb11u1_ppc64el.deb c1d79b777a452978bbce43a08788ecd8 1906740 debug optional postgresql-client-13-dbgsym_13.16-0+deb11u1_ppc64el.deb f6a996f0fa2e0f34eafe03352e6fb040 1540248 database optional postgresql-client-13_13.16-0+deb11u1_ppc64el.deb eaa87ec015a6b49df335a51a274359b2 157868 debug optional postgresql-plperl-13-dbgsym_13.16-0+deb11u1_ppc64el.deb 3827b919e7ad2ca9fa1f8e6de904756c 90760 database optional postgresql-plperl-13_13.16-0+deb11u1_ppc64el.deb 21aa03080cb291aa1d278fc8d60a38f1 160096 debug optional postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_ppc64el.deb 14f96801a28353f171ce9f8732a22062 110288 database optional postgresql-plpython3-13_13.16-0+deb11u1_ppc64el.deb 05d82f40068aac4a3e713bc7374aaa6e 74720 debug optional postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_ppc64el.deb 1eee37f82bf337651a32f1934b9d7817 44280 database optional postgresql-pltcl-13_13.16-0+deb11u1_ppc64el.deb 62459b8f511aaa6b78b5c9659a2ce6c5 1056336 libdevel optional postgresql-server-dev-13_13.16-0+deb11u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5v3ycPFoB5xoBEprvMjydu+xvRMFAma04uwACgkQvMjydu+x vROVcxAAu+L0T3UAClRnhlROE9Fl8vcVDAck7J4UW4vwJdvfBgp7pe/355WP4rbi b3ZZLeW+N36fGNsnWPzX2kqgQTdms8OrfxxXWQ9nDIxV+cXeltCJtDI23DJOEKeD b1La4EsQiTdH2drypSN8bAfL7ugcn767nvoa0E1FN3OaXb1ZoIxfYE0sF7YqxSMl S2mYkaPWxcj/NTRQvIFtCmjgDBs81f0AMgDM5Bw2y4D9TKNImTBC3QS4s7jnFVdk 5G9OP0hbdh0qPB86T+ocSmxuqGTS7XGNjRPgy7txF41jfLBGlu9vecTITA571svn dH+h1qNOH28p9acv+exRZ42j65A11Q1HC2uVGH3BDE8B1qlABtsrAHH9AUE/ONbN BMbYlWQOzVamxO39wPmQVsFnUZB52kLR80NUeZ4JjskbTJ2r+nxQfMXe0HC5Ydr/ hoqhvKabF1faWi+Hs174P1Gna6SdBk/gX0atLEMD/aa6a2zw0e4fxbf6jCX7YfIG S7jiC6/P0i8bQ1eg5trmOolzpmWG3YaL3E6B0jSCfUQBApY9CqrwmknIljR+RMDm R1IFZ6qN8vnvRPuvP/V/n2iqAs2V8WdoScBqASusxhsSXLCYCt283GI5u3mq1U6C LHZ31zXyG5Xkm8iUwLooCabbdLkXj5ycijRq1p1XNceRZxZC1WI= =eO8U -----END PGP SIGNATURE-----