-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 07 May 2024 11:24:26 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: i386 Version: 15.7-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.7-0+deb12u1) bookworm; urgency=medium . * New upstream version. . + Restrict visibility of pg_stats_ext and pg_stats_ext_exprs entries to the table owner (Nathan Bossart) . These views failed to hide statistics for expressions that involve columns the accessing user does not have permission to read. View columns such as most_common_vals might expose security-relevant data. The potential interactions here are not fully clear, so in the interest of erring on the side of safety, make rows in these views visible only to the owner of the associated table. . The PostgreSQL Project thanks Lukas Fittl for reporting this problem. (CVE-2024-4317) . By itself, this fix will only fix the behavior in newly initdb'd database clusters. If you wish to apply this change in an existing cluster, you will need to do the following: . In each database of the cluster, run the fix-CVE-2024-4317.sql script as superuser. In psql this would look like \i /usr/share/postgresql/15/fix-CVE-2024-4317.sql Any error probably indicates that you've used the wrong script version. It will not hurt to run the script more than once. . Do not forget to include the template0 and template1 databases, or the vulnerability will still exist in databases you create later. To fix template0, you'll need to temporarily make it accept connections. Do that with ALTER DATABASE template0 WITH ALLOW_CONNECTIONS true; and then after fixing template0, undo it with ALTER DATABASE template0 WITH ALLOW_CONNECTIONS false; Checksums-Sha1: 1bc3bc11f9e33c6241f10743c0231732e334ad80 34604 libecpg-compat3-dbgsym_15.7-0+deb12u1_i386.deb 3ede729ae31ba44026fa01df166ae54528a2269e 22864 libecpg-compat3_15.7-0+deb12u1_i386.deb 1a508552bb2e9ff95559e2958e0a372e34c42a49 271080 libecpg-dev-dbgsym_15.7-0+deb12u1_i386.deb 8a5f77e88921601ace0d6d4de6a4a55b413e2886 305184 libecpg-dev_15.7-0+deb12u1_i386.deb 5bed85bbfc5d7d472090593ec356d0c05d34169e 101760 libecpg6-dbgsym_15.7-0+deb12u1_i386.deb 5539df5a002709a232432ac36af58d1712aa302c 64184 libecpg6_15.7-0+deb12u1_i386.deb fd70de8e2ebbecad2e2c345a01ca772f175bace7 80808 libpgtypes3-dbgsym_15.7-0+deb12u1_i386.deb b7c9d26cce93906b214b10d88fe3465ab7793e83 45996 libpgtypes3_15.7-0+deb12u1_i386.deb 82e098f41dc1603ce858523507ac86587bac5b57 152264 libpq-dev_15.7-0+deb12u1_i386.deb 1324e3b79793bb054911b0daf819c1aab49fcacc 241400 libpq5-dbgsym_15.7-0+deb12u1_i386.deb 9c033894f5d775a68009d587b2c097111b4e5181 195124 libpq5_15.7-0+deb12u1_i386.deb fcfa5bc4fbb240ef86aff871b51711f8bdf4a4eb 15257652 postgresql-15-dbgsym_15.7-0+deb12u1_i386.deb c50177c53b49c550371799da77e983aaf795a5a1 16842 postgresql-15_15.7-0+deb12u1_i386-buildd.buildinfo f21551ef7f689d980a5250a920ca727caf8d93ec 17043300 postgresql-15_15.7-0+deb12u1_i386.deb b4db692802625dbd8f3dcae95a9543c690b14dff 2058744 postgresql-client-15-dbgsym_15.7-0+deb12u1_i386.deb 103851b80c35caa411fd2b595338faaabf5cccaa 1721872 postgresql-client-15_15.7-0+deb12u1_i386.deb 6cafbd0b3242631ed0cba51eb8d66336f8408e8e 173676 postgresql-plperl-15-dbgsym_15.7-0+deb12u1_i386.deb 8d6ec8d3fd446087dd2a53cbfb284d154c17b728 92484 postgresql-plperl-15_15.7-0+deb12u1_i386.deb d15287a15e5bf976981609e16afbbc97b6abb698 163336 postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_i386.deb 02118d4847764bafe6903ccd8d382471e07767e7 113028 postgresql-plpython3-15_15.7-0+deb12u1_i386.deb 82fd330cf4bc79eee82388a3e71fbb4fee25fdc0 74004 postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_i386.deb 6fd0426225142300b25fd736f063d563ec0abda8 42420 postgresql-pltcl-15_15.7-0+deb12u1_i386.deb c4cbfd9c21c6d055eb4758ef8d74420db8c2a1d0 1157544 postgresql-server-dev-15_15.7-0+deb12u1_i386.deb Checksums-Sha256: ed39942e220e45cf349f2fc11b88de8ec38bad7817bacaa05162d944bf291b9e 34604 libecpg-compat3-dbgsym_15.7-0+deb12u1_i386.deb 977bf067a8ec686053c6bcb1ed4c4123a7cfd49daeb2dc7e9c17ef4aa673494b 22864 libecpg-compat3_15.7-0+deb12u1_i386.deb e5f4eab1f10b90780f3187a781fe6a73285b6c616b62e78baf88685a45b2d640 271080 libecpg-dev-dbgsym_15.7-0+deb12u1_i386.deb 085a427e2979fdd5176ad7bcadeb1325c925eedcc27003e81f0e3a204e9751f9 305184 libecpg-dev_15.7-0+deb12u1_i386.deb 83a5ecb373819c4fb1a5e912e95d94b1c96d0d6705f933840c2d9e8d6f44fbf3 101760 libecpg6-dbgsym_15.7-0+deb12u1_i386.deb ea8f009793998f2d1328f429e72fc66c76e2e55b5a7cc5f5c147e345ff902a74 64184 libecpg6_15.7-0+deb12u1_i386.deb ff5412037463eb6a2bd9da3829c2f4f642a1a6f4ea4211bc1383bbd1d2888f79 80808 libpgtypes3-dbgsym_15.7-0+deb12u1_i386.deb 3337abb56baa1450564810960a0b36fe9643955ca5e61709f7e23afbb7bf7803 45996 libpgtypes3_15.7-0+deb12u1_i386.deb d11e22058fc037cf07387b423e50d226b3564951da144930546400cb5c5932f5 152264 libpq-dev_15.7-0+deb12u1_i386.deb 12c96ad01d366c06fa71ed0598c033732f9c8776ba6cd0f06943d57d5ec6a49a 241400 libpq5-dbgsym_15.7-0+deb12u1_i386.deb 1e96ffd283c2e865cbb679dcb2ca005733b40795afb5dc72a2f86ceb97f79dcb 195124 libpq5_15.7-0+deb12u1_i386.deb 5fee56ae8f4142a3639ced432d31c54d1617edc635d545d5e502f9797af9d624 15257652 postgresql-15-dbgsym_15.7-0+deb12u1_i386.deb f05f75d6895afa3da060166fcf907b77e07f67ed7dacb73a5f040a87a53aa3c2 16842 postgresql-15_15.7-0+deb12u1_i386-buildd.buildinfo 5b5aed98515cce342356d0a399dff3e2bfd662c593dfbaf9d7be0389cbd453e3 17043300 postgresql-15_15.7-0+deb12u1_i386.deb 1961fd61c32b11f5107ba798c3f3defc5aaf8596d05bac8827f51aa232de140e 2058744 postgresql-client-15-dbgsym_15.7-0+deb12u1_i386.deb 2a68ce642f3a6cf6c68607217a5caf2ea452ae7ad1efacb8c389333b467da3c1 1721872 postgresql-client-15_15.7-0+deb12u1_i386.deb 4712da195fa082b2e9e912913034c4cf16c8db29a2b06526200105b68881ec84 173676 postgresql-plperl-15-dbgsym_15.7-0+deb12u1_i386.deb 88c001546ec448f65ed9f6438c30bf8bac0838dd4e9efc459b83aeb3e647aa25 92484 postgresql-plperl-15_15.7-0+deb12u1_i386.deb 11efcb51940549a18d02d0bee4d1485527a32255306c734298b89f18afb3179f 163336 postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_i386.deb 61de9d4223c74c81a82a579d9ac2908ec222bac933236ca491fc46431d1d3c5a 113028 postgresql-plpython3-15_15.7-0+deb12u1_i386.deb 6dfe5ff669a0422aefbf3583e90566a8ed0ee1ec8ff56563502cc45bad0f2be8 74004 postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_i386.deb f49318dee57384ae3427956603c22c00bf75ef1dea17892a59f39b9684e6ef84 42420 postgresql-pltcl-15_15.7-0+deb12u1_i386.deb 46738fca4208c74f197f7a168743ccc96e0d2ea9a34382be667962fd62b89422 1157544 postgresql-server-dev-15_15.7-0+deb12u1_i386.deb Files: 25ef81917259e231270e6faeccad2218 34604 debug optional libecpg-compat3-dbgsym_15.7-0+deb12u1_i386.deb b05890e6d0bf0339f2494c5034fc4772 22864 libs optional libecpg-compat3_15.7-0+deb12u1_i386.deb 91b0e83a424e99569d5c4a5c64fd5cec 271080 debug optional libecpg-dev-dbgsym_15.7-0+deb12u1_i386.deb e8b359573c243927ace2f01253330450 305184 libdevel optional libecpg-dev_15.7-0+deb12u1_i386.deb d9efefe0c2fab2ffa3c3dec6f8681dbf 101760 debug optional libecpg6-dbgsym_15.7-0+deb12u1_i386.deb 7b5534fb536746ec86d241df82bb6708 64184 libs optional libecpg6_15.7-0+deb12u1_i386.deb bec89f766e9b28e84065c16f2ee94fec 80808 debug optional libpgtypes3-dbgsym_15.7-0+deb12u1_i386.deb 48d2f6241a678b2a94d227b217d5c8ca 45996 libs optional libpgtypes3_15.7-0+deb12u1_i386.deb 5be8f0b80f7bcd9b9118e72bd452284f 152264 libdevel optional libpq-dev_15.7-0+deb12u1_i386.deb 41498c338f3e79573c49a64aae947ee5 241400 debug optional libpq5-dbgsym_15.7-0+deb12u1_i386.deb 5b82e6ec1fdeb01060f8d6d6db4a76da 195124 libs optional libpq5_15.7-0+deb12u1_i386.deb 8048eae3b607e022a588226338050dcb 15257652 debug optional postgresql-15-dbgsym_15.7-0+deb12u1_i386.deb 5678eba2e2e7633ce2a951e247a75d7f 16842 database optional postgresql-15_15.7-0+deb12u1_i386-buildd.buildinfo cb3deba776a957328cfcab86c5f5aa67 17043300 database optional postgresql-15_15.7-0+deb12u1_i386.deb 9276c68b6e16b1a0ae0474c94baebd12 2058744 debug optional postgresql-client-15-dbgsym_15.7-0+deb12u1_i386.deb 52f480b5c8fc577051dcf6de0ac889ee 1721872 database optional postgresql-client-15_15.7-0+deb12u1_i386.deb 1eeff6e095770201183b8717e328fdbd 173676 debug optional postgresql-plperl-15-dbgsym_15.7-0+deb12u1_i386.deb c10e9024a60dd2675131316efcec0737 92484 database optional postgresql-plperl-15_15.7-0+deb12u1_i386.deb 924334649c93e9fbf39f4e406452c323 163336 debug optional postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_i386.deb 5c5aecff0c08fc223eeff71558897582 113028 database optional postgresql-plpython3-15_15.7-0+deb12u1_i386.deb ba59b03e0851f137de2d13e704c9083b 74004 debug optional postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_i386.deb 04b45af9a3be4669634a8238f1476e18 42420 database optional postgresql-pltcl-15_15.7-0+deb12u1_i386.deb 279aa0e2bf2edd0fe135cff5c7b3a8d9 1157544 libdevel optional postgresql-server-dev-15_15.7-0+deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEyTfXx8sBpQ0Lh3cUU9a0/LcaTpMFAmZLzfQACgkQU9a0/Lca TpN5PBAAgF9dFGXxbUsWXodwvXXnvZ4QmqVL2O9+dMbMR+uUEQFW4qmS1m/Z75ed 7wBaPCsVCPd7faj0jZ3fjWIuKsOjrYUrjWdgG1ggSJsuFV1KyX0m8hgsV83OeBee hpnXb2XPvoOO6BrTdvVflWf67zXf6OBvRe68/k46i1MUzrtEePMF+DUHnHCJwK08 KuqvajaBRQd8CV2mytjzPeiSwIcjS54Lk0O2id+zcrkW8IdTnqXNqEJ4n7wLIqeE LU9+wtwqRvi7DXNdwmemC0OwrtXU0sgKiQn5wku5AcR+Z6gfuUKAacD+GBYPo2P+ 4gl0fkBwkurqsrRir5htkyKInk0yQBPm/2hPlsuEV1fWkaVbgAIEuTl5dNyNHq3l jdu3hERhjtEJCOATgNopwQN5GVBMuD4l1Jlu3gOFGPwOnI+i+6/ZYVSPLOqQFn6x cVnYMHA3tbxkqvQFgsriYuwKnoPtufYVDU9YFExpKEe7QpD3u3l8t4k8BjsX+K+V JKHGq83GRdW8wKnW7sJGsj4TEuTs/zpetQHxvInYsIVUMw5Y+KKrBQGMxgRZhBYj MJVIonAlmras739f9SaG/6zWC78tfIxXoE5YcapkiUftzG5my8438303UF9evKnS 6KAmwrBEOp6N+T+loqN6ih3n/CzcB3Uhy0yKdM0GZsU8eYZdbx0= =d1K8 -----END PGP SIGNATURE-----