-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 07 May 2024 11:24:26 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: arm64 Version: 15.7-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-ubc-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.7-0+deb12u1) bookworm; urgency=medium . * New upstream version. . + Restrict visibility of pg_stats_ext and pg_stats_ext_exprs entries to the table owner (Nathan Bossart) . These views failed to hide statistics for expressions that involve columns the accessing user does not have permission to read. View columns such as most_common_vals might expose security-relevant data. The potential interactions here are not fully clear, so in the interest of erring on the side of safety, make rows in these views visible only to the owner of the associated table. . The PostgreSQL Project thanks Lukas Fittl for reporting this problem. (CVE-2024-4317) . By itself, this fix will only fix the behavior in newly initdb'd database clusters. If you wish to apply this change in an existing cluster, you will need to do the following: . In each database of the cluster, run the fix-CVE-2024-4317.sql script as superuser. In psql this would look like \i /usr/share/postgresql/15/fix-CVE-2024-4317.sql Any error probably indicates that you've used the wrong script version. It will not hurt to run the script more than once. . Do not forget to include the template0 and template1 databases, or the vulnerability will still exist in databases you create later. To fix template0, you'll need to temporarily make it accept connections. Do that with ALTER DATABASE template0 WITH ALLOW_CONNECTIONS true; and then after fixing template0, undo it with ALTER DATABASE template0 WITH ALLOW_CONNECTIONS false; Checksums-Sha1: b5460b0d6261476c2932003d9737e5acd48a19df 38636 libecpg-compat3-dbgsym_15.7-0+deb12u1_arm64.deb f00ec89be5a8501b0424f333eb89aceba05f1c8a 21560 libecpg-compat3_15.7-0+deb12u1_arm64.deb f7942f53ffd0f5b2b9626bba9977a47aaade7571 273220 libecpg-dev-dbgsym_15.7-0+deb12u1_arm64.deb 93f21204f5c6d9eaed4b56e2bf8c4021be181574 278976 libecpg-dev_15.7-0+deb12u1_arm64.deb c41bcf5b14351813ce51fba49c657e64732af13f 113264 libecpg6-dbgsym_15.7-0+deb12u1_arm64.deb e67878af5f5614ff72739c8d5025864b8e303457 57496 libecpg6_15.7-0+deb12u1_arm64.deb 10c0e1cc55a24193a4ab2a43e25f2ba949bee346 87292 libpgtypes3-dbgsym_15.7-0+deb12u1_arm64.deb e8f7290705d3a15dcd587ac7b1d0fee9b7e1c0fc 41540 libpgtypes3_15.7-0+deb12u1_arm64.deb f1ae7b1ef60d8dd20564400cdf2f89cce1c09232 139508 libpq-dev_15.7-0+deb12u1_arm64.deb bac1b4935ea107ffef8fd0afc8e4c753b098eb52 274360 libpq5-dbgsym_15.7-0+deb12u1_arm64.deb f0c24d8173a68446723d68fcfb923bd0d3f1c428 178920 libpq5_15.7-0+deb12u1_arm64.deb e485a990d76c5a92e2db99ec0c7d5a7ff8ee7b74 16448792 postgresql-15-dbgsym_15.7-0+deb12u1_arm64.deb dc599b77158affdd471e9e8cac41a5ae4f2aa5e8 16923 postgresql-15_15.7-0+deb12u1_arm64-buildd.buildinfo 05d4bb2a6768a79a4f639f2975eccc370cba2a46 16342064 postgresql-15_15.7-0+deb12u1_arm64.deb 0e16edd633608ca546f8557432819df08a544f79 2426104 postgresql-client-15-dbgsym_15.7-0+deb12u1_arm64.deb 76f5a5d2c4a39bad9a71ffc56264ca6663c35cb6 1648992 postgresql-client-15_15.7-0+deb12u1_arm64.deb 6e691128cd7cceb3f195cccbcfb0a1e0cbbed55f 183356 postgresql-plperl-15-dbgsym_15.7-0+deb12u1_arm64.deb 7421ff57e93c017008eeb3f42d1fdb15e02a6937 85688 postgresql-plperl-15_15.7-0+deb12u1_arm64.deb ee79932518a0107e47c10e4655845fc150df64ee 175344 postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_arm64.deb 05af6ef2e9d570e80dfc8be8d5873bb32a806d9c 106200 postgresql-plpython3-15_15.7-0+deb12u1_arm64.deb 6dd7a164d42c63359a617a55a5ea47c4afd9863e 79188 postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_arm64.deb 7302a597aabdca2aa69fd1f097228c25c9ff45be 39580 postgresql-pltcl-15_15.7-0+deb12u1_arm64.deb c25b365f0d490997ddf955d5bf66335c355617bc 1136000 postgresql-server-dev-15_15.7-0+deb12u1_arm64.deb Checksums-Sha256: 2c4b1186f616994c1633229987f9c6635349e06c84db668eba2dad3bf3008a8b 38636 libecpg-compat3-dbgsym_15.7-0+deb12u1_arm64.deb 6b1c1a5c0f6bce05bb6195388afa7d7fe84d8cc0b54f8ff0206fe112c762cd2e 21560 libecpg-compat3_15.7-0+deb12u1_arm64.deb 3593fdf17c18cd73d531b5e53a6edadb87e0c396c915e90aafd0bff16bbe79d9 273220 libecpg-dev-dbgsym_15.7-0+deb12u1_arm64.deb 0a32e35129ddee164d441b2741be4fdc3fb70e152fbe513558db844966c27ba4 278976 libecpg-dev_15.7-0+deb12u1_arm64.deb e80feef6f8e53b634cad4c184e9d210885920fe9a052d5181338253dc11aaae3 113264 libecpg6-dbgsym_15.7-0+deb12u1_arm64.deb c1dcbe9ca050ba7f3dd6597b65b27c0c6b33c04be5c744704cf681eab1d995d7 57496 libecpg6_15.7-0+deb12u1_arm64.deb 1ec07e0a93318dcba5d54ebe6488d312314f4bec46cd48bd9538ee5af915bf8a 87292 libpgtypes3-dbgsym_15.7-0+deb12u1_arm64.deb 214238bc3b72db40d946de2639592b4a0613d9b273bd2cad3247051ea33d8d23 41540 libpgtypes3_15.7-0+deb12u1_arm64.deb c4024d0332d3518bc8f805eefae3988e0a5c43f9808733f7058fac3034d95783 139508 libpq-dev_15.7-0+deb12u1_arm64.deb 2211a43039a03f73ddd28c5ef370a0cf80f39a8063f9f0cb31f8046105732faa 274360 libpq5-dbgsym_15.7-0+deb12u1_arm64.deb 1172d27c653ac8fb26ed6daa40a9506f3aa29a33991e19b7b19785bdad69a1ce 178920 libpq5_15.7-0+deb12u1_arm64.deb 2d13b6a5a6fb46ed476102f67a846b3a06bc8be6d18d7d2d2f8825f549db4d9c 16448792 postgresql-15-dbgsym_15.7-0+deb12u1_arm64.deb 1e42d36e33faf3b289b35cc865bd632e6503f22336a29c857c37355a0b96d1b3 16923 postgresql-15_15.7-0+deb12u1_arm64-buildd.buildinfo 226ebab1d467a090c4a187f008beeb8aa2076a5caa7b4b990a3fc37db0aa2f62 16342064 postgresql-15_15.7-0+deb12u1_arm64.deb 28d70013a4d52678652b9f00ed31b6595359194103a8f09f37bb55fa9c3f3426 2426104 postgresql-client-15-dbgsym_15.7-0+deb12u1_arm64.deb b421768b456a18a8677fd4d8422bd6b5922d3630439e8d9b70447dcb102d9010 1648992 postgresql-client-15_15.7-0+deb12u1_arm64.deb 841b0ee38c36417880cd2323bb7e58314c9b3a7cc0ddf275dcfa6ad2f25641b0 183356 postgresql-plperl-15-dbgsym_15.7-0+deb12u1_arm64.deb 9132c6ad4c1e6e3bbd7f1e48aeed06e4e03612aae132b26af845b9768b7f715d 85688 postgresql-plperl-15_15.7-0+deb12u1_arm64.deb bb47622c268cd6a5a689ce3955eeadefa138b4dc5195ffb06447ade9f187f53f 175344 postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_arm64.deb 6b90001a10fa5b068fa3041b04bf99cef0685ff84b910fe2e24966bd947d0d4c 106200 postgresql-plpython3-15_15.7-0+deb12u1_arm64.deb f21083416a7813f597285e6a90c973f1b98b171066fb5fff42242337f4bb1964 79188 postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_arm64.deb 8e5481edfe9d00eed07048a4f61b52b9a94febd874f2a60ce106876bd94d7ada 39580 postgresql-pltcl-15_15.7-0+deb12u1_arm64.deb a69edb066d0ee5fab6f7a0cafab2214a0d58e3bb74f8097bc21277b77071b270 1136000 postgresql-server-dev-15_15.7-0+deb12u1_arm64.deb Files: 8e591c1b772e5d2df7d1c601dd6ff125 38636 debug optional libecpg-compat3-dbgsym_15.7-0+deb12u1_arm64.deb 5fc78f04e5eb1571a8483dfd869d6e5e 21560 libs optional libecpg-compat3_15.7-0+deb12u1_arm64.deb c6e98f6fdcc204c150aa37506c3d63ab 273220 debug optional libecpg-dev-dbgsym_15.7-0+deb12u1_arm64.deb 1ff4823cce2873d00c891cd1dede803c 278976 libdevel optional libecpg-dev_15.7-0+deb12u1_arm64.deb c1736a2328f276d89aebbbc5ecb32041 113264 debug optional libecpg6-dbgsym_15.7-0+deb12u1_arm64.deb 5b5056efc492cf894dbf37d7fd513c02 57496 libs optional libecpg6_15.7-0+deb12u1_arm64.deb 39c88ffad2cbd59c1399fbcd16ebcfb4 87292 debug optional libpgtypes3-dbgsym_15.7-0+deb12u1_arm64.deb 3e2549b0d5a1550810cb1832f1cb6312 41540 libs optional libpgtypes3_15.7-0+deb12u1_arm64.deb 4eb93350d69cb1719995ad0ab5878392 139508 libdevel optional libpq-dev_15.7-0+deb12u1_arm64.deb 72dd44edcc507cf02e7a85724775fd03 274360 debug optional libpq5-dbgsym_15.7-0+deb12u1_arm64.deb 2e84bb1180a8232b56520ed3c7e70bfb 178920 libs optional libpq5_15.7-0+deb12u1_arm64.deb d3757fb2e8fe28834c9c4ebeeb865963 16448792 debug optional postgresql-15-dbgsym_15.7-0+deb12u1_arm64.deb 67a7435dd4d0d29d28d4014a3175f6d4 16923 database optional postgresql-15_15.7-0+deb12u1_arm64-buildd.buildinfo dc0238b02b8e793ba6b09f6e2ff8b098 16342064 database optional postgresql-15_15.7-0+deb12u1_arm64.deb 9829c12807227a82b2df3447fd1e0cd5 2426104 debug optional postgresql-client-15-dbgsym_15.7-0+deb12u1_arm64.deb 432eeaf35f64bfb402b90639bb485219 1648992 database optional postgresql-client-15_15.7-0+deb12u1_arm64.deb cfc99ac0631887a4cb6424ab19871b1a 183356 debug optional postgresql-plperl-15-dbgsym_15.7-0+deb12u1_arm64.deb 90d0be761511a8a84f53ba6bf4f0eb43 85688 database optional postgresql-plperl-15_15.7-0+deb12u1_arm64.deb 53b9a466ff3297048452be76d5364f5d 175344 debug optional postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_arm64.deb 27a4c921389e619eca33888cb9edaf47 106200 database optional postgresql-plpython3-15_15.7-0+deb12u1_arm64.deb dd22e1550044ad7f18760c88f46358cc 79188 debug optional postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_arm64.deb fdca3e0668a6978e6cefde5348305ad3 39580 database optional postgresql-pltcl-15_15.7-0+deb12u1_arm64.deb 899ca51a77a3cce8306684d8b49bf12c 1136000 libdevel optional postgresql-server-dev-15_15.7-0+deb12u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEH43oX1cK+BEEs9Pe/9j0ct/+ZwwFAmZL3ScACgkQ/9j0ct/+ Zww6VBAAjIExyYlXNqV4qt5XSxLRhc2ZO9v/dlLGlxVywbZl0iTt1Q4keT4L/vbz 1jnodhmP3lYAE338B6xiRpWZVcuiEmVbS+tSbVKnGDYm8+1AylNabaojV0nakhGR aC95HdhArretdQYE0OpwoWNUYJwaTgt4zMjmVK2ugye35sJrBH/AlrKa3g5AgfLf aShRn/3AgjzakBFNc/01NKfQepWKSDDSTtui0oxciTieCDL1QbTLt8WOhcPlm1/N rjiWX30yC/NRbQxkVsbYzswT6SqK1IbDsPkaW9bk6zruavZYGkEw7a3o2LEGtPTy dukLVS6DPMQoinwSo+hUcoQ0cL7fxKU2uNyh328c/4mvlo3lsmNy7BQ2AFc5LyJk Vi9JwQSdIjBIL8sfYXfkkYwTKuZFNq2GBtEot+ZMmJbr+veifHlsjeBxqqMRR5Qh PmtU/DLR9wZHFWWo4RQbPBSPv0t4iD7MaDJsBocDpLg7tBXuk0eStOCa5BBVA19G VwXhPoINB9Saa3gRzQvjl9RvpYxJLO4V8FrPX+N2MeK0RZyVTdhzqFRG5mEwrD+E ymtgsQPDcdIhnVio+J9uOuQbejuqzFbO4KsyUsSj8Tmv5m5zWj52MHdz7ZdHCR9/ C1UHLRpqOm7BTsoki2+afeehBHH6sQVkkiPQklyVAe6nXbkBhHs= =fPol -----END PGP SIGNATURE-----