-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 15:24:37 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: mips64el Version: 15.8-0+deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-03) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.8-0+deb12u1) bookworm-security; urgency=medium . * New upstream version. . + Prevent unauthorized code execution during pg_dump (Masahiko Sawada) . An attacker able to create and drop non-temporary objects could inject SQL code that would be executed by a concurrent pg_dump session with the privileges of the role running pg_dump (which is often a superuser). The attack involves replacing a sequence or similar object with a view or foreign table that will execute malicious code. To prevent this, introduce a new server parameter restrict_nonsystem_relation_kind that can disable expansion of non-builtin views as well as access to foreign tables, and teach pg_dump to set it when available. Note that the attack is prevented only if both pg_dump and the server it is dumping from are new enough to have this fix. . The PostgreSQL Project thanks Noah Misch for reporting this problem. (CVE-2024-7348) . * Refresh debian/patches/focal-arm64-outline-atomics. Checksums-Sha1: 39215169d838e7b6f36849767cc7b18883c5806f 39776 libecpg-compat3-dbgsym_15.8-0+deb12u1_mips64el.deb 9c2afb3435b80b682c2c195162a34684b2777c5b 21688 libecpg-compat3_15.8-0+deb12u1_mips64el.deb 1042c7f9fa3ea7b76b43e4605744ef892d8226b0 250072 libecpg-dev-dbgsym_15.8-0+deb12u1_mips64el.deb 5a7d2c8f91d3c275cec2c1671797ce0d203b6b14 285688 libecpg-dev_15.8-0+deb12u1_mips64el.deb 8712e62f6f44c49d9d90169011fff94bb0a28a5e 116740 libecpg6-dbgsym_15.8-0+deb12u1_mips64el.deb 14190ba8645927007dc93b2bbe77fc95d0aada71 57504 libecpg6_15.8-0+deb12u1_mips64el.deb d13e77577b339fec18dd99ca110beab6d8368330 92536 libpgtypes3-dbgsym_15.8-0+deb12u1_mips64el.deb 04541b8b8f898fbdd41899bcb9cfb7999664d49a 42660 libpgtypes3_15.8-0+deb12u1_mips64el.deb 30639cba4fb3b0878b831f9efcc2bbece92113fc 149404 libpq-dev_15.8-0+deb12u1_mips64el.deb 550270a0674ecea4857d8cb4a16bdef6b7349d2b 286236 libpq5-dbgsym_15.8-0+deb12u1_mips64el.deb 6749ffc08d2347629ce8106420b0a38b91c4c3e0 176692 libpq5_15.8-0+deb12u1_mips64el.deb 8db2cdbf2c5403a0f98afc0c222477ce5d78f55b 17022800 postgresql-15-dbgsym_15.8-0+deb12u1_mips64el.deb aa81d8c2cfe7fb5d457d7ff1ca2e4a79404c4a70 16961 postgresql-15_15.8-0+deb12u1_mips64el-buildd.buildinfo d7e23ae2cad911e3287878454fd40f9192332d64 16337816 postgresql-15_15.8-0+deb12u1_mips64el.deb 951ba3eafe28e5295cd6c5d2f8ceee06cde4ffe5 2404176 postgresql-client-15-dbgsym_15.8-0+deb12u1_mips64el.deb 6736c9d80a07a845e4759ae1be8ee80973b1a3f4 1645688 postgresql-client-15_15.8-0+deb12u1_mips64el.deb 3f71950bae402471ef335cab75d88c2432735b02 190120 postgresql-plperl-15-dbgsym_15.8-0+deb12u1_mips64el.deb 80e50529f85cdba016083333be2af672e3f8c2f3 84672 postgresql-plperl-15_15.8-0+deb12u1_mips64el.deb 0c410071e13281b8c3b0885ae64963dd1e965a20 182488 postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_mips64el.deb 9a165dd3646bd4870106738f6c3e3060d32d1223 103756 postgresql-plpython3-15_15.8-0+deb12u1_mips64el.deb 25ffcd1b1b4f8f574d1b3a8828279e479068aa90 81356 postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_mips64el.deb 69d5a74b33f09068e9b80ace728ccd8ca43a17ed 39048 postgresql-pltcl-15_15.8-0+deb12u1_mips64el.deb a27f977818f8d5af681eb7f563a00bbf4cd7fd4c 1149268 postgresql-server-dev-15_15.8-0+deb12u1_mips64el.deb Checksums-Sha256: 4905ed75cbe95a8d04a6167600619002268d158b964813e5cbbc22d932cb5ba0 39776 libecpg-compat3-dbgsym_15.8-0+deb12u1_mips64el.deb 0cfc900e442d5ec7bdb48ba08ad25faf5e93c0bad3079be9e019eb4546c409fb 21688 libecpg-compat3_15.8-0+deb12u1_mips64el.deb cecdc96678be77838283bdff79281015b3fb8a672d7c36bfa48e2ae5ec7ce8ca 250072 libecpg-dev-dbgsym_15.8-0+deb12u1_mips64el.deb b04bd6fc9238c245f322e34ed5d0ee16c4c3084626031a2cb93c87b652f5a989 285688 libecpg-dev_15.8-0+deb12u1_mips64el.deb c8b49fb4e7551b66b22bb7fd1c4189d666f7547f731533b6e215feb29573ca17 116740 libecpg6-dbgsym_15.8-0+deb12u1_mips64el.deb f7fe0d670ed078b05347e9fd2dbda9558aff87343abb03a8a172a032e5defd72 57504 libecpg6_15.8-0+deb12u1_mips64el.deb b82b0ef431f3564d345ca496cba7bab5a21bb9a73c821ee98c9985bb4c98e98d 92536 libpgtypes3-dbgsym_15.8-0+deb12u1_mips64el.deb b517af0cd76a6c772c321f51333cfe01c07e075f1ef7762cf0ae797365868f21 42660 libpgtypes3_15.8-0+deb12u1_mips64el.deb 0c58a6f31937913764b10e937679fc1f8ccb01499ccf7ea7738f2a14dfb074a7 149404 libpq-dev_15.8-0+deb12u1_mips64el.deb a6b76ca328b8b075d367843466fe1f7c086427fa44e595f0d3b0495ba73500cd 286236 libpq5-dbgsym_15.8-0+deb12u1_mips64el.deb fdc72d5aef4487778af78e0439953e74170ce53b44637c047018b243d48a94db 176692 libpq5_15.8-0+deb12u1_mips64el.deb 5f88a443839af46e256817a409774d654b9843c5819f9f224bdd9a5ce4b0426e 17022800 postgresql-15-dbgsym_15.8-0+deb12u1_mips64el.deb f2d44fb6789b212ecc6ed82b16b4862a6c0572f3a08aa27861a58c105af68e2f 16961 postgresql-15_15.8-0+deb12u1_mips64el-buildd.buildinfo 2a222c9ff4264633e5a72a8535e93daeb5b06cc3e4695d828be81f4d9879e078 16337816 postgresql-15_15.8-0+deb12u1_mips64el.deb 2c6fea41fb419ff5ac8bf7ebd8d68882e965f48b5dc17e4c86efc5ba1e52d74f 2404176 postgresql-client-15-dbgsym_15.8-0+deb12u1_mips64el.deb 9d5b7d548a5fbbfab6f1dbd9eba396cd7a00de00d1f3f0baead3ca4b9b32a7bf 1645688 postgresql-client-15_15.8-0+deb12u1_mips64el.deb 3fdc9aa57d5280f179a6a74e0fb4b836e1974134f5b31862055568a94422c7d9 190120 postgresql-plperl-15-dbgsym_15.8-0+deb12u1_mips64el.deb 571b7165c397891b8d35dc72c4844b8bff0e11130ca8713425f9478e0113d7ae 84672 postgresql-plperl-15_15.8-0+deb12u1_mips64el.deb 53cc6412dcf12e9e21ab36d819029ce8f4df1919df3edd6d3f12077ac205af3e 182488 postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_mips64el.deb e39b28b76a01656266df9192e3899967eeed1f9d52f3f0d634ad7dfbe4b7f75b 103756 postgresql-plpython3-15_15.8-0+deb12u1_mips64el.deb a38355571823cde3130de909f08dcd2cfe0a865fec8cc02aa61703c6e9beb7ef 81356 postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_mips64el.deb bfd77234901aad0e9ce5ec204edaa2e6cb988fc709e11065a189620e4f66bf64 39048 postgresql-pltcl-15_15.8-0+deb12u1_mips64el.deb 805c0f39d0ebf5d7f6c6716d425ce94975b7daa282148023777a9fbba06cf478 1149268 postgresql-server-dev-15_15.8-0+deb12u1_mips64el.deb Files: 03841bb84f56dd0b46ac03a0702f05f7 39776 debug optional libecpg-compat3-dbgsym_15.8-0+deb12u1_mips64el.deb 892725fe2ee11793c31a119e896ab756 21688 libs optional libecpg-compat3_15.8-0+deb12u1_mips64el.deb ee07fb95175c5823e1def564df91061f 250072 debug optional libecpg-dev-dbgsym_15.8-0+deb12u1_mips64el.deb 4dc2639a5342f36c21c8a6d6fc7555f0 285688 libdevel optional libecpg-dev_15.8-0+deb12u1_mips64el.deb d878545f5560b86f988886f1922ecbad 116740 debug optional libecpg6-dbgsym_15.8-0+deb12u1_mips64el.deb 519400269080fb6d8694308c2df1ea99 57504 libs optional libecpg6_15.8-0+deb12u1_mips64el.deb ec3dea4b4a1737a4a891204c246c24ef 92536 debug optional libpgtypes3-dbgsym_15.8-0+deb12u1_mips64el.deb ca5b069b14f8b6ce72166223fec1f339 42660 libs optional libpgtypes3_15.8-0+deb12u1_mips64el.deb 50b5c5ddaabdba50e477fef032d6793e 149404 libdevel optional libpq-dev_15.8-0+deb12u1_mips64el.deb 0e8b559f8820eb43a443be95e1fb47c0 286236 debug optional libpq5-dbgsym_15.8-0+deb12u1_mips64el.deb aa609c93bd8bd45be0a83acf7218514d 176692 libs optional libpq5_15.8-0+deb12u1_mips64el.deb 06451eb79564cc2e06adf646e4f6add6 17022800 debug optional postgresql-15-dbgsym_15.8-0+deb12u1_mips64el.deb c78f469fd8ade6f3c26e53908abd6890 16961 database optional postgresql-15_15.8-0+deb12u1_mips64el-buildd.buildinfo e1f4e240462fd56a51c22e2013e8a000 16337816 database optional postgresql-15_15.8-0+deb12u1_mips64el.deb 757304891c506e5adb7c1bf4240eb611 2404176 debug optional postgresql-client-15-dbgsym_15.8-0+deb12u1_mips64el.deb ea6244ab8ad15e3388af7460cc0cfac0 1645688 database optional postgresql-client-15_15.8-0+deb12u1_mips64el.deb dffdd850aec0e47b7b7e4df1851c4a71 190120 debug optional postgresql-plperl-15-dbgsym_15.8-0+deb12u1_mips64el.deb dbc51e0d30cff7ca8bcf6ca19183c409 84672 database optional postgresql-plperl-15_15.8-0+deb12u1_mips64el.deb 69fcf8b3e352c6cb6c7b623cd2f02a9a 182488 debug optional postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_mips64el.deb 0c973890e5f9b8352dcc5d0fece0868c 103756 database optional postgresql-plpython3-15_15.8-0+deb12u1_mips64el.deb 6e3118b1aea5561ac315beb58c2c5850 81356 debug optional postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_mips64el.deb 01b5ba4511099294ca5d1277e559610c 39048 database optional postgresql-pltcl-15_15.8-0+deb12u1_mips64el.deb dd7bd4be8a9c8db275c4ae2b25c97cfa 1149268 libdevel optional postgresql-server-dev-15_15.8-0+deb12u1_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEunmvxaaGKuI+hxxClmZGXOM83t8FAma07OIACgkQlmZGXOM8 3t8pvxAAiy/JlLZTkwkPIGXucQAKyaLCKHG8kk6vJlLRol9fSiWOp0Qb5J/+ZOCD 6ukusRZApX1eix2Vaoun9C22fBll08uv+QVzDLmCq0HZJUhp4ZiLnpGiuTCVve1Q 6snS8lJzoTYkH/7WxTSB0WPsZ6mi73TiOZUOarrImQDo2RiZytTXQknpp5e1+F2r GQbYKfRjlvYSWbH690Kg5FwEmt6kO3ncAJAMIKUoEqTA8AjJAghBOl4t89X2rt89 cbB4qlLGgSEBJgL5tdC9vcRg3d+nqP0EBX0m5c/bnkNC2cE0zGcR4KRXubI9aMNq B5m7U1KjKpH4KVaECqcGctPFg72mMPF2g03EGiG0I/p9RrNkIMnjeYjr5OmGhS9c KHFBmr0zzq1xhNu5w7mzjb14enSldM2V9VD/+dHeeRAxp6TKDK1ZlgTGF9UwfkGm 1jknho2/sFi4Vw8fkMYz4iZ3322jc+gfTb7wL/fGf27ciGkB3w8Kr1lz/G4GZcxa ZWccOgW/qScXNiT7FS4QaM58WkuCf0TLn2W5M/Ojl4B5jSRKRDLhD9J/o1qNL6R6 NKfovgShjoJ7e8pNHv5qZJGjE5g9VhYJItmdr4D4+uI9RdUHnRlsuvNDVKvC5zCy CWm73EP/AxTjhDWT4ddzHEG5TI3dqgT+s9SyF7QbE5dqpKmmVPs= =o2Mv -----END PGP SIGNATURE-----