-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 07 May 2024 11:24:26 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: armhf Version: 15.7-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-conova-03) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.7-0+deb12u1) bookworm; urgency=medium . * New upstream version. . + Restrict visibility of pg_stats_ext and pg_stats_ext_exprs entries to the table owner (Nathan Bossart) . These views failed to hide statistics for expressions that involve columns the accessing user does not have permission to read. View columns such as most_common_vals might expose security-relevant data. The potential interactions here are not fully clear, so in the interest of erring on the side of safety, make rows in these views visible only to the owner of the associated table. . The PostgreSQL Project thanks Lukas Fittl for reporting this problem. (CVE-2024-4317) . By itself, this fix will only fix the behavior in newly initdb'd database clusters. If you wish to apply this change in an existing cluster, you will need to do the following: . In each database of the cluster, run the fix-CVE-2024-4317.sql script as superuser. In psql this would look like \i /usr/share/postgresql/15/fix-CVE-2024-4317.sql Any error probably indicates that you've used the wrong script version. It will not hurt to run the script more than once. . Do not forget to include the template0 and template1 databases, or the vulnerability will still exist in databases you create later. To fix template0, you'll need to temporarily make it accept connections. Do that with ALTER DATABASE template0 WITH ALLOW_CONNECTIONS true; and then after fixing template0, undo it with ALTER DATABASE template0 WITH ALLOW_CONNECTIONS false; Checksums-Sha1: d053477296c5d9fdb1ba9dfb0aa50918165a6955 37656 libecpg-compat3-dbgsym_15.7-0+deb12u1_armhf.deb 57c449ac2d7dc4e2d14bea7c480b3a1f4c91eeef 19560 libecpg-compat3_15.7-0+deb12u1_armhf.deb 25b6255d8c5455dd743440745f490845c010c9e2 234864 libecpg-dev-dbgsym_15.7-0+deb12u1_armhf.deb f32dd91a44db894f2f4a4bc35cee847e4caff34a 275556 libecpg-dev_15.7-0+deb12u1_armhf.deb fc670eb6b65671bc1d27027579be7aaa728f9125 111556 libecpg6-dbgsym_15.7-0+deb12u1_armhf.deb 3726c88c713d022cb15b030e76a9adba639361aa 52452 libecpg6_15.7-0+deb12u1_armhf.deb 7ea1a94053d80e149c465421ca137b75753a22fc 88572 libpgtypes3-dbgsym_15.7-0+deb12u1_armhf.deb 31ef313f8334a7b19dc2dc5305930dcf16159ca9 39404 libpgtypes3_15.7-0+deb12u1_armhf.deb 15b94ec039e0ad9749d915a7bfb02938da147b23 131828 libpq-dev_15.7-0+deb12u1_armhf.deb 7ea0dc632cf682592d4647832bf4542eab636c8b 273648 libpq5-dbgsym_15.7-0+deb12u1_armhf.deb e095820cdd5b06a7812327d6141c9aa718851840 169540 libpq5_15.7-0+deb12u1_armhf.deb 407470c2df73f27a4b6e0cea05effb93db84786e 16165448 postgresql-15-dbgsym_15.7-0+deb12u1_armhf.deb 882972a338967e56178507da80c56a06d489f957 16799 postgresql-15_15.7-0+deb12u1_armhf-buildd.buildinfo 982d0d1e769680cc6aab1431730c9d62db4d3382 16052156 postgresql-15_15.7-0+deb12u1_armhf.deb 3410683c3d22fe35e104b845862254f3e68ed299 2241752 postgresql-client-15-dbgsym_15.7-0+deb12u1_armhf.deb f7fde02a1aad9d049ec9297edd4e3cd78546612b 1614932 postgresql-client-15_15.7-0+deb12u1_armhf.deb ca0b91e399c3f13804e9ca2414f67859fa17906c 182852 postgresql-plperl-15-dbgsym_15.7-0+deb12u1_armhf.deb d29db1cab331db77e6d0697d9b5b67e38ad2e525 85840 postgresql-plperl-15_15.7-0+deb12u1_armhf.deb 1d5548c4a274d47b552e63f20562e228e2ca89a1 171968 postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_armhf.deb 55eab1eb60f559f39977595f90748c24b662508a 104528 postgresql-plpython3-15_15.7-0+deb12u1_armhf.deb e493cbd0d600fa6ff05af7fc1b58d3eb98e50a0b 78180 postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_armhf.deb 5593271078a01af950a0e65592194ede3c8fdabc 38392 postgresql-pltcl-15_15.7-0+deb12u1_armhf.deb bcfbbd81b6d0a83bf6518eeae813e86e3b265d6e 1124460 postgresql-server-dev-15_15.7-0+deb12u1_armhf.deb Checksums-Sha256: 37bf45ab33a8b7b52916bc71c186be0e869086b3862a6f7f411be0f250a7d833 37656 libecpg-compat3-dbgsym_15.7-0+deb12u1_armhf.deb 21a60ab1de19996a41afdb76b3de4f4ec32f25bcac6e809a2aa4470ea149a68c 19560 libecpg-compat3_15.7-0+deb12u1_armhf.deb 3c706f7953fed13281b63bebc5dde180c79331931566c79f81200bcb089974dc 234864 libecpg-dev-dbgsym_15.7-0+deb12u1_armhf.deb f7d5d9f55e768615255159a3f108c2ad138ceab40817c5de163ada7b54d8fd16 275556 libecpg-dev_15.7-0+deb12u1_armhf.deb e08c127f637d6269c94660906948c129f9a08cbdf373e683c9c66139fa23cf31 111556 libecpg6-dbgsym_15.7-0+deb12u1_armhf.deb 380ba1c1ce464b2f83dd1f3e7942e7750e0ba3d63cc06d2208f98d70c943f7e0 52452 libecpg6_15.7-0+deb12u1_armhf.deb 4d06f742da9dd6121e27170d5c07ea25178fecf4760855a7d4f501717e55b445 88572 libpgtypes3-dbgsym_15.7-0+deb12u1_armhf.deb fa8c22c7e9da7b680c02564c22eeef4db121ac1250c57bee0206d70f5d078b15 39404 libpgtypes3_15.7-0+deb12u1_armhf.deb 20cfc49773fa3864b04f40c41d4f6b15139ae1c1cd79ebb0aeb71ceda81c80e5 131828 libpq-dev_15.7-0+deb12u1_armhf.deb 696cde5c621157f531474e6517b884932990d9c9d8b9e07cf6401d1a32977848 273648 libpq5-dbgsym_15.7-0+deb12u1_armhf.deb cad72ede70b3f3b9cacb11f8c07cecce539517b2971b3f075537d5f567adc3d6 169540 libpq5_15.7-0+deb12u1_armhf.deb 00795a30cef3c157f89fda3cb0aaef82b130e744481964f8f80120dbda7b2425 16165448 postgresql-15-dbgsym_15.7-0+deb12u1_armhf.deb 8c62d2289ad0f190fe9dab365a6b42b2371762076210556831204589ee4501d4 16799 postgresql-15_15.7-0+deb12u1_armhf-buildd.buildinfo 5fa49a773ea67fc7f349f1ea28eb8f34bf9eec4f2906e15ddb77003a4b1d879e 16052156 postgresql-15_15.7-0+deb12u1_armhf.deb 41615a106c2ad30faf6063dadc59b80984b9e064cc63f4a0f885ed4958334071 2241752 postgresql-client-15-dbgsym_15.7-0+deb12u1_armhf.deb 30fc9fb4e76f94611c89f348d96ac02f27251edc05009d06b319a333ca397b4d 1614932 postgresql-client-15_15.7-0+deb12u1_armhf.deb e1715d9459f5715c9cb69f7aaecbf7b927462fa877e23a8bdb2e176e236759b1 182852 postgresql-plperl-15-dbgsym_15.7-0+deb12u1_armhf.deb a310f9ec82d85e207229d016db6bd816f80dea947d2c7e7d710c8ac5fa24acbd 85840 postgresql-plperl-15_15.7-0+deb12u1_armhf.deb c1953174e14bc6137c76a4b3015527bb41bcc82f9b746217f7a222abe93796ab 171968 postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_armhf.deb 9ff77677df9de1f175aca66d4d0ad54bce7219a7052126df53a3839619d4585d 104528 postgresql-plpython3-15_15.7-0+deb12u1_armhf.deb d6a8cb0d00fd5a5e9bc78c9d8eaf3e22728ee908045ff48170d65fea4a619e35 78180 postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_armhf.deb 9c757cfc593a9d3af75ba49b90a570d0e64ce30e46fa412d76d2cdf734d94ed9 38392 postgresql-pltcl-15_15.7-0+deb12u1_armhf.deb a24ac2542285a707abb54a803bb11f777c62b25ae727e05d41f9129578aa0603 1124460 postgresql-server-dev-15_15.7-0+deb12u1_armhf.deb Files: ac1cdad1107e8c180186ce41fae93686 37656 debug optional libecpg-compat3-dbgsym_15.7-0+deb12u1_armhf.deb 0b5d8b0dea30bea409b567450fc418c8 19560 libs optional libecpg-compat3_15.7-0+deb12u1_armhf.deb 861f1a4ef4f2c9fc9bb87fbc9532e687 234864 debug optional libecpg-dev-dbgsym_15.7-0+deb12u1_armhf.deb 678ce4782255cc54c34e3b192c996fe1 275556 libdevel optional libecpg-dev_15.7-0+deb12u1_armhf.deb 132663b065b57d977b37ce4cac1d113f 111556 debug optional libecpg6-dbgsym_15.7-0+deb12u1_armhf.deb 37cd1f87a167f84705faaf690ca4abd3 52452 libs optional libecpg6_15.7-0+deb12u1_armhf.deb 8899b33cd348964f577bf33df76b3dfb 88572 debug optional libpgtypes3-dbgsym_15.7-0+deb12u1_armhf.deb e5f843f890d5bcb271f18e3e9d260587 39404 libs optional libpgtypes3_15.7-0+deb12u1_armhf.deb 0f959f138e05696cf8fcd928c096f1e0 131828 libdevel optional libpq-dev_15.7-0+deb12u1_armhf.deb f26afffa389a099cec5b19a4a2d5c41f 273648 debug optional libpq5-dbgsym_15.7-0+deb12u1_armhf.deb 208847b708e39fe3b7db7fe0d5ee74b1 169540 libs optional libpq5_15.7-0+deb12u1_armhf.deb 2882014aca5e7b9c2de6e74d572846ce 16165448 debug optional postgresql-15-dbgsym_15.7-0+deb12u1_armhf.deb 2c33963543a174487170d4879d1dd46e 16799 database optional postgresql-15_15.7-0+deb12u1_armhf-buildd.buildinfo f8ddb1c96321bfe92cc740171c9ba4e6 16052156 database optional postgresql-15_15.7-0+deb12u1_armhf.deb 95c44f4d422b9dd623a2310c01c94e8a 2241752 debug optional postgresql-client-15-dbgsym_15.7-0+deb12u1_armhf.deb aac13ac234e60132def2f17b5a92237c 1614932 database optional postgresql-client-15_15.7-0+deb12u1_armhf.deb 0ca66e6523d6e14228599bd54b53cef4 182852 debug optional postgresql-plperl-15-dbgsym_15.7-0+deb12u1_armhf.deb cc3380089e066a7e3ec2480e026abe48 85840 database optional postgresql-plperl-15_15.7-0+deb12u1_armhf.deb f0753f726635f348d48356f765a92e50 171968 debug optional postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_armhf.deb 550fc86cf98a91813fbf015c9459ff81 104528 database optional postgresql-plpython3-15_15.7-0+deb12u1_armhf.deb 487476125a0ea2eb16cc7002d9dba9c5 78180 debug optional postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_armhf.deb 0203baf132b5c6b2953e2529804d2170 38392 database optional postgresql-pltcl-15_15.7-0+deb12u1_armhf.deb 6b231aa33fe6fb03f35f23787ac31c75 1124460 libdevel optional postgresql-server-dev-15_15.7-0+deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEU81tY/BC8e+eAeWhLffeOnPnbLUFAmZL5jwACgkQLffeOnPn bLWUtA//WwQV7K0nIz3ri/87zClOh1EZjqRMR8f7r6V6DfHd40fBACKjpZlZUvu0 +xRZ2dIiAe+dsdazEhk+dux/useCVm20TNDfPUWkEH6xVu0A0wOJAEEjJGse6klF S/g9ojrOJBTHRi08k9NFw1RDRHrtuhQ4v/BHyxth9Z26pUdkCDguvla0jmSNWs4M 7r0DCGf2v7/03h2E4pu0K5VoyHgHxiOaqbXI7X+nWHwWpDj+3PZqrERxSpkn40jD hsEQF0q/ZFcGucc4/h9hMF395HRqr0cYytVmwZ99GebX4sLMciGO1SY+T0R4W36f 5Pzr86gM6WAV8G7nwp9a8ahq4yA9TnXs0in6B1Y+0fzTK9/2d3cSvwKJx3RUvMEZ EKoG1hgV9O4X7Z8NSQkx7LRQ4HWQUiXb3BArIZ/0zr2p8o1rOFZ/rOXK7i40epvw 4jBUhOw4afTJFVOYIZUHznY8+QFnl9xQWjXbkvCPghtcGvClXF519Krv3gWztNL0 1Fe8y9KrQTHkQZxp1f1Kh7SWBK+YDF6j1sYM2xpw5nKCVuK9fE5IJuzE4jhQ2N6h 9+7jIbsXcXuoaEXtGMcDQXxlBoQvKv48BsmIp9YbQB99PzDKIqL6KmTtI+mk1WEc EM5iJ8nohOiCTW1odc97+RBzFrwci36Vb9WtP86+VGan5zyvDHI= =Jciq -----END PGP SIGNATURE-----