-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 15:24:37 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: amd64 Version: 15.8-0+deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.8-0+deb12u1) bookworm-security; urgency=medium . * New upstream version. . + Prevent unauthorized code execution during pg_dump (Masahiko Sawada) . An attacker able to create and drop non-temporary objects could inject SQL code that would be executed by a concurrent pg_dump session with the privileges of the role running pg_dump (which is often a superuser). The attack involves replacing a sequence or similar object with a view or foreign table that will execute malicious code. To prevent this, introduce a new server parameter restrict_nonsystem_relation_kind that can disable expansion of non-builtin views as well as access to foreign tables, and teach pg_dump to set it when available. Note that the attack is prevented only if both pg_dump and the server it is dumping from are new enough to have this fix. . The PostgreSQL Project thanks Noah Misch for reporting this problem. (CVE-2024-7348) . * Refresh debian/patches/focal-arm64-outline-atomics. Checksums-Sha1: 9f939a1c1a315a7d61e17703befbff125f227ab3 38108 libecpg-compat3-dbgsym_15.8-0+deb12u1_amd64.deb 76938d2a24110f35daa1353bca0921b625b77bfa 22576 libecpg-compat3_15.8-0+deb12u1_amd64.deb 66c707568225c17ed433f76c4a5b964ec989dbe3 280776 libecpg-dev-dbgsym_15.8-0+deb12u1_amd64.deb 29b0a5069c89f70dd12bba14bb013b25d7a56510 295244 libecpg-dev_15.8-0+deb12u1_amd64.deb d733e6be988a237679ce48be78690a7b863cc3c2 113160 libecpg6-dbgsym_15.8-0+deb12u1_amd64.deb 09cab1289a60818b8afdc0632d1f2ad2b6ebfb2e 60672 libecpg6_15.8-0+deb12u1_amd64.deb 90844f6c11aee5153eeee92893caad1e4d7016c9 88324 libpgtypes3-dbgsym_15.8-0+deb12u1_amd64.deb 12b1f75a75e5740c18d6dd9b78221c550854e4c1 44264 libpgtypes3_15.8-0+deb12u1_amd64.deb 5ea4e70d99dad5213f30e6a1444ae6d7c77d51d4 143764 libpq-dev_15.8-0+deb12u1_amd64.deb 375ba41793b63a0a38999fa7bfefae0e0f2c2ae7 277124 libpq5-dbgsym_15.8-0+deb12u1_amd64.deb e69dc40010938b5a2a142cca6de362c8fa92a186 188080 libpq5_15.8-0+deb12u1_amd64.deb 68f4c87983150c2db767f41abe58e41f782e6304 16879804 postgresql-15-dbgsym_15.8-0+deb12u1_amd64.deb 3337680d6a8c8544d8eaa0b73908bb09ab02af2a 16951 postgresql-15_15.8-0+deb12u1_amd64-buildd.buildinfo 5e4773b73cece2471c493cca848cc1e1d0c9110e 16798684 postgresql-15_15.8-0+deb12u1_amd64.deb a9a730f4e660e41395b5c522b03bc2e4a4f4e695 2420564 postgresql-client-15-dbgsym_15.8-0+deb12u1_amd64.deb 00f876525b7a4917dbb85b4e91ccfeec623d54ab 1701104 postgresql-client-15_15.8-0+deb12u1_amd64.deb 9adf2020e98db40ce030e0dbebec9239b1c3054c 186756 postgresql-plperl-15-dbgsym_15.8-0+deb12u1_amd64.deb 13f5081389deb0c9beccaf56a3ceb6d53845c664 89544 postgresql-plperl-15_15.8-0+deb12u1_amd64.deb babe0f385434b2dae39c028c2918b9efb6141673 178368 postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_amd64.deb fd9a4c3576bdbfe7ed5fa7062b581d103c9e2695 110724 postgresql-plpython3-15_15.8-0+deb12u1_amd64.deb 00e0a6242aa7185e47d561e58b88b8196f904119 79580 postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_amd64.deb 790639478518fa87d38bdc445d70ba0c124ea159 41688 postgresql-pltcl-15_15.8-0+deb12u1_amd64.deb ac316f6b54a94dd089fa55b46b042ea244ca898d 1143564 postgresql-server-dev-15_15.8-0+deb12u1_amd64.deb Checksums-Sha256: cd786d5e984948995e398fe42cc390ec087d4b945a269377651e14c7648b7e39 38108 libecpg-compat3-dbgsym_15.8-0+deb12u1_amd64.deb e0147f9cec8e3e47e49dada8d61d17b85d308e09243deda1026008577c94c6dd 22576 libecpg-compat3_15.8-0+deb12u1_amd64.deb 76ded60258783e4f8ae5cd224ce145286dc27fa7fe65cea14c629f4c8d18309f 280776 libecpg-dev-dbgsym_15.8-0+deb12u1_amd64.deb ab0e6c6bba70fc128da9559d93793266607e350e36d19f67c55214c841b9c3e6 295244 libecpg-dev_15.8-0+deb12u1_amd64.deb 9fc77e921abc466fb45ff01171017bcee5aaaee4cf5df10ed961a5d26174e5f9 113160 libecpg6-dbgsym_15.8-0+deb12u1_amd64.deb 9b36508135c6297f0186878ed38a469a7c2a4be41370a0f84ec7b52b866fa06d 60672 libecpg6_15.8-0+deb12u1_amd64.deb 8c0666569b0aa0a61482c4faf75aae32e2e8c0905db2b1681b18c127ea5c514f 88324 libpgtypes3-dbgsym_15.8-0+deb12u1_amd64.deb 47580186218910f0f366619dc72d020dad268a2317d9152f5d68a2661c248d2c 44264 libpgtypes3_15.8-0+deb12u1_amd64.deb d412a5b703076456955b73825606f00a31a56858961ecbfd2b99597d43e36365 143764 libpq-dev_15.8-0+deb12u1_amd64.deb 641c15cf1d3794464bcc3d247dfa697dd0d9d8a6df7d962575ce9d05548522da 277124 libpq5-dbgsym_15.8-0+deb12u1_amd64.deb f2b8a141361128eda34a3ba3ee4051caf31fdbf0657adc209b738da0282de425 188080 libpq5_15.8-0+deb12u1_amd64.deb 9409f00200cfe88d4f5d8d2da99d329b1c81fc46cc03b2c29dedcfe036544c7e 16879804 postgresql-15-dbgsym_15.8-0+deb12u1_amd64.deb b0515af1199d26c7a3d577f22c0d3b600b27c10c5a0f9b73940071df43dd9e8b 16951 postgresql-15_15.8-0+deb12u1_amd64-buildd.buildinfo cd5506ea57bba75b68cd91dbf1a673acc95a2321b0c942e75f3533d95ffd9470 16798684 postgresql-15_15.8-0+deb12u1_amd64.deb 6bd7b4e005ac57a071a50df17d3aea5865271b07dc3ad909edb42c5af09a4ca7 2420564 postgresql-client-15-dbgsym_15.8-0+deb12u1_amd64.deb e88cfe7aa8548f8461dcbd56f69a1bb365affcd380469f705aca697fc2146994 1701104 postgresql-client-15_15.8-0+deb12u1_amd64.deb 3bbead00b3c9b1cc4e76ea4f74c9d03737335a9e95f67a991b3fbac3f7dc7b4a 186756 postgresql-plperl-15-dbgsym_15.8-0+deb12u1_amd64.deb 75ea1f6019b2938925fe273e4fac56a2ddf9b05396e52d1ef702a6ac0bd105f1 89544 postgresql-plperl-15_15.8-0+deb12u1_amd64.deb 07608c25f592a348178c01eef8d0cfe32e2bfd6824c732bf04df7458dc2b2252 178368 postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_amd64.deb 640307b1febd22d44b55d7f5d5b81ee21a1b92521e2e21169de1a5bafbd876ea 110724 postgresql-plpython3-15_15.8-0+deb12u1_amd64.deb 6e382dd12d2f44c3360f125800d5b63763a7b44874d980f4db265b9e7d602212 79580 postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_amd64.deb d3a0c0d622a64c7563e0a9d76411bd046a89cfeaf17d3aa5be1b7966dd07fc3c 41688 postgresql-pltcl-15_15.8-0+deb12u1_amd64.deb a54a10312720a84f40c092b7c81de782cced429fa96798ca521f682c320ddc80 1143564 postgresql-server-dev-15_15.8-0+deb12u1_amd64.deb Files: 0e96f32c7295174e96e21a137c548c10 38108 debug optional libecpg-compat3-dbgsym_15.8-0+deb12u1_amd64.deb b6d3ade20bf13d7be1307c3b476138b1 22576 libs optional libecpg-compat3_15.8-0+deb12u1_amd64.deb 7a795414fbe9aa0cc5874985c56bbb1b 280776 debug optional libecpg-dev-dbgsym_15.8-0+deb12u1_amd64.deb 53a41b53d73580bc9295e24de08c18c6 295244 libdevel optional libecpg-dev_15.8-0+deb12u1_amd64.deb 107297016cdaa7f9d8b9fee3eaad6344 113160 debug optional libecpg6-dbgsym_15.8-0+deb12u1_amd64.deb 56783d82b9d5aa26913c006ae83b6088 60672 libs optional libecpg6_15.8-0+deb12u1_amd64.deb 5a45bc8b9d5794bc9fd57b842ac75f7f 88324 debug optional libpgtypes3-dbgsym_15.8-0+deb12u1_amd64.deb 8d7c97d11a5cbdb387d16510d5f2a260 44264 libs optional libpgtypes3_15.8-0+deb12u1_amd64.deb 5db5c109b124aecc339499f02e225572 143764 libdevel optional libpq-dev_15.8-0+deb12u1_amd64.deb 7d073d5152b35c729ae2b7214bf840a5 277124 debug optional libpq5-dbgsym_15.8-0+deb12u1_amd64.deb 2fc695057d6f9bc5896b8a38b92ff0d7 188080 libs optional libpq5_15.8-0+deb12u1_amd64.deb 92b3632f117accf7856dbfad934a3158 16879804 debug optional postgresql-15-dbgsym_15.8-0+deb12u1_amd64.deb ee09610fde124290fe585750c4f76253 16951 database optional postgresql-15_15.8-0+deb12u1_amd64-buildd.buildinfo 878a5c44cd53d9c567a5b8655f27f9f2 16798684 database optional postgresql-15_15.8-0+deb12u1_amd64.deb 3f5a3e16587a1749046a36eefc88ae51 2420564 debug optional postgresql-client-15-dbgsym_15.8-0+deb12u1_amd64.deb c07bf196db33e58c6152cc70381e5556 1701104 database optional postgresql-client-15_15.8-0+deb12u1_amd64.deb bdf967b04172baa371d962b12963d173 186756 debug optional postgresql-plperl-15-dbgsym_15.8-0+deb12u1_amd64.deb e34ed7b049c7f174bfd961b22b906ccc 89544 database optional postgresql-plperl-15_15.8-0+deb12u1_amd64.deb dfe30dba853b3e3f3108dab200c1bf0c 178368 debug optional postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_amd64.deb 984c3ad2791f2b31b70db567a7b74232 110724 database optional postgresql-plpython3-15_15.8-0+deb12u1_amd64.deb a51d4ce1a864ac3e4dc4d9c80f2822d6 79580 debug optional postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_amd64.deb c5a766ab9c1add747b88c59441b2e6f9 41688 database optional postgresql-pltcl-15_15.8-0+deb12u1_amd64.deb ffc2979a8af483d4e19db38a92ed7afa 1143564 libdevel optional postgresql-server-dev-15_15.8-0+deb12u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE4Unr4QHS5Yi4rr9Q3KGKEAtjIVgFAma04AkACgkQ3KGKEAtj IVjApRAAilL/1kRMDmQRVel3J8o45lw2fBsAOGIpXtxIZHEusH3W/kkKd6jcsWvZ en+6cHg0Xq7y/tulmr0qtcleGzQYvyLwft4Rmpx3i8GuipjG0LP5NDVyVOkT3Hrl 3L5590ZHMCUJQEBObr00/xBSRq33+eKWBNUySJ+F0LGLnZ21AlDWVZrtlvwEI3oQ tTXQxW+msChvqUepa0euQLuVroyAuzdhA2eO4xo4vBupMQfImoNOGaM+gdqh0Ah4 IP1ebEY9mK0tiQ8vGX/GZV4CUhahPxxPXKIi11UbpLz3kaZQK/UmGHI+4cAVRGxk 8YWLIYc8e4ERBDWzazdC1UH0IL9mUyJcdMtajLlAU2RWSBjCxCVkOFANs73n5cSw CUZjlH/uP1DE62dMu7cXTMfTU6lgJnQWEKY+vERMxnVvUDBIpwf++PsT5JTLp5jq hTvKWrHRan4OGEEB5DjdVoD1u+ymqyGDwBzsJxA9p7vLh1TiuzTfK9OhJhzGw/Ci GjYQbGm8ImM3dkpQZ00OjtJCXm5FgXo4Bw0afX+wKBxdR0Lq9LBd3am7R0gxSbkI If/qZh/1cqGVDFckSJNGDdLJWqp/dZdCaprsYWdtqGx8WZgLTCWMmNiLj1JOTDOW 28kXptyBy9Pt2hDGOhSTPlwH4RTSHqyzj7kCYYjL9jwelwI7F5A= =tNbe -----END PGP SIGNATURE-----