-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 06 Feb 2024 13:37:19 +0100 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: armel Version: 15.6-0+deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.6-0+deb12u1) bookworm-security; urgency=medium . * New upstream version. . * Tighten security restrictions within REFRESH MATERIALIZED VIEW CONCURRENTLY (Heikki Linnakangas) . One step of a concurrent refresh command was run under weak security restrictions. If a materialized view's owner could persuade a superuser or other high-privileged user to perform a concurrent refresh on that view, the view's owner could control code executed with the privileges of the user running REFRESH. Fix things so that all user-determined code is run as the view's owner, as expected. . The PostgreSQL Project thanks Pedro Gallegos for reporting this problem. (CVE-2024-0985) Checksums-Sha1: 4e66a4b6dd998629b7e2a1eb1427933852ee143f 37140 libecpg-compat3-dbgsym_15.6-0+deb12u1_armel.deb ae7739940722cd76870bb22efe8663ecb883a058 19264 libecpg-compat3_15.6-0+deb12u1_armel.deb fb39e443d370fc7a094e53f92ccbe2f8566f8993 231580 libecpg-dev-dbgsym_15.6-0+deb12u1_armel.deb c888e51bb9965f6c0509d280e2fdce4858d78cfd 270256 libecpg-dev_15.6-0+deb12u1_armel.deb cbe92ed67d889b425b32d37e14c619149ac1f11d 110560 libecpg6-dbgsym_15.6-0+deb12u1_armel.deb 632ba738245c0f6db307698fbee22080e03ea2f2 53368 libecpg6_15.6-0+deb12u1_armel.deb 791b493b94e28870ee2ba04282a9bf26e25e2bf6 86552 libpgtypes3-dbgsym_15.6-0+deb12u1_armel.deb 1424f33f0ae9574e15492d8c62fc77b89ebbe577 39680 libpgtypes3_15.6-0+deb12u1_armel.deb 79b75f748e3e085e77cb1abba931a29cfb6bbe11 131148 libpq-dev_15.6-0+deb12u1_armel.deb 194a8291b1d4a49018ad4cdd3f27adef73d0aff6 269572 libpq5-dbgsym_15.6-0+deb12u1_armel.deb 0b1aa34a37139d65165d32e73bec6023e8445b35 167124 libpq5_15.6-0+deb12u1_armel.deb a15c27c24f4c542c9d6c268fced2744e9dbe80f3 16085992 postgresql-15-dbgsym_15.6-0+deb12u1_armel.deb 6082d1f820d2945718016674bf8c79e6a4387512 16680 postgresql-15_15.6-0+deb12u1_armel-buildd.buildinfo 9562464249a34b8e17ed6577ccf538871a084137 16105264 postgresql-15_15.6-0+deb12u1_armel.deb dcc08d94f8451c12b63a47208c4dbb602e46a4c7 2221156 postgresql-client-15-dbgsym_15.6-0+deb12u1_armel.deb 6612536769107b66f163853eeeb6a60dec0b9158 1598384 postgresql-client-15_15.6-0+deb12u1_armel.deb eced74c4a3e872c264a78f70e162db06e8e4262a 181896 postgresql-plperl-15-dbgsym_15.6-0+deb12u1_armel.deb 1c5be9b12ac446ccbc379fab54469b6070d8fcf8 85020 postgresql-plperl-15_15.6-0+deb12u1_armel.deb 02cca63211bb3dc547c807c58a67b2d2d26e0e09 171812 postgresql-plpython3-15-dbgsym_15.6-0+deb12u1_armel.deb 2d950bbe575a53207a8e204da1cebdcadbcc169f 104008 postgresql-plpython3-15_15.6-0+deb12u1_armel.deb 95cbcca0bbf3617aab334c6505d711b6ce5bf9ec 77876 postgresql-pltcl-15-dbgsym_15.6-0+deb12u1_armel.deb 92d7a0fb7df7af22531dc0c2238bd1d4082c737f 37744 postgresql-pltcl-15_15.6-0+deb12u1_armel.deb 1ff81a115d64796384e536561c1ca0681bfc7ed1 1125712 postgresql-server-dev-15_15.6-0+deb12u1_armel.deb Checksums-Sha256: dcf9b800961dd111c4d4b82d7ff9c262aa7230b1b172d3f40dc464886c783774 37140 libecpg-compat3-dbgsym_15.6-0+deb12u1_armel.deb 471a03f171e26f51300d2ee16b8ae3334496d11617335f8b2862352c00d15596 19264 libecpg-compat3_15.6-0+deb12u1_armel.deb 5a5be18b2959d8d7a4cef34277c162258ad0f76bb4d77e17a0db8df0cb4faf68 231580 libecpg-dev-dbgsym_15.6-0+deb12u1_armel.deb ac65762f6cdbd1432e870e0be215b2687364aa0727a770a08db227d3af451698 270256 libecpg-dev_15.6-0+deb12u1_armel.deb e5cc5e81861e04ee1ceb6e57f9894b446b9f4a35bd5016dca3708f18ae62f774 110560 libecpg6-dbgsym_15.6-0+deb12u1_armel.deb c658786edcdfe9b665a291ab88c757ecad20f69b7c0adb10006da0587641a6c7 53368 libecpg6_15.6-0+deb12u1_armel.deb b33ddfa000b3cd0ff4cfdb71f5c57e36aad9aea4de9d1cc793649a73babc5440 86552 libpgtypes3-dbgsym_15.6-0+deb12u1_armel.deb 499bca16d868a305958dcd813337d31636ec9e0e1d408e5e49ebcfc4a5a6adc4 39680 libpgtypes3_15.6-0+deb12u1_armel.deb d0754060f5850df04fe1b41571e5a887110864ff13148d217086981af614f6d7 131148 libpq-dev_15.6-0+deb12u1_armel.deb e5603c3bd669d01ff9ece926d3d31a14925ffc69a2fee5aab674ec1408fd19a0 269572 libpq5-dbgsym_15.6-0+deb12u1_armel.deb eb2c79c10ba40f495af88c62014c04a337e14e71e7a12d18783a11dbc0153673 167124 libpq5_15.6-0+deb12u1_armel.deb 9209687579e1d6e9b320f99e89a318c4fdb9cec452f4a0106bef7b8dccddc2d9 16085992 postgresql-15-dbgsym_15.6-0+deb12u1_armel.deb b3575acd5ae1a26515f42833efe491fce707723a779f0f9adf0301376a08d9b2 16680 postgresql-15_15.6-0+deb12u1_armel-buildd.buildinfo 4ccc32b54fa0a03bc039a242d18e602bc21130474505e78ab775414d1bf80643 16105264 postgresql-15_15.6-0+deb12u1_armel.deb e7c56692fd06b1592ab5e388c05c03e533b71c8fa305398de0d87fbc4163d0d6 2221156 postgresql-client-15-dbgsym_15.6-0+deb12u1_armel.deb 7c3ef43b3a7e9babe31bce8b14af19f75242e3428a3a35b7a44ff9f0c7786e82 1598384 postgresql-client-15_15.6-0+deb12u1_armel.deb 747140021e2f6b54043e01e0b62fc6642a16a7ef81f6a2d49ea9d1be9435226b 181896 postgresql-plperl-15-dbgsym_15.6-0+deb12u1_armel.deb 7a5d8f4b312835ef1bac4caf1d9613e9d85d74366e8f88e77eee9172797141f7 85020 postgresql-plperl-15_15.6-0+deb12u1_armel.deb a134016b3d0ce0ea4e8bfe2ae1887745adad18c14cecdd13534e34496adfcea3 171812 postgresql-plpython3-15-dbgsym_15.6-0+deb12u1_armel.deb 131b51201619fc329cbe56adf38ce1b8522138c64d27144d456e21f8c9e2a75d 104008 postgresql-plpython3-15_15.6-0+deb12u1_armel.deb 8fbcef6bf3c91e3402c5b4c265ce7e05a4dff409c1f12e68703ad041b7234534 77876 postgresql-pltcl-15-dbgsym_15.6-0+deb12u1_armel.deb a8215885a3e68844062e28e19da67e040b7f10ac1ed0b74f539926da1d300efa 37744 postgresql-pltcl-15_15.6-0+deb12u1_armel.deb 8cf5bbd830f388b3773fd9f6656f1b77f413ac327218088997c2359b5b67c1a4 1125712 postgresql-server-dev-15_15.6-0+deb12u1_armel.deb Files: 7664b2a13c400df62715e1e5540bca67 37140 debug optional libecpg-compat3-dbgsym_15.6-0+deb12u1_armel.deb 1c2b7478b27cfa745456a359bbfaf2c8 19264 libs optional libecpg-compat3_15.6-0+deb12u1_armel.deb 05ecf54b50356e36a95a9aaf96b6db5d 231580 debug optional libecpg-dev-dbgsym_15.6-0+deb12u1_armel.deb 8182e2057fa2192ae71a7c673236304a 270256 libdevel optional libecpg-dev_15.6-0+deb12u1_armel.deb 0b9c13864c99fcf58c06f79f7a4fdc4a 110560 debug optional libecpg6-dbgsym_15.6-0+deb12u1_armel.deb f659db3b5264212e1cad783bfc6d8a83 53368 libs optional libecpg6_15.6-0+deb12u1_armel.deb 6bd7ba7e1429a330bd3d35b15dc62e8e 86552 debug optional libpgtypes3-dbgsym_15.6-0+deb12u1_armel.deb 89947bc8f55c9b0e312be2923b635cbd 39680 libs optional libpgtypes3_15.6-0+deb12u1_armel.deb ae2e47c127f2ba16768cbe9d3febc9ea 131148 libdevel optional libpq-dev_15.6-0+deb12u1_armel.deb bbb16b70e9615351eb2ff98a51f770b5 269572 debug optional libpq5-dbgsym_15.6-0+deb12u1_armel.deb a4fce6906fe598c9d6f2adc3554391f6 167124 libs optional libpq5_15.6-0+deb12u1_armel.deb 837dcb9c90fd3836a7ec6dc283932bb6 16085992 debug optional postgresql-15-dbgsym_15.6-0+deb12u1_armel.deb 93097c0c3465c5bc338cb650b2408569 16680 database optional postgresql-15_15.6-0+deb12u1_armel-buildd.buildinfo 789ec848c0f25714287b87c7abfb9118 16105264 database optional postgresql-15_15.6-0+deb12u1_armel.deb d129eb28447201e5016d044ef5411c0f 2221156 debug optional postgresql-client-15-dbgsym_15.6-0+deb12u1_armel.deb 9bf70a14bd0bdb219406ab3f48825bdf 1598384 database optional postgresql-client-15_15.6-0+deb12u1_armel.deb 9ef7d3d757a6b3e3c4955336ea55a0cd 181896 debug optional postgresql-plperl-15-dbgsym_15.6-0+deb12u1_armel.deb 5a665bb6fdf7f2df8d728e96a14f2628 85020 database optional postgresql-plperl-15_15.6-0+deb12u1_armel.deb 6720bc427cc81b87ee0ab34c7abf9cfb 171812 debug optional postgresql-plpython3-15-dbgsym_15.6-0+deb12u1_armel.deb a7bdddb021b3e637fa19696ed3a93924 104008 database optional postgresql-plpython3-15_15.6-0+deb12u1_armel.deb d7662eb8e5507b4d12aee1d3015f328a 77876 debug optional postgresql-pltcl-15-dbgsym_15.6-0+deb12u1_armel.deb 8f72bb45f02f9576d85062c373e251e6 37744 database optional postgresql-pltcl-15_15.6-0+deb12u1_armel.deb f37876d25056bdf37c93d116bd265e3b 1125712 libdevel optional postgresql-server-dev-15_15.6-0+deb12u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBv+o19JDIRm4yIQ5CeROIpkCGwcFAmXMxDcACgkQCeROIpkC GwcuQw/9E75EGX/7RXlvb4kzfzNIl9vjI5/N/3AJfRcvLGwKOxk9P13pHaddVPdO qrhnCvgokLVXUhBdzhQ0x4xINPbuSpJi4KFvByqZZoK4F+vtli+39t8kj2hgH909 lD1eAQMxH0GECmRepdRMeyYhKdbJ/UcV39YX2EWheHNEXnWVRFDNFxAmmy/TGSVG DQPc/K3PBh91pkYsn6kQ13UrUFw4jwgR3y+dgWIEJzVVkNPNR1S2o3jIyoKLyGt6 aJltJElCEHu5xu10IOqqqS7d2TJFNJXKqcCCY78jBcIgKuDxkOBOdOsEsBFiaMop k+U0GRL8SDALASMm1/rpFe89SZgdpEauaJLarXDIq16fj/STXo7fcNqpx/EqRAjd tiVd1LiqkGdrVKcs4uwJh1XbZ56GftfM4+mYqLVqYlEXYuwuDJn3TQXFwI/45P4Y 85yP014RrDrmdiA6S/upzjKVH8s7pZJhRJ1IqL3FoaKnR6j/rTZcRtTdM1TfiaMJ zlzLgvec6UACpBKEakL+im1G89JypI7Go7qAJB7DYrxNZbDJIzCsGBfCkcbb6kt+ Mn0abWyLNccgahjBI8DjGuvrbBDtMe1dCk8CjtQJmyqte+kkTpLBfAMy2vnKKIpB gcvJwZOU3fiHgDt8GaNSc1eCokwT7NOexfmXZZPcQef+29sdiPg= =B/lp -----END PGP SIGNATURE-----