-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 07 May 2024 11:24:26 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: mips64el Version: 15.7-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: mips64el Build Daemon (mipsel-osuosl-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.7-0+deb12u1) bookworm; urgency=medium . * New upstream version. . + Restrict visibility of pg_stats_ext and pg_stats_ext_exprs entries to the table owner (Nathan Bossart) . These views failed to hide statistics for expressions that involve columns the accessing user does not have permission to read. View columns such as most_common_vals might expose security-relevant data. The potential interactions here are not fully clear, so in the interest of erring on the side of safety, make rows in these views visible only to the owner of the associated table. . The PostgreSQL Project thanks Lukas Fittl for reporting this problem. (CVE-2024-4317) . By itself, this fix will only fix the behavior in newly initdb'd database clusters. If you wish to apply this change in an existing cluster, you will need to do the following: . In each database of the cluster, run the fix-CVE-2024-4317.sql script as superuser. In psql this would look like \i /usr/share/postgresql/15/fix-CVE-2024-4317.sql Any error probably indicates that you've used the wrong script version. It will not hurt to run the script more than once. . Do not forget to include the template0 and template1 databases, or the vulnerability will still exist in databases you create later. To fix template0, you'll need to temporarily make it accept connections. Do that with ALTER DATABASE template0 WITH ALLOW_CONNECTIONS true; and then after fixing template0, undo it with ALTER DATABASE template0 WITH ALLOW_CONNECTIONS false; Checksums-Sha1: 7641de8e4e361e685eddde46d7be25a865daddd1 39780 libecpg-compat3-dbgsym_15.7-0+deb12u1_mips64el.deb b96fca8898889165123237f161092cb9db29394f 21292 libecpg-compat3_15.7-0+deb12u1_mips64el.deb 3dc7a9927b3adaa2a756a2750c2641c3353d7852 250080 libecpg-dev-dbgsym_15.7-0+deb12u1_mips64el.deb bb7bde772cc9484ccdf110dc116e8d8d2f6a8e73 285360 libecpg-dev_15.7-0+deb12u1_mips64el.deb 904f4e76564718dbc3c84c7d36f0985fda6ebdf6 116496 libecpg6-dbgsym_15.7-0+deb12u1_mips64el.deb 180d935e76f4bb8751200fddef2992d856351c84 57076 libecpg6_15.7-0+deb12u1_mips64el.deb 1f6fa0551e9eb797fa6b8e77d9dd4649fa5b690d 92548 libpgtypes3-dbgsym_15.7-0+deb12u1_mips64el.deb 9e4e58f17bd5cc1f19d3966f6dd9924a718f6e5d 42292 libpgtypes3_15.7-0+deb12u1_mips64el.deb d94f49475394df88308bbecec685bf359dba9aa9 149024 libpq-dev_15.7-0+deb12u1_mips64el.deb 8de19eebf13873c8a571d6518733a4bca9cf918d 286416 libpq5-dbgsym_15.7-0+deb12u1_mips64el.deb 89530c919b621ce9dfccd18a8d8f18b3ea6e0071 175980 libpq5_15.7-0+deb12u1_mips64el.deb 7870b2e78c826154f580bebf6e45622f90ded369 17010316 postgresql-15-dbgsym_15.7-0+deb12u1_mips64el.deb c4f6a427fe755d9bfdf0ac005c35cf8e131dc4e4 16956 postgresql-15_15.7-0+deb12u1_mips64el-buildd.buildinfo f79288c2cec16dc81b85f1863a317c962e37fb25 16353164 postgresql-15_15.7-0+deb12u1_mips64el.deb a0c66703eab223bb51128b0b12475da637def90c 2401644 postgresql-client-15-dbgsym_15.7-0+deb12u1_mips64el.deb b0f0606063d58961da67203f02621880a2f622e7 1643984 postgresql-client-15_15.7-0+deb12u1_mips64el.deb 90667b18afa7e77e7d3b643f0fc94f6596ec3407 189952 postgresql-plperl-15-dbgsym_15.7-0+deb12u1_mips64el.deb 9b0e3a9be8735a8cbe586ede68bafe24f6c88d2b 84396 postgresql-plperl-15_15.7-0+deb12u1_mips64el.deb 8f2a966a04e443eb0274e4bd1fb1ebcafabb348b 182156 postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_mips64el.deb 492bcd74303da244d1ebb13c74fce710a2fdfad7 103140 postgresql-plpython3-15_15.7-0+deb12u1_mips64el.deb 00d06c3a557103d255b75d3df3adddd338e4adf1 81296 postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_mips64el.deb 04b57ce27a83b9731df1ad8513c52797c9f035ea 38488 postgresql-pltcl-15_15.7-0+deb12u1_mips64el.deb db19261c194d98dedde5d0d63c733c9261e0c819 1148188 postgresql-server-dev-15_15.7-0+deb12u1_mips64el.deb Checksums-Sha256: da2a7ed1d80eb300722dcf3eb2ad5299412215c9ce833982497a94884c3f7341 39780 libecpg-compat3-dbgsym_15.7-0+deb12u1_mips64el.deb 894c904c1f2560158c91c86ee09052b6c32575b87a8e74f2b449813dbc8c5b7f 21292 libecpg-compat3_15.7-0+deb12u1_mips64el.deb 84171b76172e35191751e2b52c9fa1145fa4ad0e23188277a7d760935487e278 250080 libecpg-dev-dbgsym_15.7-0+deb12u1_mips64el.deb e437ecda20f581c00c200f4749d24d01e019c55b9e7ad900480ef2346a77022e 285360 libecpg-dev_15.7-0+deb12u1_mips64el.deb 3f8ddb54908ebca241c5ec4291120632eca91d546dbca5e797f5da550b04fc90 116496 libecpg6-dbgsym_15.7-0+deb12u1_mips64el.deb 85318c800d4e85c0c512d4c8300894fc5c89e9569ffef9416e854e46a0e721f4 57076 libecpg6_15.7-0+deb12u1_mips64el.deb 0e9ba1b24a17987681352a5677d09f523e5889d227fb70779262c210840f2c96 92548 libpgtypes3-dbgsym_15.7-0+deb12u1_mips64el.deb 72275eac097c9c95190c6dd5aeb244290ce14c4bb7a776b62d1907f9e0c57a55 42292 libpgtypes3_15.7-0+deb12u1_mips64el.deb fe96b879163dea00f03a85c9c73a1f1cc5b1ee6ae605816a922eddb9b06e0563 149024 libpq-dev_15.7-0+deb12u1_mips64el.deb 8fd1338e9c0f758b1c6812809b1cdc5a26ce9e53b40f49e702d924b05f65825f 286416 libpq5-dbgsym_15.7-0+deb12u1_mips64el.deb c5aec6e81b55c96086a1f68d9a9aebf57a55f705b8778a306ffc0e4d617b0b29 175980 libpq5_15.7-0+deb12u1_mips64el.deb 5365f9bb5a877aadb8696813848b8ea64be5a89092e947ef1be0f127bb6ccf59 17010316 postgresql-15-dbgsym_15.7-0+deb12u1_mips64el.deb 9723c9b03b7d039847eaa0b1fc41b2f922c753da177ef0084351f26a18702644 16956 postgresql-15_15.7-0+deb12u1_mips64el-buildd.buildinfo f93bfb799acc36568dd5a55af2373537bf8c1e7373030f8207969588002ea9c0 16353164 postgresql-15_15.7-0+deb12u1_mips64el.deb 056fcbf8c7c6d1df2ddbff68479bc0b16832722af5f59df5b481cc38b8f0f1cb 2401644 postgresql-client-15-dbgsym_15.7-0+deb12u1_mips64el.deb 88d3aa5af0229026201507e12c3531b5889439b10dd2dfb378691f8620602ea2 1643984 postgresql-client-15_15.7-0+deb12u1_mips64el.deb 07e91c8fede1e85bab254704998078ff0b38fabc6a20723b26fb048d94956ac9 189952 postgresql-plperl-15-dbgsym_15.7-0+deb12u1_mips64el.deb f54aa35e1cc658ff7d7860210aac461d7dd7bffaad270fd37fbed594a7f20fa6 84396 postgresql-plperl-15_15.7-0+deb12u1_mips64el.deb 606c2a136f1cc783120879f41e62c814ea75efb6e1efc739417fb99b823bc1cb 182156 postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_mips64el.deb 5670adca2781410b1be09671b602c9a0a64c6665e74f4964c6aa585e6fc20aaa 103140 postgresql-plpython3-15_15.7-0+deb12u1_mips64el.deb 313b4361083933df5657647196746bbb750eebb6f4a2e3dfcfc00bb5813b2d40 81296 postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_mips64el.deb ef43f673ad89e44fc70235039045713acafb7a5a967e15480d48ae2265c9d245 38488 postgresql-pltcl-15_15.7-0+deb12u1_mips64el.deb 36d5d6099ce8d586a3d304149aa97f977c208b495ae2f9defd252ded6c56822d 1148188 postgresql-server-dev-15_15.7-0+deb12u1_mips64el.deb Files: 9a4273eaa010ba35b917316ae4625ef3 39780 debug optional libecpg-compat3-dbgsym_15.7-0+deb12u1_mips64el.deb 44c76df3132f12f5cf0ff3e35a5c19cd 21292 libs optional libecpg-compat3_15.7-0+deb12u1_mips64el.deb d7e70953b5ea168ce22bc8301f1dcb16 250080 debug optional libecpg-dev-dbgsym_15.7-0+deb12u1_mips64el.deb ffeb6d81537e29f1ef5eec18f60e8cea 285360 libdevel optional libecpg-dev_15.7-0+deb12u1_mips64el.deb 12c3aa37427cb8f710fef629914a4b7b 116496 debug optional libecpg6-dbgsym_15.7-0+deb12u1_mips64el.deb d691a5246f2d0b9548931ee7d11ad192 57076 libs optional libecpg6_15.7-0+deb12u1_mips64el.deb 9fe3ef9250a1f53e21775e25176864a8 92548 debug optional libpgtypes3-dbgsym_15.7-0+deb12u1_mips64el.deb ab80b425b8fdb3d788ecb61c2c6f7ba7 42292 libs optional libpgtypes3_15.7-0+deb12u1_mips64el.deb 8373ffb931de3f90be7be5e064d2933d 149024 libdevel optional libpq-dev_15.7-0+deb12u1_mips64el.deb 639ddd98b84836ae3f02901099748740 286416 debug optional libpq5-dbgsym_15.7-0+deb12u1_mips64el.deb 85e9144abf0c79b9a4d1f5f6c5eae4cb 175980 libs optional libpq5_15.7-0+deb12u1_mips64el.deb 17c8bfe4c86d4e703ab1d7b1092374d0 17010316 debug optional postgresql-15-dbgsym_15.7-0+deb12u1_mips64el.deb dba23fb856284b9eb7b43e64df9e225f 16956 database optional postgresql-15_15.7-0+deb12u1_mips64el-buildd.buildinfo 6fc00d0ee5ee8bb76b50b4ba04d843d0 16353164 database optional postgresql-15_15.7-0+deb12u1_mips64el.deb 0db2661ae9c1e21c4bb901f749b84ca9 2401644 debug optional postgresql-client-15-dbgsym_15.7-0+deb12u1_mips64el.deb cd077d099bb4b7573458c2f55e663c84 1643984 database optional postgresql-client-15_15.7-0+deb12u1_mips64el.deb b8a912630f1aa40d33af8f05b3f460f8 189952 debug optional postgresql-plperl-15-dbgsym_15.7-0+deb12u1_mips64el.deb 8bdd0d958e28b73fdd8b95c199480584 84396 database optional postgresql-plperl-15_15.7-0+deb12u1_mips64el.deb 429554114457229aa594fdd579dadeef 182156 debug optional postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_mips64el.deb b31cc4766cc3b5572555915146441a9d 103140 database optional postgresql-plpython3-15_15.7-0+deb12u1_mips64el.deb 338a871e1c0ec743fbd3c79428d481f5 81296 debug optional postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_mips64el.deb 2808af292d2daeda78f4944f95824cc3 38488 database optional postgresql-pltcl-15_15.7-0+deb12u1_mips64el.deb ccbac8a9884ba260eeeb2597e139ab45 1148188 libdevel optional postgresql-server-dev-15_15.7-0+deb12u1_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERCYbPUzzGtvq4mlq066AbFDPUlEFAmZMXz8ACgkQ066AbFDP UlEwAA//bRn58PJJF+66h8sYV16UWxKcCitg9kPr3+pzSOLTV72CwQ3oBDWLG0GB WIt+2HwlTVq6sSc0bL1zk2VuxOO/OUfXP7MXS/6f52H5zT+65NIa5XIs9T968znw T1jv+jOiEovuZZLQtqRQRVjEZeJQQK9sFdngKo/FpJLjuykj43C0JwLvqryfKBo1 dzjuifv019QVvnGsGSuW4QMaTH/z6D/Jvk1tu2ejUJ/zAOagbIKIBOQo0BPoTbjC GZ+0YD2+YzbG707e9mbdopMhb0Dm3Q36EjEmudlkods6vgec66E8AGX94eo+aUmF G/zrt4LUz7n97ZkIdvD+zs5sZTqnc0o4XkrmzGWnWl8GwUhrkC0yjeMbQ/wh0tBf 13A+twrCg43bUDGm5MZWvIm0RzjEy4uPOE829QNkhaufX915e/stP/Sza7in2rBv 6FqFU9ZEP/E8sHCTjf5gpQOZsMS+2nkTywwXk1p8GyfRgqCss9DnPfKXLc1JxKSp +Rgjj5WuvliTXIq55sNRq56hFcHjVAseHUXO0GEHFfgKrGmv7LtXim2S3pYlXnP7 u9WovsR4do0/kwFoAdzHmHKH/3wUkYD1cDzut/aM8u2eavlb4fTaWPjfBnmuZTGi LOPkhdixAiZzAxcpx/7EWIFMicQ3Q4U6uYjjcpqs+gdTvdsRaNw= =5QKA -----END PGP SIGNATURE-----