-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 15:24:37 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: armel Version: 15.8-0+deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: arm Build Daemon (arm-ubc-06) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.8-0+deb12u1) bookworm-security; urgency=medium . * New upstream version. . + Prevent unauthorized code execution during pg_dump (Masahiko Sawada) . An attacker able to create and drop non-temporary objects could inject SQL code that would be executed by a concurrent pg_dump session with the privileges of the role running pg_dump (which is often a superuser). The attack involves replacing a sequence or similar object with a view or foreign table that will execute malicious code. To prevent this, introduce a new server parameter restrict_nonsystem_relation_kind that can disable expansion of non-builtin views as well as access to foreign tables, and teach pg_dump to set it when available. Note that the attack is prevented only if both pg_dump and the server it is dumping from are new enough to have this fix. . The PostgreSQL Project thanks Noah Misch for reporting this problem. (CVE-2024-7348) . * Refresh debian/patches/focal-arm64-outline-atomics. Checksums-Sha1: 925bda7b2c25e7c2d44906e9c4852aa4b394546f 37068 libecpg-compat3-dbgsym_15.8-0+deb12u1_armel.deb 9a7c1f4e53ffd1931bc36bd7318e3012c698353e 20332 libecpg-compat3_15.8-0+deb12u1_armel.deb 0c282556f02e06490f772d33fa879e2b77fe04fc 231252 libecpg-dev-dbgsym_15.8-0+deb12u1_armel.deb f1c8ccb31a4b3f17acbdae65ad3f9c52614f7911 271472 libecpg-dev_15.8-0+deb12u1_armel.deb 31fed0e5dd0cdb3429abb39d60f77d000e9d5b63 110684 libecpg6-dbgsym_15.8-0+deb12u1_armel.deb 7b6142462e38879d63ac00c41b492c122df391ce 54444 libecpg6_15.8-0+deb12u1_armel.deb 403ec796ee97bbd2a9f82e97d5ba39224dbd73a7 86552 libpgtypes3-dbgsym_15.8-0+deb12u1_armel.deb 5e15cbc970207a4baaa96bc251d9f7c16630336e 40728 libpgtypes3_15.8-0+deb12u1_armel.deb 7f4c037e873a922d255670841da20f14d3fd9b0b 132192 libpq-dev_15.8-0+deb12u1_armel.deb 5bf6d961910562b005ca21d73ab3f3077d3296c1 269664 libpq5-dbgsym_15.8-0+deb12u1_armel.deb 4f5d90e4b5608dc4f610e97bfb1828818c49c650 168936 libpq5_15.8-0+deb12u1_armel.deb 99eca7cb5ab6bdc4d2e98267727cf7f0613bd661 16107980 postgresql-15-dbgsym_15.8-0+deb12u1_armel.deb c673fa139b630d29a79ef0770102716d6906d0f9 16802 postgresql-15_15.8-0+deb12u1_armel-buildd.buildinfo 622455b32a0148defde02b021ebac3284c471c55 16103700 postgresql-15_15.8-0+deb12u1_armel.deb bc1892a2c1b2ad591f9e90f6fecfc050301085f2 2225240 postgresql-client-15-dbgsym_15.8-0+deb12u1_armel.deb 2f28f3cd570ee8d6df506a9b49021a441e07bf51 1602808 postgresql-client-15_15.8-0+deb12u1_armel.deb 03b8f8cf65f9853ee7177d9417ead33e71778ed0 181880 postgresql-plperl-15-dbgsym_15.8-0+deb12u1_armel.deb 821097217a57008058c1d6630151660f84da6b79 86064 postgresql-plperl-15_15.8-0+deb12u1_armel.deb 7ef6b72d7d84cfdc6038132f49d6a7bf22fb2279 171436 postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_armel.deb 8582bdfd7081d3a5ddd76e5d4775bb0a7fdc15ee 105064 postgresql-plpython3-15_15.8-0+deb12u1_armel.deb d19871549ab987fd5cac44b81a9c49710eb517b6 77988 postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_armel.deb d563d0fd65d8a55062aaa653fe005740d7de659c 39036 postgresql-pltcl-15_15.8-0+deb12u1_armel.deb 148b3f20ce7f9e619da0f76c2587eba6a51cd724 1127840 postgresql-server-dev-15_15.8-0+deb12u1_armel.deb Checksums-Sha256: 981e53099f696d052fd6ed9c4b83bd2d5913c6664fdd7bb077329e9a14a01d3e 37068 libecpg-compat3-dbgsym_15.8-0+deb12u1_armel.deb 58f77dc64628242be56b418c42ac68827115fbdce1200f4a9a11a685e034d243 20332 libecpg-compat3_15.8-0+deb12u1_armel.deb f8bd52c13464ac78bb2da6e9602f9caa336c2c1888958ab079e9fd656b419c3c 231252 libecpg-dev-dbgsym_15.8-0+deb12u1_armel.deb 7ed22909a127ec25066b6220f6ec8297f4d22287addf119503da0dc4e820b181 271472 libecpg-dev_15.8-0+deb12u1_armel.deb 69c09cf94e3e0b6f2e0f7c4acfa44cf8506c89fea8dc1690469ca9fc1213cf67 110684 libecpg6-dbgsym_15.8-0+deb12u1_armel.deb c8901f434b251581e4d60b60a4d5fe7aa72e9669825991d74f450f0872f61d6b 54444 libecpg6_15.8-0+deb12u1_armel.deb 8ceb9fe051251637d490c7e90f517368ab675da14aba5033ba460c04e3aee1cd 86552 libpgtypes3-dbgsym_15.8-0+deb12u1_armel.deb f9c27fb05fb9ff59a0938fec05d350fe7741b2ed89a097d3a67bcfed24a65257 40728 libpgtypes3_15.8-0+deb12u1_armel.deb 7d1851e2083cdcdc0f1797f6663779c6ceb9ac4d4dd7bc3056a9486044ef0c78 132192 libpq-dev_15.8-0+deb12u1_armel.deb dcda4fb9dac7763cb416ade10f0beea19d84b86f51883806dc458f0c8a06caf9 269664 libpq5-dbgsym_15.8-0+deb12u1_armel.deb aee84090d5b4ab6a206a92b551270946fa208d2492a98c514834ce6c882e9835 168936 libpq5_15.8-0+deb12u1_armel.deb 1ea997d67fd19660a485dfa7786ce6c33514be6c223562533a85c6004cd032be 16107980 postgresql-15-dbgsym_15.8-0+deb12u1_armel.deb 87d434de73f075db35a92ccd6624367056b8ce2cf6751ee6b2503fd2a297014f 16802 postgresql-15_15.8-0+deb12u1_armel-buildd.buildinfo 8a23df558357c09dc631bfa485c157b756cca9c2bba226b927cb2af6fa836db6 16103700 postgresql-15_15.8-0+deb12u1_armel.deb 208d120c999f8c1bbcd7f23ed2a73a6ab3ae64a15bdd81a3928615bed4e8c311 2225240 postgresql-client-15-dbgsym_15.8-0+deb12u1_armel.deb 9d814d086ed553023d169be81de3970a53c7db0d362f60c7962778741e4b5a32 1602808 postgresql-client-15_15.8-0+deb12u1_armel.deb 3cd4b3cdc2be15ed1ddd1127621b12308c40fd354a6e0b888f7dcd1aaeae1a29 181880 postgresql-plperl-15-dbgsym_15.8-0+deb12u1_armel.deb fcc4cd4902209ca764b98385c5b447ee0ee281f9e88b28ae1da75a4ca127afc4 86064 postgresql-plperl-15_15.8-0+deb12u1_armel.deb d3bdca677f09de64befc8ff26b58595ea94dad9375e419cdca4556dd95786286 171436 postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_armel.deb f110cd88bfd4dec12acac07939b69e3b625044af597f4dff369c0a5e9e26f689 105064 postgresql-plpython3-15_15.8-0+deb12u1_armel.deb 36d9751f60c72124a2cf5353330c5cc88caf8ef9a21c22da78d70bb8083c6a50 77988 postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_armel.deb 4a0a6d5a72c6f4c8cacdf1b9e405c6f1d4b9e583803cae05c81aee73b7f5b154 39036 postgresql-pltcl-15_15.8-0+deb12u1_armel.deb 9d75d23cee82512e01a43ef9000eed4ea8a18cc766feb289706cb5d20d45e86c 1127840 postgresql-server-dev-15_15.8-0+deb12u1_armel.deb Files: 3413737efc19dd0b0ebe17e67d1badcf 37068 debug optional libecpg-compat3-dbgsym_15.8-0+deb12u1_armel.deb e0c1c8ca231c001239d1e4bdc5f893e1 20332 libs optional libecpg-compat3_15.8-0+deb12u1_armel.deb 5943e53c2c1898bbf0a62b5a8f073251 231252 debug optional libecpg-dev-dbgsym_15.8-0+deb12u1_armel.deb 80ec0f44de12da304bdeacaaef99c59e 271472 libdevel optional libecpg-dev_15.8-0+deb12u1_armel.deb d0cf341335f6702e76620c65dd23f7af 110684 debug optional libecpg6-dbgsym_15.8-0+deb12u1_armel.deb e60d2c39c26b43ca8397be31922e2523 54444 libs optional libecpg6_15.8-0+deb12u1_armel.deb ce9cbab919b8c007b2af12d9d486903c 86552 debug optional libpgtypes3-dbgsym_15.8-0+deb12u1_armel.deb 9b2495473cab16467531e90ee842086f 40728 libs optional libpgtypes3_15.8-0+deb12u1_armel.deb 18692037d8a100c7d2deca95e879509b 132192 libdevel optional libpq-dev_15.8-0+deb12u1_armel.deb b114ac7cc11de955d91199672edbba7f 269664 debug optional libpq5-dbgsym_15.8-0+deb12u1_armel.deb ccefd99b9562f75b1b2d5bf528d8e680 168936 libs optional libpq5_15.8-0+deb12u1_armel.deb fada6ac22a317c1c66f463e9c1408a28 16107980 debug optional postgresql-15-dbgsym_15.8-0+deb12u1_armel.deb db4d0cd10d666d99bf59e45fcae8a2e6 16802 database optional postgresql-15_15.8-0+deb12u1_armel-buildd.buildinfo a5cf5ed2c4378da11c746762e9ed07e1 16103700 database optional postgresql-15_15.8-0+deb12u1_armel.deb 1076ded718ec32acc12a07d433a9d3ff 2225240 debug optional postgresql-client-15-dbgsym_15.8-0+deb12u1_armel.deb 8891ce37ffacef8bd5bc169ddc8c69de 1602808 database optional postgresql-client-15_15.8-0+deb12u1_armel.deb ca9be0b0cb802dcb9b17e4ee075fc718 181880 debug optional postgresql-plperl-15-dbgsym_15.8-0+deb12u1_armel.deb 22a11bf4e972efd9b03ee80ac1e10c25 86064 database optional postgresql-plperl-15_15.8-0+deb12u1_armel.deb 687bcec9f17dfeaff83db21186d13791 171436 debug optional postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_armel.deb 82b998d341e4a4b0e5bbed96f3dc56f8 105064 database optional postgresql-plpython3-15_15.8-0+deb12u1_armel.deb 431dea10df28a88774ec71ddb7107853 77988 debug optional postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_armel.deb ef1b3fa25855df31fc43af41c9e9099d 39036 database optional postgresql-pltcl-15_15.8-0+deb12u1_armel.deb b00644f04b3e8e3b84ba516a6f541c41 1127840 libdevel optional postgresql-server-dev-15_15.8-0+deb12u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEErcTbumGV7Ig2iXlfQdxRZ9J7nEgFAma09sQACgkQQdxRZ9J7 nEh4BA//fsGD5gI6I0PH6blw08RpGJ0CtE7UhXyEPvA618heQGuLYb2qXLFey1jq bxNnCuYs+7pVqygNg0DK7tkMgbT4keu83UsNEF3PK+/jyA7gWPxqZibw5q7P8+Ot CIafRYKMZFchplxkEunOLI+zGKfJH3fgAn5IXc58QGOt9vgp2Yej9M/+VtJtgfi4 xNOizBy2XOUVkqdW6EB5tOUkvrtqcp8y2SmtBo/m99bfhjNXo+v9TUGVEQJPLKUX x2zUqae3fAHWT9I7goshdtmDxp+1z2fJZefsFVFEmfc6goec3FAZfrwfgK9mxAim l+lNLsxj3qoLvqjPtftLw6hV2UUgeMsYVbiQ0xHJlG7aG4mx9KUMWOosyZL/ayNY npxEeMC28DUJCaBw5MwI6OVYKo+/37wnc2xouEyqpozNVMuRRP/cmPheqg5XaMQw O1z3wNbsgxPPIUtS3Fl2RLhqqGx/PLCxhb/6R5w9Pbvt5Lz3CjbHtzI3YoZjPhNu ZVQvxZVgzspnw9U8gv93a44w18JrWhFc7AujEcSmzK7NfR4rXdoT+F5FZjRttK0F bUSdxZfXsaV7kMU9YdkYCCPD2N8xDAFd8FzFQuW5Q++r+uE70yljAOxbPXdfjgZX EyrW2VKHFSSNc6rd3pnU4GTrbcDnahJO26g2n48E7dLV4lPfqaA= =EDdx -----END PGP SIGNATURE-----