-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 07 May 2024 11:24:26 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: s390x Version: 15.7-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: s390x Build Daemon (zandonai) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.7-0+deb12u1) bookworm; urgency=medium . * New upstream version. . + Restrict visibility of pg_stats_ext and pg_stats_ext_exprs entries to the table owner (Nathan Bossart) . These views failed to hide statistics for expressions that involve columns the accessing user does not have permission to read. View columns such as most_common_vals might expose security-relevant data. The potential interactions here are not fully clear, so in the interest of erring on the side of safety, make rows in these views visible only to the owner of the associated table. . The PostgreSQL Project thanks Lukas Fittl for reporting this problem. (CVE-2024-4317) . By itself, this fix will only fix the behavior in newly initdb'd database clusters. If you wish to apply this change in an existing cluster, you will need to do the following: . In each database of the cluster, run the fix-CVE-2024-4317.sql script as superuser. In psql this would look like \i /usr/share/postgresql/15/fix-CVE-2024-4317.sql Any error probably indicates that you've used the wrong script version. It will not hurt to run the script more than once. . Do not forget to include the template0 and template1 databases, or the vulnerability will still exist in databases you create later. To fix template0, you'll need to temporarily make it accept connections. Do that with ALTER DATABASE template0 WITH ALLOW_CONNECTIONS true; and then after fixing template0, undo it with ALTER DATABASE template0 WITH ALLOW_CONNECTIONS false; Checksums-Sha1: 6895505a1f210717be80e1bbc1ba582a53825d4b 37772 libecpg-compat3-dbgsym_15.7-0+deb12u1_s390x.deb 36ed5beb10a0301903f2b7e81fb874899c0803a9 21444 libecpg-compat3_15.7-0+deb12u1_s390x.deb 41d008228cb31680e58b3df038f6dfa96e496f2a 214584 libecpg-dev-dbgsym_15.7-0+deb12u1_s390x.deb 203cd792d50369e5fd0f3bd7abcb915cd1dd4f51 278840 libecpg-dev_15.7-0+deb12u1_s390x.deb 5a795e26547b39fae931ddfe68293f82f7ea2c8e 112188 libecpg6-dbgsym_15.7-0+deb12u1_s390x.deb 94501aa4fb38c003275f99209d78e44cad7c2f9c 57560 libecpg6_15.7-0+deb12u1_s390x.deb 0af7fad4575f5592f60a30a4cd426816617eac87 88356 libpgtypes3-dbgsym_15.7-0+deb12u1_s390x.deb 9ca295c4f1ce6454bf1c1a22820d3c65e0cf0799 42700 libpgtypes3_15.7-0+deb12u1_s390x.deb 74a2acc1894a342c5315b544e32ff96bc17a4477 136412 libpq-dev_15.7-0+deb12u1_s390x.deb 906fbe6c0c043e2c8120002c28f04ff71c106ecd 272684 libpq5-dbgsym_15.7-0+deb12u1_s390x.deb 7aad4e858c2c38f1cb1095ad1c80a356f1282234 177060 libpq5_15.7-0+deb12u1_s390x.deb 07ec45b2212d8e02356f85d84853d3a422b5df61 15347356 postgresql-15-dbgsym_15.7-0+deb12u1_s390x.deb 423a83f02985a88156261c78a133d27c36ab26e1 15878 postgresql-15_15.7-0+deb12u1_s390x-buildd.buildinfo b7e645b9e08806968b20184854198bc4cf216c6f 5659296 postgresql-15_15.7-0+deb12u1_s390x.deb f53239c4036cf4e63ee0c64c8ad048b669d39e86 2234708 postgresql-client-15-dbgsym_15.7-0+deb12u1_s390x.deb 00aae80e392f9938a4877f1d6462cd98a744d4ee 1637016 postgresql-client-15_15.7-0+deb12u1_s390x.deb 4004684cb012a4032742eefbb5eddf3328b36cef 180488 postgresql-plperl-15-dbgsym_15.7-0+deb12u1_s390x.deb 9235760749ec7d0163281babcbcd1bc2adfc2f0b 64040 postgresql-plperl-15_15.7-0+deb12u1_s390x.deb 9ef560698fa1a455dccef998f3c8e2fe61a2ba01 169844 postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_s390x.deb ae513526565cf1dac6d9f1fe07d838f1f71ef982 87164 postgresql-plpython3-15_15.7-0+deb12u1_s390x.deb 6f5321c2731b44936310ab15d466084b1a184578 77564 postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_s390x.deb b79c95b58fc3d32a5d4c1ead2327a25c0e760b31 39504 postgresql-pltcl-15_15.7-0+deb12u1_s390x.deb 1461df1b6942a51a5d24ded03d7bea79569390db 1133312 postgresql-server-dev-15_15.7-0+deb12u1_s390x.deb Checksums-Sha256: b51c5a5fc9d2fbc2cfc87f8e57336a584441a943f939920e89c11275424e5f19 37772 libecpg-compat3-dbgsym_15.7-0+deb12u1_s390x.deb d4514969f4b6379774c5b0d7709db4a595fc16d787fc3fc989051d851da9dbb9 21444 libecpg-compat3_15.7-0+deb12u1_s390x.deb b0ab2d5f653c6e83ea9a85b6f357eda80faa92aff2975582c8ac5cd8dd3d0e71 214584 libecpg-dev-dbgsym_15.7-0+deb12u1_s390x.deb 25fdc80cda23c20671701aec278ad73334d9805423e5396ac861b575d5ef3877 278840 libecpg-dev_15.7-0+deb12u1_s390x.deb 9e1db3fe9d24e95808629ed63bb1bf3f315eb77ef4e46bc3423200a07c8826b8 112188 libecpg6-dbgsym_15.7-0+deb12u1_s390x.deb a51089c7d470b42df4331d2afc492b65e9cc7280e231b00608f0b6872f2c8dbf 57560 libecpg6_15.7-0+deb12u1_s390x.deb 1a1dd6c1ac0784410e10eaa6be7d7e539a338807ff822d6f66f93073b3d12ca5 88356 libpgtypes3-dbgsym_15.7-0+deb12u1_s390x.deb 7f1f075383539c4442af7818ff2c5e0003232e0993d6cf8e938c097fe23c9462 42700 libpgtypes3_15.7-0+deb12u1_s390x.deb 97a92d13b7120174e0b05d3609bb22912b3e377cafe9d53e95a95e7ef95436ba 136412 libpq-dev_15.7-0+deb12u1_s390x.deb 045161a0cb564a96eafeed914a1ba7ad1ee3661622f18bef37a40cedade3c415 272684 libpq5-dbgsym_15.7-0+deb12u1_s390x.deb 01975b3d24b715348491d161602a9efffb490084213a70fac34948f26f01512b 177060 libpq5_15.7-0+deb12u1_s390x.deb af1af3bb6b3273e06e77e65fb90bf1d4b290ceabe13f29b066c00f43373f85cc 15347356 postgresql-15-dbgsym_15.7-0+deb12u1_s390x.deb e6df692e0f067c962c79087c2f1978cd7b4c9b232c07b7b0b9faf3b98bda5f79 15878 postgresql-15_15.7-0+deb12u1_s390x-buildd.buildinfo 75a70b0ab4dee6b034d95fcf1b79944d84cd252dec84964808a32f8d20579c16 5659296 postgresql-15_15.7-0+deb12u1_s390x.deb 854b61e16818b4456892996e32f79a270f612fcdc41c47c06cf59703099c4c64 2234708 postgresql-client-15-dbgsym_15.7-0+deb12u1_s390x.deb b05672975e52220b2212a415f3a2356250f98e504e6611a3fba3e81cae021c3b 1637016 postgresql-client-15_15.7-0+deb12u1_s390x.deb 597bd23be6961e830ec07ab83e6b4739b81385ab27332ee58c32f765712552c4 180488 postgresql-plperl-15-dbgsym_15.7-0+deb12u1_s390x.deb ebaa2cab6649e5757b15fce51a6300c5d529d3cf42cf0ed50a29d897e14f8619 64040 postgresql-plperl-15_15.7-0+deb12u1_s390x.deb 17ba29171fc2f785c15b0c19c3d2d6267283d9b00acf6a29ca28856e51ff6da9 169844 postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_s390x.deb 43e9e84a076f5448c386ae2a1a88929dbcaeee076dbe4c7fb7ad406afa418c6f 87164 postgresql-plpython3-15_15.7-0+deb12u1_s390x.deb 1773d7c516a283f6cbb1f7ebace6d49bd27c07d7702b7a5dedd106656c4b9d36 77564 postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_s390x.deb 5fdc86749925f08ed4d42d50bb325333e4ef15a1fd5ccb8a26f03fa715c688ef 39504 postgresql-pltcl-15_15.7-0+deb12u1_s390x.deb e364266aa1d34226b9aa0cb44426bc3258ad33f8d60d6539443ef1a53618d000 1133312 postgresql-server-dev-15_15.7-0+deb12u1_s390x.deb Files: bdc0ab80afcf3c633ea6ffa7165191b3 37772 debug optional libecpg-compat3-dbgsym_15.7-0+deb12u1_s390x.deb 5591688aebfde66b2c0472f8b41b0ccf 21444 libs optional libecpg-compat3_15.7-0+deb12u1_s390x.deb 0275ed8fd3cef0f0b9f535396fd174b2 214584 debug optional libecpg-dev-dbgsym_15.7-0+deb12u1_s390x.deb ce46268872364836dccecb9db2ad4fd0 278840 libdevel optional libecpg-dev_15.7-0+deb12u1_s390x.deb ec649e8fe5277755b1f21914e6e99c79 112188 debug optional libecpg6-dbgsym_15.7-0+deb12u1_s390x.deb 57472429db2d09425e346bf00f9ef53e 57560 libs optional libecpg6_15.7-0+deb12u1_s390x.deb b949b555158311fa58663c0ed7d3bc4e 88356 debug optional libpgtypes3-dbgsym_15.7-0+deb12u1_s390x.deb b2d9ee06ef5c907691a0f5be1001fdbb 42700 libs optional libpgtypes3_15.7-0+deb12u1_s390x.deb 247aef3c739a66e1c9c9190f96096401 136412 libdevel optional libpq-dev_15.7-0+deb12u1_s390x.deb 9bbcd087d316c198714a80c247eec31b 272684 debug optional libpq5-dbgsym_15.7-0+deb12u1_s390x.deb f901ae69aee5c628834b241a477ac7bd 177060 libs optional libpq5_15.7-0+deb12u1_s390x.deb 4e6ba4fdb8b25cc1bd3f33ae482e4f15 15347356 debug optional postgresql-15-dbgsym_15.7-0+deb12u1_s390x.deb 56c9c581c91b75be9693e12f6ca11fc3 15878 database optional postgresql-15_15.7-0+deb12u1_s390x-buildd.buildinfo 27a3dc6172b6c4bf29d22a8b34ddb456 5659296 database optional postgresql-15_15.7-0+deb12u1_s390x.deb f71b481d3086e96276b2e9f8ecaac490 2234708 debug optional postgresql-client-15-dbgsym_15.7-0+deb12u1_s390x.deb 36aaac34c752e270de049176f3bf3740 1637016 database optional postgresql-client-15_15.7-0+deb12u1_s390x.deb c5b729ad4f1d64492e79cf8ee9d93f3b 180488 debug optional postgresql-plperl-15-dbgsym_15.7-0+deb12u1_s390x.deb 88f64d6968870b90c93e623839729e34 64040 database optional postgresql-plperl-15_15.7-0+deb12u1_s390x.deb a8d25679babaf494e63406cf805304be 169844 debug optional postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_s390x.deb a6783d12ba37866b12a9714fd11a1943 87164 database optional postgresql-plpython3-15_15.7-0+deb12u1_s390x.deb f9a59f2d71faa040f36d0b676eb73ef9 77564 debug optional postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_s390x.deb 6247deb02464e9cef8ea17bafd31122b 39504 database optional postgresql-pltcl-15_15.7-0+deb12u1_s390x.deb 4200741dc488120b3e8cb779b8403244 1133312 libdevel optional postgresql-server-dev-15_15.7-0+deb12u1_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEctqRAwcjFMIrbct74euoNlQ3ywQFAmZL4lUACgkQ4euoNlQ3 ywQS2g//UZ7Nf6JT1cmlWkblkxHFwPxeS8f52pXrE6/fXmLZadTtjciRT1iX+u5o RSDPQ7lEy23VwYAK5qqdpC97gSBKczhCz0NlyXNvAFqe2kPXS29GnYT8KRhUrlvl k86OEnRkAxvi1EiblVJ/IqKvbjXaj3MPWduXvJ4UFhwbG9QeEJo6Lz1PBgGYmQxR CA30+vfWPWCLGNS1CE90X/lCDKvzGSDOu9cHza0Cj9Fyr01WEbjY+ydVBj0dXJ74 1t48ye49dxDDYKLUIGdG2UcVdfdBY7Hh6MkvqXR9Rvd0PPTYfiEI6IjW49p5IBta eOwG12RW3/GUHA+JIkmS+KB3/K4jPQpN6AWJ1Z3I28wk/9M7j5WeLSwuJTBJygpv n6tFRsVxm2JoVEyBgWaRjTwysrrGM7HHDl9YlfBnTeeQLAOvfLAM3DWGlYN6jVrn LFuzWvXOwtrAJCT/fjIN4jxyKRwEt1jEKBTpCty6qU41B2G987uBVaBKHNCtrs4y 3P8tJ87KpZ8aS6O8I5L4AA6cIwV+WiJ+E2LWN5Zf1mkAerYvYYj2QKDzryARx5F1 L5iPiQS1xV2ZYUql7o97ZsaCJfi8isYBU4P5QsOiyaMCQoVtljBJ+G4FZ8yI9U88 npsVVtcWiDX0CWWTepJ629sjpWBRjtjEHxWeP13PYWDuwU60UnY= =YWxx -----END PGP SIGNATURE-----