-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 15:24:37 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: armhf Version: 15.8-0+deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: arm Build Daemon (arm-arm-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.8-0+deb12u1) bookworm-security; urgency=medium . * New upstream version. . + Prevent unauthorized code execution during pg_dump (Masahiko Sawada) . An attacker able to create and drop non-temporary objects could inject SQL code that would be executed by a concurrent pg_dump session with the privileges of the role running pg_dump (which is often a superuser). The attack involves replacing a sequence or similar object with a view or foreign table that will execute malicious code. To prevent this, introduce a new server parameter restrict_nonsystem_relation_kind that can disable expansion of non-builtin views as well as access to foreign tables, and teach pg_dump to set it when available. Note that the attack is prevented only if both pg_dump and the server it is dumping from are new enough to have this fix. . The PostgreSQL Project thanks Noah Misch for reporting this problem. (CVE-2024-7348) . * Refresh debian/patches/focal-arm64-outline-atomics. Checksums-Sha1: ba70ecf97333dae7c40368fd07482126436d8f1f 37656 libecpg-compat3-dbgsym_15.8-0+deb12u1_armhf.deb c80a9bf4db52f8924091b0165608e45f4387b087 19948 libecpg-compat3_15.8-0+deb12u1_armhf.deb e1e280e5e2f81632596e30034e1da6152671ccff 234860 libecpg-dev-dbgsym_15.8-0+deb12u1_armhf.deb 426c09a8f6c39f9d99aff9f22bad8e887cc88598 276400 libecpg-dev_15.8-0+deb12u1_armhf.deb 07ee080ce12fe33f4e933053d945bbf91e123c8b 111636 libecpg6-dbgsym_15.8-0+deb12u1_armhf.deb 9b1b2477156118e42d1f8216f65b86ad4eb68410 52904 libecpg6_15.8-0+deb12u1_armhf.deb 849fc41526d4d61f93ccf40790df4df6814498b8 88584 libpgtypes3-dbgsym_15.8-0+deb12u1_armhf.deb eb46ef4d55c367de249399f46a25c08166127ff9 39792 libpgtypes3_15.8-0+deb12u1_armhf.deb 7694bb0399aa4fa89cbabe961b456679d918868b 132084 libpq-dev_15.8-0+deb12u1_armhf.deb 5499f42fff0e630c412e8ab35f5a019ff3313293 273648 libpq5-dbgsym_15.8-0+deb12u1_armhf.deb a72718692ee7276381abd084fe8f0d48d30d399e 169420 libpq5_15.8-0+deb12u1_armhf.deb 9e5e3c197d489915e6e11aecf3b72276e642c251 16167664 postgresql-15-dbgsym_15.8-0+deb12u1_armhf.deb 8c76e94ce7292aa4f0a7b56ffca503f9226f657f 16804 postgresql-15_15.8-0+deb12u1_armhf-buildd.buildinfo 59d5fbfcea584ca09b9dec2e00c5cc8789b547dd 16042692 postgresql-15_15.8-0+deb12u1_armhf.deb e9121858733922dafbf144ab0f866194f3a80c63 2241604 postgresql-client-15-dbgsym_15.8-0+deb12u1_armhf.deb d834d6c470d6a0f770ceb4a4ad6a264eaac44f7e 1617984 postgresql-client-15_15.8-0+deb12u1_armhf.deb cd0e28b9558a67abcb8c9a3416c922b3f58caca1 182804 postgresql-plperl-15-dbgsym_15.8-0+deb12u1_armhf.deb c9ba474abd89df8a24c4e4baeb6715ea425dddac 85956 postgresql-plperl-15_15.8-0+deb12u1_armhf.deb 59a4b5cc63551e0b27c8a089d9620015b74afa3a 172180 postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_armhf.deb e3f6d54c576973b2608d8ce2ad76b8d0d6a3fa87 104384 postgresql-plpython3-15_15.8-0+deb12u1_armhf.deb b3a12b552b13216e97c646ba3931f2c9e03ae392 78272 postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_armhf.deb 63b86bfbc9263394e1e155b4b2994c2ff32f3a3a 39032 postgresql-pltcl-15_15.8-0+deb12u1_armhf.deb 309b4c09df308b0c188dcb87f950f2835b2c318f 1125440 postgresql-server-dev-15_15.8-0+deb12u1_armhf.deb Checksums-Sha256: d4cf150b3a2b306c51f629e48b51704bad98ab8859e509ae14db3066760359ef 37656 libecpg-compat3-dbgsym_15.8-0+deb12u1_armhf.deb 5aed351b7d8d591846b2e776d6f15796fecdb2232d48105e0dbe8bb12ae39626 19948 libecpg-compat3_15.8-0+deb12u1_armhf.deb f692ba0e4d9edcc88a446adbe7b96d806df2843015fcb0d083ddab18f356119b 234860 libecpg-dev-dbgsym_15.8-0+deb12u1_armhf.deb ad8812f38f3a60703d627fa3591ad4526b43c2d892bead02c677167240c243cb 276400 libecpg-dev_15.8-0+deb12u1_armhf.deb e0241be08f8c612113c41f1204e318b15b768689cb17394353ae52459ec5a55a 111636 libecpg6-dbgsym_15.8-0+deb12u1_armhf.deb b4b405c14aaec45f1f84e03bac8483fb2987c30d36e76a61498839ff48c8dcbe 52904 libecpg6_15.8-0+deb12u1_armhf.deb 2a51add5b70d0e550d9a9de380f7396288d00c55a0567e9e4e4f7c1265590be4 88584 libpgtypes3-dbgsym_15.8-0+deb12u1_armhf.deb 000c32789e91407beb0a371598516851027a3662506af0379a6c04add8534fd5 39792 libpgtypes3_15.8-0+deb12u1_armhf.deb bb0715a6f7aae4eabdbb1745431ebb772d584f69d8d297a5d2665dc551330a7d 132084 libpq-dev_15.8-0+deb12u1_armhf.deb 5db5f54f9a6a87e262740ddf2b1f735dbd5102d8f3bf7ce8d3c782d301379d09 273648 libpq5-dbgsym_15.8-0+deb12u1_armhf.deb 3f815e10268f0d67664bc4885a214f1dfef92dfade5a1cd74bd165bfed9316b3 169420 libpq5_15.8-0+deb12u1_armhf.deb eaf255a15c5e73925684bf811619f08ac23ddd63cd6b3a5b004e35ef07c8f82c 16167664 postgresql-15-dbgsym_15.8-0+deb12u1_armhf.deb ba38638d3bf481ce540c47025625b932aee7afea546da68d67fbed83f1687cdc 16804 postgresql-15_15.8-0+deb12u1_armhf-buildd.buildinfo 8920a1a50755b870f6e38fc5390fd9f1fe21b2399d41ab1ab4a32e8c3868a215 16042692 postgresql-15_15.8-0+deb12u1_armhf.deb d7dfa0ab34022c71752e8adb6e3508278efc18d28607cea7cb5d27dc6752fff0 2241604 postgresql-client-15-dbgsym_15.8-0+deb12u1_armhf.deb 1bb0a8d68973a244e2a2db5fa59de06fbdc4a55b8b01210ec8579e62155eebec 1617984 postgresql-client-15_15.8-0+deb12u1_armhf.deb eca61c3b085cf7f4cb0ee4dba5d87c5278bf1af2e52b4b7a853ec8bd425f8d23 182804 postgresql-plperl-15-dbgsym_15.8-0+deb12u1_armhf.deb cd874e6a04bb22ff37420fb427992e7125bb6957b1daf52b1414becf08a72822 85956 postgresql-plperl-15_15.8-0+deb12u1_armhf.deb eb877b12467df9e1fed6cd6d77d0a253364c69a6a6b60be9b9241f733c119b9c 172180 postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_armhf.deb fc5f6fab558f54661e60869f45571f96924b5f340b4804d701e3eb6ba235434d 104384 postgresql-plpython3-15_15.8-0+deb12u1_armhf.deb e1c2d0db3d810c6ff81d4249c49150748c79a0a6d3fd201528fe2d6488ea3187 78272 postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_armhf.deb 05d4b57e2155662cf6c5c41d79abaf574c603f38b6004540e38fd330c92d4ef0 39032 postgresql-pltcl-15_15.8-0+deb12u1_armhf.deb 9b154be8aae3a287672689ab0d3299c56e750eaae186e88f75a89784946a4b09 1125440 postgresql-server-dev-15_15.8-0+deb12u1_armhf.deb Files: 9c47a62e95e06013b28b9e4ad15c6b35 37656 debug optional libecpg-compat3-dbgsym_15.8-0+deb12u1_armhf.deb 6e3eef2de6b8646ad75086a535fcae8f 19948 libs optional libecpg-compat3_15.8-0+deb12u1_armhf.deb 9588b1fa817cbae88cb142f95f3fd447 234860 debug optional libecpg-dev-dbgsym_15.8-0+deb12u1_armhf.deb f44c1dd4cb0e21d485270fb3bba6c8ed 276400 libdevel optional libecpg-dev_15.8-0+deb12u1_armhf.deb b86be9a664e50065e8adb6f8a831e353 111636 debug optional libecpg6-dbgsym_15.8-0+deb12u1_armhf.deb 565279a0dd499fc4a93dd9f88d773979 52904 libs optional libecpg6_15.8-0+deb12u1_armhf.deb abf915eca569316d83f0cb6f4df0ea43 88584 debug optional libpgtypes3-dbgsym_15.8-0+deb12u1_armhf.deb 4d9e3d259cf1e027bdc3422c304c5f89 39792 libs optional libpgtypes3_15.8-0+deb12u1_armhf.deb 73561c714407a356f3a2a74749bb3cf0 132084 libdevel optional libpq-dev_15.8-0+deb12u1_armhf.deb 3e7661321e4d679ccd9ff550c7c8f944 273648 debug optional libpq5-dbgsym_15.8-0+deb12u1_armhf.deb 7fda4fbd6318de81df6296bc6ca00039 169420 libs optional libpq5_15.8-0+deb12u1_armhf.deb 40398e6dff02f7a79d45f12d04506dc6 16167664 debug optional postgresql-15-dbgsym_15.8-0+deb12u1_armhf.deb ebbcb1355c12981477c1780d2a6538ee 16804 database optional postgresql-15_15.8-0+deb12u1_armhf-buildd.buildinfo 9236c39a7506732a5fa32fef0ed0fa36 16042692 database optional postgresql-15_15.8-0+deb12u1_armhf.deb 0fabdccb6c662a7132e96a768b6d72d6 2241604 debug optional postgresql-client-15-dbgsym_15.8-0+deb12u1_armhf.deb 1e6e8adb7bf83217b0554ecd15ea80b7 1617984 database optional postgresql-client-15_15.8-0+deb12u1_armhf.deb abc0fb453e56832b227c3fb541168325 182804 debug optional postgresql-plperl-15-dbgsym_15.8-0+deb12u1_armhf.deb 65f21831af8fd92a4c7572f2ebeaa0cb 85956 database optional postgresql-plperl-15_15.8-0+deb12u1_armhf.deb 45f0d54fa3a2f94de4d3f9fa723fc3b2 172180 debug optional postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_armhf.deb 81c0871db3c605e83067a146d11dce90 104384 database optional postgresql-plpython3-15_15.8-0+deb12u1_armhf.deb 8ec73b723926a6a55664813c9a0d50d9 78272 debug optional postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_armhf.deb 6109f23a11df3b1df764a545ae83becb 39032 database optional postgresql-pltcl-15_15.8-0+deb12u1_armhf.deb 0cb190c94322b1c3dca7c406e7a3bc08 1125440 libdevel optional postgresql-server-dev-15_15.8-0+deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEELfAsbDZr65zRgOsKct6XE2dptMYFAma05iEACgkQct6XE2dp tMbSHhAAukkINgajKp2YiBBy2fEV+crfThDwImziX02du8lJIFA8PW9QojO5/gUw 6VhQld/ExoTd82+ez2TGNjejmC/DC01h149vRBsCbqLzSnfcOzMbY5TNMvjLC3cQ Qj2minp0jBaxhWUemePkUzLra7s1Ubknj4s1kibDeYsiZI6d2CV5fcBEO/zLxU/g Q14rcvTcOiV3LZmTM7sCfexJhtT+pzmY7VQ4HP7LZ2Oha5ykcXheHeC7kTQYdqtx XSIva80wvJwmxqE7glQY0Pt7H2dQ4ST+m1KO+4/Jk1GzJnBxOMKXC6VFOeAtKntF CpDP3HAqE6ZibJ7uGGkEmAcavzFxDurpn05G9q2/43aVX0rqYvHpD8lipcmsQcgn baVDU9yNXzLG3FmSNV+puVKu4brX4NPhJ5M1cO5+MBy6CSUe/b/XSvAk98j2XJIV KbJ20qdXYubOOFndBFFJmZheaojgkbF3/PK183irJMxsNX3TP1A0fn5tRhcROHAx W1SGIE5QjD2Eq50e15RJEuw6nC6GJUbGQfPDGP94oU5LTXc/B5+xRkbIWjN3ZCa/ irrzDJHbiz0Sx4cYAeaMeyqWau8DRX1Hhm32jnrDlrx4Lg3U7OXvxov2bf3z5kB5 gjY3NhaJ+OCxSG7vH6lwyfD1Fs5nn5kLLB018zkhfHV6ZnhTbjw= =/Qpy -----END PGP SIGNATURE-----