-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 16:09:15 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: mips64el Version: 13.16-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: mips64el Build Daemon (mipsel-osuosl-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.16-0+deb11u1) bullseye-security; urgency=medium . * New upstream version. . + Prevent unauthorized code execution during pg_dump (Masahiko Sawada) . An attacker able to create and drop non-temporary objects could inject SQL code that would be executed by a concurrent pg_dump session with the privileges of the role running pg_dump (which is often a superuser). The attack involves replacing a sequence or similar object with a view or foreign table that will execute malicious code. To prevent this, introduce a new server parameter restrict_nonsystem_relation_kind that can disable expansion of non-builtin views as well as access to foreign tables, and teach pg_dump to set it when available. Note that the attack is prevented only if both pg_dump and the server it is dumping from are new enough to have this fix. . The PostgreSQL Project thanks Noah Misch for reporting this problem. (CVE-2024-7348) Checksums-Sha1: 71698e65188e0125e14b53955d3217dd3485a730 38448 libecpg-compat3-dbgsym_13.16-0+deb11u1_mips64el.deb 9332a6c7e22ed704e1eaf32582c63393dd75cf3f 26204 libecpg-compat3_13.16-0+deb11u1_mips64el.deb 8835dc69848037062809fd73425186a008810337 231564 libecpg-dev-dbgsym_13.16-0+deb11u1_mips64el.deb 7f637a4c9f426d3ce643342555e2f8c25284e8ae 278768 libecpg-dev_13.16-0+deb11u1_mips64el.deb cb2cc95f11779886bd5e54f24efd59a5f0f53c25 114024 libecpg6-dbgsym_13.16-0+deb11u1_mips64el.deb 0e1e96ee1dcc4060cf5947f9acbbc8a61d280a5e 59836 libecpg6_13.16-0+deb11u1_mips64el.deb 6cbfaf6863bff2a0205ad59180ddd229e23d5342 92132 libpgtypes3-dbgsym_13.16-0+deb11u1_mips64el.deb 46a1e47c353a125d1fc511054c8ca54da7efd1e1 47940 libpgtypes3_13.16-0+deb11u1_mips64el.deb 57272801e7374c2f4f80c92b565cb2b44107e05f 148424 libpq-dev_13.16-0+deb11u1_mips64el.deb 5dfe7e3b78b791c95d0eac66fe8d32be5ee2e8fd 264192 libpq5-dbgsym_13.16-0+deb11u1_mips64el.deb f88a9a4dd692157297a4a1b839c290aa82adba00 172572 libpq5_13.16-0+deb11u1_mips64el.deb 50a5894601f07cbf76be7d48f3133ee7ed8d01f4 15224028 postgresql-13-dbgsym_13.16-0+deb11u1_mips64el.deb c0f864b5747359fec0a32e711905c249e5d73d84 16356 postgresql-13_13.16-0+deb11u1_mips64el-buildd.buildinfo d02ab792d62aaf42976e4059eabc591831ecfe0e 14788000 postgresql-13_13.16-0+deb11u1_mips64el.deb a535f568b6aaa44bab16b91542926c23b55d305e 1956216 postgresql-client-13-dbgsym_13.16-0+deb11u1_mips64el.deb 8ef175994b72f71bed676b1e27941ebba9ec0309 1467428 postgresql-client-13_13.16-0+deb11u1_mips64el.deb a1f66e42da3ad6b155bcdb95353588281edff11b 162672 postgresql-plperl-13-dbgsym_13.16-0+deb11u1_mips64el.deb 2a7e3efb44e750abce3eb9546ca000ebd24ffb6c 85160 postgresql-plperl-13_13.16-0+deb11u1_mips64el.deb 74897d49972838a5e196571805846462d5947a82 165668 postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_mips64el.deb 290752e58229dc96fd891165e01d21d652120def 103340 postgresql-plpython3-13_13.16-0+deb11u1_mips64el.deb 0e3fbc562c52dfb2c9a09871cb63f4ad53f9fb00 76500 postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_mips64el.deb 30b121fce0453eabd62426244388ca1c444506b9 41364 postgresql-pltcl-13_13.16-0+deb11u1_mips64el.deb c1fbc5ca8770871ff9a758faddcca1944a0e1b58 1050564 postgresql-server-dev-13_13.16-0+deb11u1_mips64el.deb Checksums-Sha256: 93fb247de16b4c7a1e379700d17ecfd7c0bbe4835ecec9b183fb100fc08ea96e 38448 libecpg-compat3-dbgsym_13.16-0+deb11u1_mips64el.deb e846703bbc8ee3acada1bfd26afe4a1320e2e61d706cf84b3e77c44dd4cdb621 26204 libecpg-compat3_13.16-0+deb11u1_mips64el.deb b6f331766d02c38deca9bacce0ed0abd4e10968af0dff13315a2e7c987bd90a0 231564 libecpg-dev-dbgsym_13.16-0+deb11u1_mips64el.deb 0dcc475ca4ac0356cde6f21123f189efeeb70cfdc32875e4f9a0646322bee1ba 278768 libecpg-dev_13.16-0+deb11u1_mips64el.deb f3248dacef793718f40779b4ef87b1a560e8a0f9c5d15351cc36bd7915fd9797 114024 libecpg6-dbgsym_13.16-0+deb11u1_mips64el.deb d940f62a272ba242c637e19b20caea41474a8eabbdb2c5888e1ee55cbf92baf3 59836 libecpg6_13.16-0+deb11u1_mips64el.deb 8c9875caa24f078f5901060096cf0432ba69de975240c58d6fc4be1b6b211360 92132 libpgtypes3-dbgsym_13.16-0+deb11u1_mips64el.deb 18365518f3ba9f5097254e7a8b80e3b7ad0f88a89dc07292b58e0d9c4ae16d3d 47940 libpgtypes3_13.16-0+deb11u1_mips64el.deb 20803d4ea1d02918eecaf9f40c022536370e9d7b2e338c0a2622e52e1ba43a15 148424 libpq-dev_13.16-0+deb11u1_mips64el.deb edac992d9fdcb2d42e0342a52c1e6b916f210ebdafd8582e572ac7e9116c20a0 264192 libpq5-dbgsym_13.16-0+deb11u1_mips64el.deb 10338fee9d1b63785eec5610ac3e273992d42d98773a3302c1ceea687661a19d 172572 libpq5_13.16-0+deb11u1_mips64el.deb 95b22f510b06f60e21e774175161a3d8fcfdce56a173ca1df6e493cb8ed5884a 15224028 postgresql-13-dbgsym_13.16-0+deb11u1_mips64el.deb 22e8234ac0bb1b03fdd452b0f2dd90eadfc5fd2ec7f3942aaa5d458c98f952fa 16356 postgresql-13_13.16-0+deb11u1_mips64el-buildd.buildinfo f617cf7a08fc147ccefc479d01783434a5f1d3f5643581c89d1acf91b126e236 14788000 postgresql-13_13.16-0+deb11u1_mips64el.deb c369268e3999610fdaa5ffdb87c93565804be2b9c51817369b9b9ccec9c9f202 1956216 postgresql-client-13-dbgsym_13.16-0+deb11u1_mips64el.deb 83b925f81894b1feba7a5869aaf9b270dc8d192fc9693f1e02c38e8d7fd0fa50 1467428 postgresql-client-13_13.16-0+deb11u1_mips64el.deb adbded13824f2c96ecfb297e733a8fb9a26ba620cfaf08ce15e2e34293983d0f 162672 postgresql-plperl-13-dbgsym_13.16-0+deb11u1_mips64el.deb 33e51a706e548392a36e3760b53fb6f39e81030bead0be9c9f36dc711c265075 85160 postgresql-plperl-13_13.16-0+deb11u1_mips64el.deb 3f87fccc43b5b5658abdd28c6651a26c38ed503aac398ed9ecf8fa97b737c457 165668 postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_mips64el.deb db920d40de6213c7a1eb14ac3e95d022ee922ea950c08117b37f6fa79d9d2901 103340 postgresql-plpython3-13_13.16-0+deb11u1_mips64el.deb d33f6e49bcf40f6d10f7955c4b5329f2a2d1c6b7a82c75a9f1ed6ba5c56134d4 76500 postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_mips64el.deb fbaa1359f7a75ce915acaf8730b687e1416ba61359b190308852b72c0c8293ba 41364 postgresql-pltcl-13_13.16-0+deb11u1_mips64el.deb af69289a46470470e424e9c8c3014ad395ee1bb6629911cf68f64d4b93282fd1 1050564 postgresql-server-dev-13_13.16-0+deb11u1_mips64el.deb Files: 21c175f0b7722b4db21d452044a24db8 38448 debug optional libecpg-compat3-dbgsym_13.16-0+deb11u1_mips64el.deb 4f823a702c906178b439a97265300584 26204 libs optional libecpg-compat3_13.16-0+deb11u1_mips64el.deb d2da3fc9a6830e1da964b5408c674a8a 231564 debug optional libecpg-dev-dbgsym_13.16-0+deb11u1_mips64el.deb 8182b3bf0825c658fe9633f644829a12 278768 libdevel optional libecpg-dev_13.16-0+deb11u1_mips64el.deb 5c8169647b60613f2210340aef83a731 114024 debug optional libecpg6-dbgsym_13.16-0+deb11u1_mips64el.deb 9ed56871ce70e34edc2b337846914c15 59836 libs optional libecpg6_13.16-0+deb11u1_mips64el.deb 96895695ef26d169976be8455d1bef4b 92132 debug optional libpgtypes3-dbgsym_13.16-0+deb11u1_mips64el.deb 51cefb829d1c0bdf558bd7a771d2786c 47940 libs optional libpgtypes3_13.16-0+deb11u1_mips64el.deb bb39ed90f416617439c5474fa95ac723 148424 libdevel optional libpq-dev_13.16-0+deb11u1_mips64el.deb 425e893c3416780c2bdb87d68d20f5f0 264192 debug optional libpq5-dbgsym_13.16-0+deb11u1_mips64el.deb a523b09ffbbe35ac9e6ec52d9c08a06c 172572 libs optional libpq5_13.16-0+deb11u1_mips64el.deb 98285f8e463501027528b870cb71b219 15224028 debug optional postgresql-13-dbgsym_13.16-0+deb11u1_mips64el.deb 3007d2408d5b4972cbfcbbef708cb0cf 16356 database optional postgresql-13_13.16-0+deb11u1_mips64el-buildd.buildinfo 510585b07da8cc07a820643a7d84c865 14788000 database optional postgresql-13_13.16-0+deb11u1_mips64el.deb 6580bc55ec01bccb695b47c577b935c7 1956216 debug optional postgresql-client-13-dbgsym_13.16-0+deb11u1_mips64el.deb 649ad8add2751475b14dae606c340044 1467428 database optional postgresql-client-13_13.16-0+deb11u1_mips64el.deb 82af3c6d05096cc199c925e1a23630eb 162672 debug optional postgresql-plperl-13-dbgsym_13.16-0+deb11u1_mips64el.deb 64adf80fb135887d113644b4005eaff2 85160 database optional postgresql-plperl-13_13.16-0+deb11u1_mips64el.deb 5b7caff353f7955a3f95872dec6f7bb5 165668 debug optional postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_mips64el.deb a4d76a170f1f34dc6ac34cb909af5050 103340 database optional postgresql-plpython3-13_13.16-0+deb11u1_mips64el.deb 91e1e02d17bf586b4cc54e614f6e585c 76500 debug optional postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_mips64el.deb 00a051c1e9a320d1df5bbdb8541794c0 41364 database optional postgresql-pltcl-13_13.16-0+deb11u1_mips64el.deb 618bc298b0ba2e458daad9e214d61121 1050564 libdevel optional postgresql-server-dev-13_13.16-0+deb11u1_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEwOi7AjfMfAOkP0DckzO9iVHf454FAma1MDUACgkQkzO9iVHf 454PoBAAgrXa1ALFqxJc5KWbRI+q8eaGolkbfQ9cszMFK0qU1PoqxjlhE3u98kFO TKbMyAjh4pHPtFYXRfLGZQ+6MGbPkjuTngS6XrWZoTFjYSfS4kT6nfuVWRdx1lrr muLkzSjpblS04U+eSyDaHTQR+3PABy2dmjkBm/a9kB0Br0GHYFhMjS7tNZeVC1gw X33ghR5OY7dRKPPt38iV3bIwkYjJrN42HOXKyJJcw4fkbzTyETWcOVtpn2J6jYPa CE8HTWmYtZsmgRq2G+rKpSCE9RgqVovNhaYQB79hg2ot6rDwmKXs36gVwYd+rzQu kBcf0hx/k4/ZsR7OirbZO37MZCTEu+9QTEU2su/OTIO0wG445QsNBJv64kUMvsUp eZZFraLnXjRfgPdh74k0C1aesoSzb77dTeqDepQe9J0r6N5tKaVYTqpYC98/O+uQ DbiovoQgOgQ4KEUwisuOhmp1ljRvHX53zNv6XfC/l4C1k4EezUXIM9fXiP7/fh/3 QTfZFRRuMZhLbQ4dCUSZq1Ko1JqWDEO07Dto0LFM/OryBlR0AFFMeBgLnsz4JutX jmGMbEw+VPZkSjP3EUi7yuhXr5LVbiLAes7YBxlYVZ0sUn223JeALqcyh8Zvnk+H f1/rVq+KENVm79KrecslbRk80FJUqGsKL5B1TtcjEtb/AhV7aQ4= =iJlI -----END PGP SIGNATURE-----