-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 15:24:37 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: ppc64el Version: 15.8-0+deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-conova-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.8-0+deb12u1) bookworm-security; urgency=medium . * New upstream version. . + Prevent unauthorized code execution during pg_dump (Masahiko Sawada) . An attacker able to create and drop non-temporary objects could inject SQL code that would be executed by a concurrent pg_dump session with the privileges of the role running pg_dump (which is often a superuser). The attack involves replacing a sequence or similar object with a view or foreign table that will execute malicious code. To prevent this, introduce a new server parameter restrict_nonsystem_relation_kind that can disable expansion of non-builtin views as well as access to foreign tables, and teach pg_dump to set it when available. Note that the attack is prevented only if both pg_dump and the server it is dumping from are new enough to have this fix. . The PostgreSQL Project thanks Noah Misch for reporting this problem. (CVE-2024-7348) . * Refresh debian/patches/focal-arm64-outline-atomics. Checksums-Sha1: af265391104cda4c5e6a476653f658f98ed74759 38736 libecpg-compat3-dbgsym_15.8-0+deb12u1_ppc64el.deb b34b26c9a116f25563b8029a72bef8c9aea9be3d 23928 libecpg-compat3_15.8-0+deb12u1_ppc64el.deb e7d6156c20d9fa97795779a5b8c895c00a83cf18 223376 libecpg-dev-dbgsym_15.8-0+deb12u1_ppc64el.deb 2830d88b68321bed9f0a716c3328e59cebf198f1 298888 libecpg-dev_15.8-0+deb12u1_ppc64el.deb 0a5f31739d2ed68646c0f948cfcf0d6b1c5e4b01 113388 libecpg6-dbgsym_15.8-0+deb12u1_ppc64el.deb 1cae6fb70e5182623d9892d8f2cf94451edc7ade 64472 libecpg6_15.8-0+deb12u1_ppc64el.deb 2e796cd89347ff44db90976f6678e2efab9c9cd8 90904 libpgtypes3-dbgsym_15.8-0+deb12u1_ppc64el.deb b466e3991bfd75189425997ee0ac1e90e0f0eca2 48104 libpgtypes3_15.8-0+deb12u1_ppc64el.deb bddf6d736a96551c0110f47bf446e110e53f6e06 156036 libpq-dev_15.8-0+deb12u1_ppc64el.deb 4fe19936b91f8382390d8d7923e118402a39d85a 285240 libpq5-dbgsym_15.8-0+deb12u1_ppc64el.deb 4941949a10475677d0df69ccc7f0bb1c8a4c66cb 199584 libpq5_15.8-0+deb12u1_ppc64el.deb d572615bd573a57749293d608bdbd469c1b6afb3 16681356 postgresql-15-dbgsym_15.8-0+deb12u1_ppc64el.deb 5ca79ac5fb9a17d734054e32540deea330c14a20 17045 postgresql-15_15.8-0+deb12u1_ppc64el-buildd.buildinfo cbced3f975df953ba05a864c0b535997b29b6ab7 17125000 postgresql-15_15.8-0+deb12u1_ppc64el.deb f24a2fe38a91a051048edf0b44cfc18592600618 2317672 postgresql-client-15-dbgsym_15.8-0+deb12u1_ppc64el.deb 04ad10dec186ab9910022ee906988eae28f3ffaf 1726660 postgresql-client-15_15.8-0+deb12u1_ppc64el.deb f901af263a2408df13ce59f044a8d08ce4682436 186396 postgresql-plperl-15-dbgsym_15.8-0+deb12u1_ppc64el.deb 56d1405dce923425cbf1b64320b2d3125c7d8d54 90252 postgresql-plperl-15_15.8-0+deb12u1_ppc64el.deb fde183f481dbab8877416cb9183b7bd5e152f002 176640 postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_ppc64el.deb fa1eedd2c1bb1da0c8e72ab783b3e5056777d8a1 110968 postgresql-plpython3-15_15.8-0+deb12u1_ppc64el.deb af2fa8e94d17e1d2b28f52670345e45f1ea05dbe 79968 postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_ppc64el.deb 9aeb6c7151b9d5edecb2ce36af1a2300a445d609 41744 postgresql-pltcl-15_15.8-0+deb12u1_ppc64el.deb 779d5eb85d7956a97207cbbd7b9bf822f61081f2 1155980 postgresql-server-dev-15_15.8-0+deb12u1_ppc64el.deb Checksums-Sha256: 0715003bdf1b69bd21fd9d823df4b03cb35c1f4e5ecc18c6ec2a1f182ca6ae19 38736 libecpg-compat3-dbgsym_15.8-0+deb12u1_ppc64el.deb db97cced4467887aeaeb8e571fc6b54a4d44127604a00972c2f31ac2e0e11852 23928 libecpg-compat3_15.8-0+deb12u1_ppc64el.deb 3ba88ad0070afddde314b0e1c555dc8d22b3667fdf218dbccdabfd7680345b44 223376 libecpg-dev-dbgsym_15.8-0+deb12u1_ppc64el.deb 280a947d128c2f51f6562a3a135ad422b0f2a03ab52c91c9ec49557695339d77 298888 libecpg-dev_15.8-0+deb12u1_ppc64el.deb 07335ca6bf806bb38d37d84527966e11163910e4b786996d66a7573444ce006c 113388 libecpg6-dbgsym_15.8-0+deb12u1_ppc64el.deb c8f3ee41e2f142ab1902616ba06ebd77c695c1ae09f066db58baba1d7a8371f1 64472 libecpg6_15.8-0+deb12u1_ppc64el.deb e9f6381bb0cdc4a5118e595ac579e3d864b3e85fa9deec219d45b0023487bf81 90904 libpgtypes3-dbgsym_15.8-0+deb12u1_ppc64el.deb 2504c7f72349a5ea345b0e8a1838ab936d213a76d888f2c189ce73a1f0a403dd 48104 libpgtypes3_15.8-0+deb12u1_ppc64el.deb 6dc88618e9242d8dac781cf988d72948f1dc2d62d18e90af0bbf7394b2e6b869 156036 libpq-dev_15.8-0+deb12u1_ppc64el.deb 6f58cd79dd5bb5e474c8407da26c9ced1fbbd5cc3b42dda34e46f7b42bf1d872 285240 libpq5-dbgsym_15.8-0+deb12u1_ppc64el.deb f8fea5fe20e9b9576fe70335e9f2c507f202916d213e3bb06e290ad7fa806f73 199584 libpq5_15.8-0+deb12u1_ppc64el.deb 378e2f3625aa864cce032cc031650fa4a7ae5e289cb35ca7a6a9ef05d04d4830 16681356 postgresql-15-dbgsym_15.8-0+deb12u1_ppc64el.deb 5163c7dc3865cc141430aaf012afd014f5916bc73a498ec700eafd6b7470045c 17045 postgresql-15_15.8-0+deb12u1_ppc64el-buildd.buildinfo 52f030a2f1cc0d7ac14e5a84b45393db9e10292b1718c67f71145b8863066ae2 17125000 postgresql-15_15.8-0+deb12u1_ppc64el.deb 27458d8be3913d7c88773b733d9af9e9d749555cd1d4690baef3ac46a3a83099 2317672 postgresql-client-15-dbgsym_15.8-0+deb12u1_ppc64el.deb 49ef11760d313f8e09124baf9474e7ab44f2f30eab93b499a6ef395bc0731eb3 1726660 postgresql-client-15_15.8-0+deb12u1_ppc64el.deb 7a93287804885f10be3a80cebfe5fc57883f9a1f85f4ca4a62829ac729635c09 186396 postgresql-plperl-15-dbgsym_15.8-0+deb12u1_ppc64el.deb f334a0eaef94f1b5e8bd064b1729769337ff3da4e281225ae770b274bdd44537 90252 postgresql-plperl-15_15.8-0+deb12u1_ppc64el.deb 02ca0e60612ddc963b34b2aceeb01b61578e362da0d8dd4df0981922a7bacb4d 176640 postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_ppc64el.deb 96ac07d209c64effafdf26ffdd77dbf84dde03fba778f8d1698e98c71c27b4e4 110968 postgresql-plpython3-15_15.8-0+deb12u1_ppc64el.deb f386d1cb636bdfbd98277d5e5d516ed9f8215204ac28e8746b5e6cc55b875990 79968 postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_ppc64el.deb f233bde9efc5902ddbd6f4587f845017b0c20cd676bc7482f738e035c3178805 41744 postgresql-pltcl-15_15.8-0+deb12u1_ppc64el.deb a0532a11ec5ca8819061a6d324c612f15d3260018f1c58c6cbfc8fdea03fa5a2 1155980 postgresql-server-dev-15_15.8-0+deb12u1_ppc64el.deb Files: 826807f047d6b2362af77339c2f607d4 38736 debug optional libecpg-compat3-dbgsym_15.8-0+deb12u1_ppc64el.deb dbce2309cea60d7be72a166912acdea7 23928 libs optional libecpg-compat3_15.8-0+deb12u1_ppc64el.deb ef37256c1387ceb50eececabb76562ff 223376 debug optional libecpg-dev-dbgsym_15.8-0+deb12u1_ppc64el.deb 1024eb87b5b593569e69dda7f67e4d95 298888 libdevel optional libecpg-dev_15.8-0+deb12u1_ppc64el.deb d9424fa88cbae920c8abb646302a2cd9 113388 debug optional libecpg6-dbgsym_15.8-0+deb12u1_ppc64el.deb 8a83fc719dd572c1bea526447213d12e 64472 libs optional libecpg6_15.8-0+deb12u1_ppc64el.deb b49a8d1741f791bca78e780c248f70c0 90904 debug optional libpgtypes3-dbgsym_15.8-0+deb12u1_ppc64el.deb 7246e805119bb354f065786774a77d13 48104 libs optional libpgtypes3_15.8-0+deb12u1_ppc64el.deb 93386958b6dbcf74c7f9bcf0ff129495 156036 libdevel optional libpq-dev_15.8-0+deb12u1_ppc64el.deb 650e8564b5e5e36b5e375befa949a2f1 285240 debug optional libpq5-dbgsym_15.8-0+deb12u1_ppc64el.deb 404ac018e1da810969da12fc58737994 199584 libs optional libpq5_15.8-0+deb12u1_ppc64el.deb ae99d2fb716bb1833802ee0cc81e9dbd 16681356 debug optional postgresql-15-dbgsym_15.8-0+deb12u1_ppc64el.deb 0f9be1ea51f9b8b7a09b7c81bd8a3796 17045 database optional postgresql-15_15.8-0+deb12u1_ppc64el-buildd.buildinfo 34951f9744fb52badb6486a95f50f47d 17125000 database optional postgresql-15_15.8-0+deb12u1_ppc64el.deb 98a03949d32c809237bcb5ff914443c4 2317672 debug optional postgresql-client-15-dbgsym_15.8-0+deb12u1_ppc64el.deb 1318658081de57fb7d7675a562f3b7e2 1726660 database optional postgresql-client-15_15.8-0+deb12u1_ppc64el.deb b6fd61a28c21180ddfbd30637e0e3a8f 186396 debug optional postgresql-plperl-15-dbgsym_15.8-0+deb12u1_ppc64el.deb 9976fd518a77b2e196c2d819abbf24c5 90252 database optional postgresql-plperl-15_15.8-0+deb12u1_ppc64el.deb 5c83f87e4c0b4cbdeb2ba9e692279304 176640 debug optional postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_ppc64el.deb ba842b13d89055b64adb6c76b11aaaeb 110968 database optional postgresql-plpython3-15_15.8-0+deb12u1_ppc64el.deb 5215fb8d84256a0e8b45b5720bc99e80 79968 debug optional postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_ppc64el.deb 125d86fba0ef85e76127f680ee69fab9 41744 database optional postgresql-pltcl-15_15.8-0+deb12u1_ppc64el.deb ee6b527e6201109d02a6f72b9d798828 1155980 libdevel optional postgresql-server-dev-15_15.8-0+deb12u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE8YyVP0bbbFwKPsGN0jKBgzfto4IFAma03cQACgkQ0jKBgzft o4LwPQ//ZAvcXFSlNvoplMROJG+JsVM5vOIIzg3BQ4VN0w4bRFOtUkB3zxg73woX 4iWn0K6FCFFUwAUpu0o0IvRCBzy06esaeM2u9wbMPJ5oETKgehbnTHyAfeiqgiyB 7lbHP29994X5WBDBZVynlvJGCAAGfAXct2Dz31tUGGMuw6/PFOTQMVpoi6KijGZj Rt3LOhtd9js8vLekJfCEgUwUk8v6/mfyJlZqNY7687F9GC7ZUBltXs4peT/IVd63 ppaf2HJspiXInyDz6hJhxA2dZScc/0oOaBdcfnCR1a4u5HV38BDZ0DHo5sqQ3UN6 3p4mvVyyv1dABQTJ++nkWRX+l6qcl3APy2XS5jLKV09icu9+MB6a+oL83u17RMaN YfSwjCEf+MTJs/YXRxTOc/kMNv3Evp40Yv8H50iR0fLz3vNb4/efR38XWhbOYDSf 2/8lXJor39umkrYzx5FUlwWLrRKpj9+4AKpfc6QqhXIL0npXQQVI3yic03sjBV0y siF32mDcjdL64iZyAfSU8xQxw7yQw2W8B5w17aJ6Xd2SjvcOkKTOzabu8OFcs3Gu FWSORzeruPCqInFDJwULLWG322QWhKGcZnZ4ns8DEqOEzUdVNm/nDd3OUhXfpNao AKXEdAQctaVzUahHuhtrgvJ2OU5+EdAJ8j2ihRCPWJtaaFADldQ= =fL/D -----END PGP SIGNATURE-----