-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 15:24:37 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: mipsel Version: 15.8-0+deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: mips64el Build Daemon (mipsel-osuosl-02) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.8-0+deb12u1) bookworm-security; urgency=medium . * New upstream version. . + Prevent unauthorized code execution during pg_dump (Masahiko Sawada) . An attacker able to create and drop non-temporary objects could inject SQL code that would be executed by a concurrent pg_dump session with the privileges of the role running pg_dump (which is often a superuser). The attack involves replacing a sequence or similar object with a view or foreign table that will execute malicious code. To prevent this, introduce a new server parameter restrict_nonsystem_relation_kind that can disable expansion of non-builtin views as well as access to foreign tables, and teach pg_dump to set it when available. Note that the attack is prevented only if both pg_dump and the server it is dumping from are new enough to have this fix. . The PostgreSQL Project thanks Noah Misch for reporting this problem. (CVE-2024-7348) . * Refresh debian/patches/focal-arm64-outline-atomics. Checksums-Sha1: d8af4d091778dd225aaa2ff2f3f6fb8824da70b1 39460 libecpg-compat3-dbgsym_15.8-0+deb12u1_mipsel.deb 98e5b9b7bea80b473a4bd608266e3f99cc05e6ba 21424 libecpg-compat3_15.8-0+deb12u1_mipsel.deb 00ecbf4c1686c0a9219ad7a7a000a0cf84876b90 260860 libecpg-dev-dbgsym_15.8-0+deb12u1_mipsel.deb d03fddec94be214455d64de0d64b95732d97dfe7 282080 libecpg-dev_15.8-0+deb12u1_mipsel.deb 3f9f01662b37642ecbfe0880b9dd0ece38e350dc 115056 libecpg6-dbgsym_15.8-0+deb12u1_mipsel.deb 9985210b37dcb8741c6e374875d28e8cd72cefe4 57912 libecpg6_15.8-0+deb12u1_mipsel.deb 5edcff70e48e7a03844e9a735542c911c642615c 91612 libpgtypes3-dbgsym_15.8-0+deb12u1_mipsel.deb ed475240cb1bc9da113cc0da76cf5a092d725728 43200 libpgtypes3_15.8-0+deb12u1_mipsel.deb 5a5134ab84c31be9af70f96bbdf1e83154d2b929 148856 libpq-dev_15.8-0+deb12u1_mipsel.deb 2f43182694edf9a6871fb0e0534f3d999e1b8a4e 282936 libpq5-dbgsym_15.8-0+deb12u1_mipsel.deb 294cea53f5e54a5206933ba62e6b029cf89d05c1 175812 libpq5_15.8-0+deb12u1_mipsel.deb f3905b22617b6de1375ecf9d4268eb5917f78052 16621360 postgresql-15-dbgsym_15.8-0+deb12u1_mipsel.deb 7ee767df484004d0e0ae6987c2d368286194f1e3 16818 postgresql-15_15.8-0+deb12u1_mipsel-buildd.buildinfo 8210265e9dafa069bcf5f9e65b4f605dfcbe2bc3 16260192 postgresql-15_15.8-0+deb12u1_mipsel.deb 43ba17da96cee08bf46e873752c38729c2f67def 2336612 postgresql-client-15-dbgsym_15.8-0+deb12u1_mipsel.deb bb5efa75288923d55ee9ddc6448ba323cde00298 1644560 postgresql-client-15_15.8-0+deb12u1_mipsel.deb 079d57a5f912893089fddd24db9f043dbb4f65c2 184556 postgresql-plperl-15-dbgsym_15.8-0+deb12u1_mipsel.deb b0e80abf4244e824f741ca8896641e7d523d027f 84548 postgresql-plperl-15_15.8-0+deb12u1_mipsel.deb 2f2791794bd67fac02ca44e20c395457f33eb347 175320 postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_mipsel.deb a50d6c3df8fa9b168abd87b89ac3816bf4d1b380 103260 postgresql-plpython3-15_15.8-0+deb12u1_mipsel.deb b469ac68e0dd3d626b0c4f2f8dc53c18074ab541 80036 postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_mipsel.deb 0443ea2f7018ea0cc5f5ab67743b2eb81aab0708 39084 postgresql-pltcl-15_15.8-0+deb12u1_mipsel.deb b7cbd3102b6540775d3fb9dbc376cac499e9ee90 1149400 postgresql-server-dev-15_15.8-0+deb12u1_mipsel.deb Checksums-Sha256: f8856215be66d22bb51e37e1240146994ff301ea2de510a37d566331cbf37dc9 39460 libecpg-compat3-dbgsym_15.8-0+deb12u1_mipsel.deb 79863f5df1ce790f1fb028497f0cccf2b04d1d46818ba52319900c475ace5ce8 21424 libecpg-compat3_15.8-0+deb12u1_mipsel.deb 3de09a2b09c3142eb2de60dfe9b6ca1206bb3d11b55655184ec931f57aab10ef 260860 libecpg-dev-dbgsym_15.8-0+deb12u1_mipsel.deb 6d68677ac56aff8168196c88fbceba533c281a1c3d06e92e39075519895f9b1a 282080 libecpg-dev_15.8-0+deb12u1_mipsel.deb a9e18e0f5915922f640b64f5ff05420d03abb28b36f902e5b38a70da598ed65d 115056 libecpg6-dbgsym_15.8-0+deb12u1_mipsel.deb e4be8398651b64a057dd42a0b3ff7ca3502c7c18c0c7203d829ab7eb54e92c50 57912 libecpg6_15.8-0+deb12u1_mipsel.deb e6d4b92721590af6f9e5075d74a8062d31496a954a0c33649084042a24b596f9 91612 libpgtypes3-dbgsym_15.8-0+deb12u1_mipsel.deb 3818f3b645c210407abcfb5e4a566f18112d75afa9115bb8b8e3619a39c91dd5 43200 libpgtypes3_15.8-0+deb12u1_mipsel.deb 2ddc2296fa1e3ac97bd7aa011a8fba2b474aceb047299ccf5380c272ddde5923 148856 libpq-dev_15.8-0+deb12u1_mipsel.deb 7ebb57eabb3d01f0dc1568413b0d7cebdb2d3f11949979ba012574d6f66151d1 282936 libpq5-dbgsym_15.8-0+deb12u1_mipsel.deb 5d16de6dab0be1d154364e36985c7dd2f07913779b2da81ea598eea8a7e82340 175812 libpq5_15.8-0+deb12u1_mipsel.deb 2cdf92d8e9e4cf09608d93e1c3d3cb533b3b5ba0e8d529b2f7390c6a60543177 16621360 postgresql-15-dbgsym_15.8-0+deb12u1_mipsel.deb d80341b13974fa794c261f0c813597f734cc5691d6194b8363c32ea96aca5673 16818 postgresql-15_15.8-0+deb12u1_mipsel-buildd.buildinfo 5c9062177cd11257e390598a10e39b78f988acf63a4c5c427afaa00c6eebaed8 16260192 postgresql-15_15.8-0+deb12u1_mipsel.deb f43c5bceb64c2ddf3bc87190fba768c3b236be723fa8efb561da3dffec0acd73 2336612 postgresql-client-15-dbgsym_15.8-0+deb12u1_mipsel.deb 4a6c9a5a2c04ab7b8fd16d95112c0638c1ade7c246229f040630a08b05f93d4b 1644560 postgresql-client-15_15.8-0+deb12u1_mipsel.deb 7f75f7aff6631fac4765c42b89da44f5fd3f3fe4d778d2a0045831e930db051b 184556 postgresql-plperl-15-dbgsym_15.8-0+deb12u1_mipsel.deb ecd0c558119ac05a430c98a4b451f126b7a99ab2a6addab6b08a17bbbcb3e99f 84548 postgresql-plperl-15_15.8-0+deb12u1_mipsel.deb 5bcf7515f75e453d8180331df0a2b79f24cdea6c988fce9d61629aeaf1ea366e 175320 postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_mipsel.deb bfcb90ab2ff532ce1467516e05aade474fa40979cc7ac0aa64b07c57ea06d6e7 103260 postgresql-plpython3-15_15.8-0+deb12u1_mipsel.deb e383de074df9209a04314b494e388287c963f1e89e3dbd09a701a85cfeb7e4c7 80036 postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_mipsel.deb 8ff2c29e4a46a48ff881a9df754c9142ee5f5b1a663c9042c534803867f9ba70 39084 postgresql-pltcl-15_15.8-0+deb12u1_mipsel.deb e74c2880a63cce1197af7d2507d80e4a27e6ce3dd5744f4f1bff617b6c72497f 1149400 postgresql-server-dev-15_15.8-0+deb12u1_mipsel.deb Files: aa8ad5f25ef4929b6c450f5b5149aaa5 39460 debug optional libecpg-compat3-dbgsym_15.8-0+deb12u1_mipsel.deb d520b7056caca3054b54ff29eb9fdafa 21424 libs optional libecpg-compat3_15.8-0+deb12u1_mipsel.deb 76f31585e099fe59a2c754114e805296 260860 debug optional libecpg-dev-dbgsym_15.8-0+deb12u1_mipsel.deb 43b0406a0d68d8545e8a33c2a1587009 282080 libdevel optional libecpg-dev_15.8-0+deb12u1_mipsel.deb d862c1b47877efd118f68478caf260fd 115056 debug optional libecpg6-dbgsym_15.8-0+deb12u1_mipsel.deb 2e3da6e9d6d7507d304fd249585d6fd5 57912 libs optional libecpg6_15.8-0+deb12u1_mipsel.deb 13fa0574252fd2f85984cae257bd701b 91612 debug optional libpgtypes3-dbgsym_15.8-0+deb12u1_mipsel.deb 630aa687e19f94371c79e7f1dbb1a1a7 43200 libs optional libpgtypes3_15.8-0+deb12u1_mipsel.deb aac5be7ae8361bdc9d09caf075e94220 148856 libdevel optional libpq-dev_15.8-0+deb12u1_mipsel.deb bac6dfe164ca3fd501df9025102d9452 282936 debug optional libpq5-dbgsym_15.8-0+deb12u1_mipsel.deb 134b157c9d136ad304c0b4d7aaef5dc0 175812 libs optional libpq5_15.8-0+deb12u1_mipsel.deb 5b043dd9abdf1a45316d4af97916e202 16621360 debug optional postgresql-15-dbgsym_15.8-0+deb12u1_mipsel.deb bc0dbe5aaf4bdfbaae49e7172b6df86e 16818 database optional postgresql-15_15.8-0+deb12u1_mipsel-buildd.buildinfo f8e1750fb1c66d6afba7506a79004a85 16260192 database optional postgresql-15_15.8-0+deb12u1_mipsel.deb 9ef4bf0d418f5468924986ab2988be0a 2336612 debug optional postgresql-client-15-dbgsym_15.8-0+deb12u1_mipsel.deb fe060da28a4ab6d63a15a2622d645c5c 1644560 database optional postgresql-client-15_15.8-0+deb12u1_mipsel.deb 30736920082b23aca347b0be1906b966 184556 debug optional postgresql-plperl-15-dbgsym_15.8-0+deb12u1_mipsel.deb 24932e0afe5104bd7b37e1e25c3890f3 84548 database optional postgresql-plperl-15_15.8-0+deb12u1_mipsel.deb 5a919de5e4ac9bf1fa7286fa1eeda2f6 175320 debug optional postgresql-plpython3-15-dbgsym_15.8-0+deb12u1_mipsel.deb 203bfa1042eabfc8959bf79186218e82 103260 database optional postgresql-plpython3-15_15.8-0+deb12u1_mipsel.deb e0ad39dae3797d1c54472e239162a57e 80036 debug optional postgresql-pltcl-15-dbgsym_15.8-0+deb12u1_mipsel.deb cb9b58fef415b1bed22048455e3b1153 39084 database optional postgresql-pltcl-15_15.8-0+deb12u1_mipsel.deb 98ccbbb9cf1b8cee2de23c7a937f180d 1149400 libdevel optional postgresql-server-dev-15_15.8-0+deb12u1_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEDr2J+AJzKxM96x4w+k4sZ5IEFbUFAma1MLcACgkQ+k4sZ5IE FbUlzhAAqHN7i8/AnMrtgckq1no8Q7FrfvMHa6PDPM6iogW1A8hm62TOIaV7CGW9 Lnycfrv1HG9KUXMmplDSnCnH8O/1xSL8v+hnQj98OOyDGFaDqDDMd/2qjRN5wrDW AX+TpdTwLJGpxy73t1VKFp/5wVTF7rOXbRdIqRDExOgOV0hJHMTfVvHEEqYvNR5l gC+sqIaoJWeIQJFBqiysBCp1UUV+TCe/Knibc06o+5J+ox2+h/vTmpfv64SWgJ7O WHU3TMlgSlSDR7Qf9pif/zoo749xcDdQxVmx8BBut1c9cFY7kZa6zuuZddLpT9vB 3i/0pRxD8aANadLpwLSVD+5AzmvuF8oLrbmd2zOUDRyV1bMBcyRaH7vSrJhwG+nT Hu2OAJMt91NpPTs+bZwlBUpA+Sj1qxn+KYyhP03gOAzde3PXr+mQ5hxS6xPJUsI2 0Yks1BZciieZuNZO4FF2ekL7c1ItYXHbk7pPYu193bsmUAB/8PF+UO83XEH0Q3xL H9NnXAeKbL9J/Z30WMIf6WGRFxcFzm0ZwApiANg5Nl48wlqK0nM2fh4DIrH9El+v TnU/tCJYsw4Y9/ErF6ElUshAaFk0uyTLrEeq0poZDoTwsnSQnoKEn4tB28/gebLm BI1cRLt64m62aLOnRzapeR2kcrPtbXybecW83VfXWqfbcP50/Dw= =VMI+ -----END PGP SIGNATURE-----