-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 16:09:15 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: arm64 Version: 13.16-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.16-0+deb11u1) bullseye-security; urgency=medium . * New upstream version. . + Prevent unauthorized code execution during pg_dump (Masahiko Sawada) . An attacker able to create and drop non-temporary objects could inject SQL code that would be executed by a concurrent pg_dump session with the privileges of the role running pg_dump (which is often a superuser). The attack involves replacing a sequence or similar object with a view or foreign table that will execute malicious code. To prevent this, introduce a new server parameter restrict_nonsystem_relation_kind that can disable expansion of non-builtin views as well as access to foreign tables, and teach pg_dump to set it when available. Note that the attack is prevented only if both pg_dump and the server it is dumping from are new enough to have this fix. . The PostgreSQL Project thanks Noah Misch for reporting this problem. (CVE-2024-7348) Checksums-Sha1: 7c08662523b8ebde4f3f2a360a425b0e8c30e6bf 39276 libecpg-compat3-dbgsym_13.16-0+deb11u1_arm64.deb 3eb4b51a81f0a812d51e71762e8a948eb14113ce 26660 libecpg-compat3_13.16-0+deb11u1_arm64.deb 17f274b030b32a24afda36569766057e16cd350d 221460 libecpg-dev-dbgsym_13.16-0+deb11u1_arm64.deb 941238994cd35167e6527679e3c2f840c33e3435 271560 libecpg-dev_13.16-0+deb11u1_arm64.deb 1a28cecd32c4c432daca50a02c1ccd46073574af 113700 libecpg6-dbgsym_13.16-0+deb11u1_arm64.deb 69364d1fa1e10ada660aa16acf2a1c430f1d0c5b 60744 libecpg6_13.16-0+deb11u1_arm64.deb d9a1c28d2c406db53c3d421f2210c2d48ea36dac 89012 libpgtypes3-dbgsym_13.16-0+deb11u1_arm64.deb a2872f9b61fd73709ae87912c470dd6c10ed5d50 47096 libpgtypes3_13.16-0+deb11u1_arm64.deb 8e0a9bb6ed69bdac1170376a02d83751031f5662 139432 libpq-dev_13.16-0+deb11u1_arm64.deb 325353790dacd9ec5c7f3aaae28dd07975605c81 255616 libpq5-dbgsym_13.16-0+deb11u1_arm64.deb b454ca701f9f51c40d3bd40b5f117dd21c5a3d4f 175440 libpq5_13.16-0+deb11u1_arm64.deb ef790b2593f77d602a29a7dd1e2aab654361f4a8 14678336 postgresql-13-dbgsym_13.16-0+deb11u1_arm64.deb e9086a64267809b8e9ed4bce7f328c6545154b0f 16266 postgresql-13_13.16-0+deb11u1_arm64-buildd.buildinfo a6b6495c6a13f04b5a33684db37de608784d150e 14738492 postgresql-13_13.16-0+deb11u1_arm64.deb 5e24cf4dc63c8425aa16522f7459b7c1f5fe4097 1882208 postgresql-client-13-dbgsym_13.16-0+deb11u1_arm64.deb 553a8cb381ba975915a145334eac8ede5bbf5adc 1477988 postgresql-client-13_13.16-0+deb11u1_arm64.deb e93ac8973754af3bc26c66c28580f4e24eff9434 155236 postgresql-plperl-13-dbgsym_13.16-0+deb11u1_arm64.deb 5c2a0198f7e5af6f50b0d6b0c2591671b4aa7867 86688 postgresql-plperl-13_13.16-0+deb11u1_arm64.deb 2ede7e68634680a16abced41db94e174c457846c 158324 postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_arm64.deb 3cd55fc69125f29cfaf6575c1d2e195ba2bb9ade 105752 postgresql-plpython3-13_13.16-0+deb11u1_arm64.deb 47998400cdff660b565fd02703a03bc6d51d907b 74028 postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_arm64.deb cd16d6655b3caef93baff82c1799140732959acb 42600 postgresql-pltcl-13_13.16-0+deb11u1_arm64.deb ad5cef91cb8c9f5bb09d6630aad1375de9700620 1039404 postgresql-server-dev-13_13.16-0+deb11u1_arm64.deb Checksums-Sha256: 33b82b39113fb339f54725c3c49c73ea7177351d7131fe1560e092f0ce1f0e60 39276 libecpg-compat3-dbgsym_13.16-0+deb11u1_arm64.deb 2e74f00e58d81659b8ad8f9a997aa6b8de9b2f2c9ec7f4560b81d7b340f3df3e 26660 libecpg-compat3_13.16-0+deb11u1_arm64.deb 2df8d08442bd9035aedf65b80a82564c5e21b50d1233efa03bfa27549c6618a3 221460 libecpg-dev-dbgsym_13.16-0+deb11u1_arm64.deb d790b5fbe7290740f2785b670c0f09b16297ed5ea1ac3f4870bf0d6f27bb1e26 271560 libecpg-dev_13.16-0+deb11u1_arm64.deb 12a4d32c8d0a03177a850e14838ae15ec64511753282e66f2be2fb33efcaab7d 113700 libecpg6-dbgsym_13.16-0+deb11u1_arm64.deb 5295ac1749b3d44ccc87e7dfc1bcd66066622bc74ce4a6674f9334b0d48907f3 60744 libecpg6_13.16-0+deb11u1_arm64.deb 6bce4208fde5a1cbb083a1cef1fe16ee0ff591fa4158a267f2a047f67e215fe1 89012 libpgtypes3-dbgsym_13.16-0+deb11u1_arm64.deb 92358ffaf3b0dbba55ad12256a2b65da1326e47c64890dab214437fb705b6460 47096 libpgtypes3_13.16-0+deb11u1_arm64.deb 58be9a2759b729362e36b25687b02310cf53ec765e0006a0257d081aeeb581c4 139432 libpq-dev_13.16-0+deb11u1_arm64.deb f4799e9d0499fb4ba9e1b0c31e4592bc9c292876f022283cb4fe790c428f9100 255616 libpq5-dbgsym_13.16-0+deb11u1_arm64.deb b51529de7a4469b4e7f05d4c1253925fa4a3304360ed8baf435dbd8e8c76f34d 175440 libpq5_13.16-0+deb11u1_arm64.deb 7367e53b6902a9bf832cbdf244fd59ca21c3f7e4f2cdfcba416c1e9356f9dad6 14678336 postgresql-13-dbgsym_13.16-0+deb11u1_arm64.deb 983771328dde8704d73f0e5922d18bb7beb77587cdc5490cbdebea890cbf6774 16266 postgresql-13_13.16-0+deb11u1_arm64-buildd.buildinfo cd62ff98ee6fbe4025601acd0ee49d7a46e08393c9de8ab3158c06fa5ad35cd8 14738492 postgresql-13_13.16-0+deb11u1_arm64.deb 539107971fe2e4ea3c9bf60e518131ff3b93dc2dda9f18d1f63bfc36bdc0fc0b 1882208 postgresql-client-13-dbgsym_13.16-0+deb11u1_arm64.deb 47ac246aa30cf6bb8f127b3fda6a886e8a1b31ab5d4d2390861dc8c8a4d650ff 1477988 postgresql-client-13_13.16-0+deb11u1_arm64.deb 7aba460febfdde62402add48ce9b9cccb4df1987ff45c54a52e9c5b9466e2aa8 155236 postgresql-plperl-13-dbgsym_13.16-0+deb11u1_arm64.deb db55fb6d1f57f7c166a00f7cd266b34404982c1cd30f34afd44479e90aa49dd0 86688 postgresql-plperl-13_13.16-0+deb11u1_arm64.deb 7287dfd1f8a3f73f06049ab312e016840e7e9f90e8a4b1b834c91af11b82838c 158324 postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_arm64.deb 9ec3b2d4345a814e170ad270af5e8a39b7b291e87fc200e1b903e1f1f06e130b 105752 postgresql-plpython3-13_13.16-0+deb11u1_arm64.deb 241398af187e4b30b69b62a86b5ad6f4603534d29bd9b4a332fa44be4aed3917 74028 postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_arm64.deb 31ba209b8e64e53f40ff634c1b50e37607f3559b7fbc88d133c3714392f36b87 42600 postgresql-pltcl-13_13.16-0+deb11u1_arm64.deb 6ee2c198d4707875e3abbc5a19f1ea7126d5e4898b3c58f7025824bc6678ff58 1039404 postgresql-server-dev-13_13.16-0+deb11u1_arm64.deb Files: 2b8d5026d2ee04be322378922da36f18 39276 debug optional libecpg-compat3-dbgsym_13.16-0+deb11u1_arm64.deb ef01914ebdd911723c9e75b892d706ce 26660 libs optional libecpg-compat3_13.16-0+deb11u1_arm64.deb 35a17ce3cba7e1c933092aacb1bde984 221460 debug optional libecpg-dev-dbgsym_13.16-0+deb11u1_arm64.deb 67b4550b6aad46032cffae4a6910349e 271560 libdevel optional libecpg-dev_13.16-0+deb11u1_arm64.deb 011cc12cce8d74e146ec3a1a96b00126 113700 debug optional libecpg6-dbgsym_13.16-0+deb11u1_arm64.deb 4690bbae06537364b7645718796dcb16 60744 libs optional libecpg6_13.16-0+deb11u1_arm64.deb 0a21fae49d7f49ae3301f273d1317e5d 89012 debug optional libpgtypes3-dbgsym_13.16-0+deb11u1_arm64.deb d545ef73a994921d47a5e20c76b1e365 47096 libs optional libpgtypes3_13.16-0+deb11u1_arm64.deb 3f94464eea41bdf06cb14686ea89ec51 139432 libdevel optional libpq-dev_13.16-0+deb11u1_arm64.deb 2260c4f42c723ebc6d581f3a8a09f7e0 255616 debug optional libpq5-dbgsym_13.16-0+deb11u1_arm64.deb ab21df659bf8a7e96097aa20825bf87c 175440 libs optional libpq5_13.16-0+deb11u1_arm64.deb 4f51f9501a2c33240c615a27469643d5 14678336 debug optional postgresql-13-dbgsym_13.16-0+deb11u1_arm64.deb 21f70a7c5b9d42bb50decc4d540cd35d 16266 database optional postgresql-13_13.16-0+deb11u1_arm64-buildd.buildinfo a38877d6dcb5227af7e5f0011362e0d4 14738492 database optional postgresql-13_13.16-0+deb11u1_arm64.deb 20164792ae5ed8ab9ca8e9e47b376da5 1882208 debug optional postgresql-client-13-dbgsym_13.16-0+deb11u1_arm64.deb e90834516fa0b39a727ba6568fb52e50 1477988 database optional postgresql-client-13_13.16-0+deb11u1_arm64.deb 73d59106e118ccc835dfa0924bdea71d 155236 debug optional postgresql-plperl-13-dbgsym_13.16-0+deb11u1_arm64.deb 47422b7bf807fb7ebf23d35a982ea4f5 86688 database optional postgresql-plperl-13_13.16-0+deb11u1_arm64.deb 1e2edf109df28fdde407c9696fed6232 158324 debug optional postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_arm64.deb cd6db134b92ba72da682ee9c8ceec319 105752 database optional postgresql-plpython3-13_13.16-0+deb11u1_arm64.deb 7c2b2fc96453512751a337ba2ae3fa87 74028 debug optional postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_arm64.deb 33094b7e3148e214ef2b27d4e1a6723b 42600 database optional postgresql-pltcl-13_13.16-0+deb11u1_arm64.deb 57046d7fe2f36748fb5ac0d22882a7e4 1039404 libdevel optional postgresql-server-dev-13_13.16-0+deb11u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKAzExpjGvTI78ZO8LARVyvnD3xkFAma04cwACgkQLARVyvnD 3xkqURAAnmnk+OoVSbRZvRYaX5cLPno/a8G7L+zUCvvZXEkUfeUhSiddd1Y5C2RB cdAfYYCoAfIzldMWjsktKlc0Bi7Ay4cSvPhni79r0CBIqdROqmmIR3ZyNqQM+ih9 czpLaoy9qZXjW0Zsy6rAUqWx69SDN5uibjZnBoW2C7E/DoWyoddnlsg/ROCe9N++ Tk7zyhZHE88Sg+IOWVyAYDVXOpWXEUX8LaJ1GPohZvyyC/rmsBQaS6ASyW6npP0e fln2J41y5i2SHV/+PsTeeYMyNXZ+LkS7b86IyDXK+d7fYUT1/ILDpveI3oFdntZR AsYPB8Aza44Y1rZwdREgHAnTTuTpwzGJSldkcv1WPccn/w+WvNhubcZOCnjW1YzQ 0FdxzwygfBdcKpnhEkPmjFXKwsDhe4ixLcN1QTS6Qwb/lWNULuQcQrLQhMpukJbI +SA4ih4eJrKgtC4c5BhZvJAjzu9/fueuzwnwO3P0YOrpNNc3cKL3wgcryD4JST9s VRootMuorBifpn6XNt7R7t+zzKGBqdOegj9pbGMCylom7y2qrwUSsuSMGZJnjHOe VsC7gvjOqXXVhBpIZd0yovTvnN4BCQbSlZh2sbfSuK93MnW39UqXSUpADu1QqICR XLd5owXsNSiZVIq8AoTjpOothgha0nDn/2pXTidVYuUlvVIUxUQ= =YhTQ -----END PGP SIGNATURE-----