-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 07 May 2024 11:24:26 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: armel Version: 15.7-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.7-0+deb12u1) bookworm; urgency=medium . * New upstream version. . + Restrict visibility of pg_stats_ext and pg_stats_ext_exprs entries to the table owner (Nathan Bossart) . These views failed to hide statistics for expressions that involve columns the accessing user does not have permission to read. View columns such as most_common_vals might expose security-relevant data. The potential interactions here are not fully clear, so in the interest of erring on the side of safety, make rows in these views visible only to the owner of the associated table. . The PostgreSQL Project thanks Lukas Fittl for reporting this problem. (CVE-2024-4317) . By itself, this fix will only fix the behavior in newly initdb'd database clusters. If you wish to apply this change in an existing cluster, you will need to do the following: . In each database of the cluster, run the fix-CVE-2024-4317.sql script as superuser. In psql this would look like \i /usr/share/postgresql/15/fix-CVE-2024-4317.sql Any error probably indicates that you've used the wrong script version. It will not hurt to run the script more than once. . Do not forget to include the template0 and template1 databases, or the vulnerability will still exist in databases you create later. To fix template0, you'll need to temporarily make it accept connections. Do that with ALTER DATABASE template0 WITH ALLOW_CONNECTIONS true; and then after fixing template0, undo it with ALTER DATABASE template0 WITH ALLOW_CONNECTIONS false; Checksums-Sha1: ea723d7b21f94d91943cb5621286a1b16713b89b 37076 libecpg-compat3-dbgsym_15.7-0+deb12u1_armel.deb 3dd1b0cb72285fe214ce189a2f17d5114f2b71d2 19948 libecpg-compat3_15.7-0+deb12u1_armel.deb bc2fa90d93edc8404d2c458590e6924b532e0ca5 231248 libecpg-dev-dbgsym_15.7-0+deb12u1_armel.deb f2b51d1ccba564fadc5ad31ccc60dc7d7a03969d 271012 libecpg-dev_15.7-0+deb12u1_armel.deb 180d176c2c0ecea4f3b5ed836f5db40005fbd172 110632 libecpg6-dbgsym_15.7-0+deb12u1_armel.deb f77cfc40e4a058a7823e01064e0949a334cb2590 53956 libecpg6_15.7-0+deb12u1_armel.deb b4946ec13e8c1d5c5bb6ee72b7bd9f93df8a27f5 86548 libpgtypes3-dbgsym_15.7-0+deb12u1_armel.deb c08f4c46362eb673db18078987b7f79cebbba6a2 40340 libpgtypes3_15.7-0+deb12u1_armel.deb 63cd47767c0b1c0076c7b91b4d58504074e25a2d 131788 libpq-dev_15.7-0+deb12u1_armel.deb e6d48b69661114c6996c79ec0e634b5d30872f1a 269692 libpq5-dbgsym_15.7-0+deb12u1_armel.deb 1fbbaaabde40cc519c3396142f4895ce72ab4d7f 167920 libpq5_15.7-0+deb12u1_armel.deb cf42b0b49017f944e49760dee4f7917d5f8780f3 16093892 postgresql-15-dbgsym_15.7-0+deb12u1_armel.deb 86e2212b7c32258b910b95f90388da0967ccd27c 16797 postgresql-15_15.7-0+deb12u1_armel-buildd.buildinfo c8da7270d41b5044a7c7a972c092ac16a74f3a45 16112200 postgresql-15_15.7-0+deb12u1_armel.deb c7a0d1f8b7436a58f711aa7a696f288cba01a301 2222160 postgresql-client-15-dbgsym_15.7-0+deb12u1_armel.deb a2fe552895eb798d174de99cdcc0c838b7492267 1598932 postgresql-client-15_15.7-0+deb12u1_armel.deb 676b44dcb9fa7c7dc713ea872695f9b8eb4ed4c4 181868 postgresql-plperl-15-dbgsym_15.7-0+deb12u1_armel.deb f7aaf38566e67d052dd8e46fd6835856ecd6f88a 85716 postgresql-plperl-15_15.7-0+deb12u1_armel.deb 55c08101e99b041b7ddca5231a215d2a385e2d02 171780 postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_armel.deb 3f2665ed3e000761e5293339e15c9a486c062aca 104700 postgresql-plpython3-15_15.7-0+deb12u1_armel.deb 01a7424b63a4d4bb591d493a981dc1cc0cb3b74c 77872 postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_armel.deb 2690ca00bf5b37a9274ace72247d3ac84dcc8764 38200 postgresql-pltcl-15_15.7-0+deb12u1_armel.deb 847e469db395845c14012cd04c0a7f80979259c5 1126556 postgresql-server-dev-15_15.7-0+deb12u1_armel.deb Checksums-Sha256: 9fcd393177246e3e767727c3394fb1a5dee7b58d92ab8a9c7e53bd7da83c90da 37076 libecpg-compat3-dbgsym_15.7-0+deb12u1_armel.deb 9764551ff019a746befc554d9c0763bcf2bdf43e609a85054a733d630743b85f 19948 libecpg-compat3_15.7-0+deb12u1_armel.deb 8952e00fb29c7139fe97deecabe3357647c724e777ddd31e1c8db5e079cf8b4c 231248 libecpg-dev-dbgsym_15.7-0+deb12u1_armel.deb 6140bcdb00f8420f219d425d5a204a1e018022654b65dcb4217dc87f525869ac 271012 libecpg-dev_15.7-0+deb12u1_armel.deb b30083c66f52d40d248cd3c6d619f897b5d6cfb10ea6bccafe91c257a6b7c0dc 110632 libecpg6-dbgsym_15.7-0+deb12u1_armel.deb 4fdac5f0a26e0015adb8dee56fff3d0cdd3b5d242c54f7530b3778a67304f7d0 53956 libecpg6_15.7-0+deb12u1_armel.deb 4cf7dff7673f8683dda4138c5da401f5948cf391deab2d7d44a1ac369bcb47d5 86548 libpgtypes3-dbgsym_15.7-0+deb12u1_armel.deb 6184420fa403f1512961ff6d1cdc4c58115f97d71fbfd0927a0ec6eaf0817b27 40340 libpgtypes3_15.7-0+deb12u1_armel.deb 1ca2214520ba2aaeb3b5a2d3410ccface11234bb77815c0e5eb8fff2364b4673 131788 libpq-dev_15.7-0+deb12u1_armel.deb dfebe293195e29d402146b40d6a4aa785ea78961904a4a3c8e6ee7cf2f509ba0 269692 libpq5-dbgsym_15.7-0+deb12u1_armel.deb ac9e6e474b25c9fa190adb5e09c6eeb142b0d5d321c50aca5dd6a28b83ef9b88 167920 libpq5_15.7-0+deb12u1_armel.deb c992880a6f6548172611ec74088abc4be674d7f63bcf74ea8e0b69ebda8b3d33 16093892 postgresql-15-dbgsym_15.7-0+deb12u1_armel.deb 0a81fe93261eeccdd5ce1bedf8152527ac795fc89b4ad319c9a87d6898026270 16797 postgresql-15_15.7-0+deb12u1_armel-buildd.buildinfo 464af2d4861042e60b07f4391815ee8217d6720a3399db4d3da236304b2b2edb 16112200 postgresql-15_15.7-0+deb12u1_armel.deb ff7cdfb295fcdbad072c2054c82d3d73418b84ae2e15c8d5b43089b0ad2bcc87 2222160 postgresql-client-15-dbgsym_15.7-0+deb12u1_armel.deb 1a385906a073e37755f2405381eb4279c43e99ebdb064feb50f0d86e458a8fd4 1598932 postgresql-client-15_15.7-0+deb12u1_armel.deb 72391b3645aefdede8c1661006af117f787d743a56593ae343f17d51f2e0aeaf 181868 postgresql-plperl-15-dbgsym_15.7-0+deb12u1_armel.deb 6afca1ce005cca8415df568374567218bfe89cd3afbd4111869264e8226d2d77 85716 postgresql-plperl-15_15.7-0+deb12u1_armel.deb 525c9dc83fbac9b5a2f2841304c5454e2790c9a244cc2869476203de511f0eee 171780 postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_armel.deb 7337de2f0f316be65c7ddbeca9a2ed667a80a16b404f001586d68755a2f3ff80 104700 postgresql-plpython3-15_15.7-0+deb12u1_armel.deb 4bb0221a4aa9c6c18e7cfeed21ae392b91ddbc3094d9f308fd12599ba9512a90 77872 postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_armel.deb ebcc2ab857211ea31eaac2bd9fd8bf3675e306ecb393b783007047a6ffea46c7 38200 postgresql-pltcl-15_15.7-0+deb12u1_armel.deb dba01c716c7578192918983657bbfe391f73f6bdf35d0dbc113e6247d8598800 1126556 postgresql-server-dev-15_15.7-0+deb12u1_armel.deb Files: 70a541ffe1168f9a61626495fa595a74 37076 debug optional libecpg-compat3-dbgsym_15.7-0+deb12u1_armel.deb 3f359740930ba6dfd8ea0621f6d16326 19948 libs optional libecpg-compat3_15.7-0+deb12u1_armel.deb 39d0e66a96051447b6d69de739a46633 231248 debug optional libecpg-dev-dbgsym_15.7-0+deb12u1_armel.deb efd6d56ae95b959402d654ef87b177ad 271012 libdevel optional libecpg-dev_15.7-0+deb12u1_armel.deb 8582610c0eebec8d29ac1eb39b175364 110632 debug optional libecpg6-dbgsym_15.7-0+deb12u1_armel.deb 486cde866822988d519cc11a0a846580 53956 libs optional libecpg6_15.7-0+deb12u1_armel.deb 0162b20b1f51d763b51acccec0bd5e16 86548 debug optional libpgtypes3-dbgsym_15.7-0+deb12u1_armel.deb 1c02277a9158272456618370d3481c99 40340 libs optional libpgtypes3_15.7-0+deb12u1_armel.deb 6dea42a57e4e5bb2ec8a9edacb6d0d16 131788 libdevel optional libpq-dev_15.7-0+deb12u1_armel.deb 292f011d0041db3dd3691f0786d30dfb 269692 debug optional libpq5-dbgsym_15.7-0+deb12u1_armel.deb 6f956425982fe5d62389776597ca537f 167920 libs optional libpq5_15.7-0+deb12u1_armel.deb c6daf2cc700f37e2e0ab70aa5e2d2967 16093892 debug optional postgresql-15-dbgsym_15.7-0+deb12u1_armel.deb da7c37226cd78785f746dd9c747568dc 16797 database optional postgresql-15_15.7-0+deb12u1_armel-buildd.buildinfo 047b0ee4cdbb14a973c9cc34e1fdf26f 16112200 database optional postgresql-15_15.7-0+deb12u1_armel.deb 203f34fb5ce20cac8cac1aac10d54df8 2222160 debug optional postgresql-client-15-dbgsym_15.7-0+deb12u1_armel.deb 394304cb07d896947f72206a4addf744 1598932 database optional postgresql-client-15_15.7-0+deb12u1_armel.deb f36be1d87ba2a2f78e139f9fafd375c5 181868 debug optional postgresql-plperl-15-dbgsym_15.7-0+deb12u1_armel.deb 901f28b736b2d0dd4ee416d9977f9dbc 85716 database optional postgresql-plperl-15_15.7-0+deb12u1_armel.deb bf2bdf85583e395cacbcd6a3381a627a 171780 debug optional postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_armel.deb 28d8648455a29fc28db027979be1c0d3 104700 database optional postgresql-plpython3-15_15.7-0+deb12u1_armel.deb 8080bcbfa9786cecca762335a18d94d0 77872 debug optional postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_armel.deb 6c65ea5097ef355095c96d1fbe48512d 38200 database optional postgresql-pltcl-15_15.7-0+deb12u1_armel.deb 5f04620a2746ae2ee4ec4a6b0f8ee9a6 1126556 libdevel optional postgresql-server-dev-15_15.7-0+deb12u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBv+o19JDIRm4yIQ5CeROIpkCGwcFAmZL0AkACgkQCeROIpkC GwfmVRAAh8M8s9riLFL7nZvDpcxiaP6RU3/03RTKR0TsK0vp/rFp2329/UDtlWH8 eDQcVP2d9h5yf0duUySwZ4UXWe2x2b0Zk7sIVN7qpqRqMJqyFpyREUXrNETNoa7k 6ggzw2KMiU86hJTC3HbqJ0OFAnK7TW1bjJ5hJiIvlWZOXhdimZPV/yUttDndSpU2 g76fO1D+OipCKwWxNQHVSvoLYj8u6kItsN4h1eO39E5BrM+si4VYepHBV0UXb5Sk tIbcjJlR5GADq8bNNdevUxC0zhA3W6XGHoX2YJnwjVE2eEkOXJ7ZpH8ZWrsPdy/m fC7GygZKWyKrDudebv9oCezrWagqEzkieeu2AaJSjxJiHwPmer59jg9AvSFZ5wVS K7X4lyrr0aLxcwisXYopI+uZSICo3WFRLGuU8WFrDFTGWogAXigHFQ6zcnt4T8yZ 2+s2fX8wvNYo8E4E2SVaFdx0wx+7Abwm29nxzoAyGHkxq+dGWDAG+KcAcAKqjXDE 095SL1tS409PHbH6GTeKepAKDgvrNfnk52VgYBUavGi8y+k6o55Tgmv34TIHlBuz pJUMljwKo4v5rOoCPqC13FNpVTGDtOxb1i9My5RYSqGiCr2cxN5lN37Luo1G4dqz /1hbGjbgDINKLtjm1RxNyUU30LmnYRhXYKL3dEp4dUM5KtEnDkM= =1Hsz -----END PGP SIGNATURE-----