-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 11 May 2022 15:03:33 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: armel Version: 13.7-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: arm Build Daemon (arm-ubc-04) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.7-0+deb11u1) bullseye-security; urgency=medium . * New upstream release. . * Confine additional operations within security restricted operation sandboxes (Sergey Shinderuk, Noah Misch) . Autovacuum, CLUSTER, CREATE INDEX, REINDEX, REFRESH MATERIALIZED VIEW, and pg_amcheck activated the security restricted operation protection mechanism too late, or even not at all in some code paths. A user having permission to create non-temporary objects within a database could define an object that would execute arbitrary SQL code with superuser permissions the next time that autovacuum processed the object, or that some superuser ran one of the affected commands against it. . The PostgreSQL Project thanks Alexander Lakhin for reporting this problem. (CVE-2022-1552) . * Fix default signature length for gist_ltree_ops indexes (Tomas Vondra, Alexander Korotkov) . The default signature length (hash size) for GiST indexes on ltree columns was accidentally changed while upgrading that operator class to support operator class parameters. If any operations had been done on such an index without first upgrading the ltree extension to version 1.2, they were done assuming that the signature length was 28 bytes rather than the intended 8. This means it is very likely that such indexes are now corrupt. For safety we recommend re-indexing all GiST indexes on ltree columns after installing this update. (Note that GiST indexes on ltree[] columns, that is arrays of ltree, are not affected.) Checksums-Sha1: fb4719412614a8b3d07ab6a25d34774d494cd798 36304 libecpg-compat3-dbgsym_13.7-0+deb11u1_armel.deb 02d0ae27f4ed08877360d95f5d8d3f30c5fb2ba0 22564 libecpg-compat3_13.7-0+deb11u1_armel.deb 4929c560ba3de7b11f517f74a383042753f97c43 225612 libecpg-dev-dbgsym_13.7-0+deb11u1_armel.deb 4179204bdec86b98feb3e894dc1a8a15d0aa7ce5 258860 libecpg-dev_13.7-0+deb11u1_armel.deb ee654f2be7ceb7e464a977034c7749abe6456bff 106788 libecpg6-dbgsym_13.7-0+deb11u1_armel.deb 18845d6e8c64214b5d0144600dde2a9d0bed4638 53840 libecpg6_13.7-0+deb11u1_armel.deb fffcd741a246992579975ffdff9568442a67f21a 84160 libpgtypes3-dbgsym_13.7-0+deb11u1_armel.deb cd50dbb585d870c18514c032a6b26cbc4680bcc8 42660 libpgtypes3_13.7-0+deb11u1_armel.deb abf2db1eba410702724d92ab1f101566a5d7cd59 127740 libpq-dev_13.7-0+deb11u1_armel.deb 199a0de97d64ebbc190ce2a6525c87b2ba122c3f 242368 libpq5-dbgsym_13.7-0+deb11u1_armel.deb 0f6ab9710223a6d571eb9781a31045d8ff61db0c 162080 libpq5_13.7-0+deb11u1_armel.deb 992d714e7e2672303e56daf4abad456c85cc4b17 14029028 postgresql-13-dbgsym_13.7-0+deb11u1_armel.deb 53c00dc5138390bd067478900de84c0ddeac25fc 15824 postgresql-13_13.7-0+deb11u1_armel-buildd.buildinfo 99cd61608f96895fa887ac08a2680a0f4dfe877a 14527772 postgresql-13_13.7-0+deb11u1_armel.deb 5fb3097ce85b5f221286e9b3e5dfb37e2c939df0 1794328 postgresql-client-13-dbgsym_13.7-0+deb11u1_armel.deb 54c3e5419551558429ba70d2d96d2c3555d7ea95 1437416 postgresql-client-13_13.7-0+deb11u1_armel.deb 7af6112c6b069045bd4082b3df8b007c874daa1f 151508 postgresql-plperl-13-dbgsym_13.7-0+deb11u1_armel.deb aef3d01fccdc2c77bb2ee3ae9d1fb9e062ef2537 83492 postgresql-plperl-13_13.7-0+deb11u1_armel.deb d78b81e659fadeae481864ef2d6e69659467566a 153468 postgresql-plpython3-13-dbgsym_13.7-0+deb11u1_armel.deb aa7acdfd9cda6b84ca088756f3f7f3c7d77e899f 101328 postgresql-plpython3-13_13.7-0+deb11u1_armel.deb b03bb0924d9654f7cfe1471588c16e316c837af3 71848 postgresql-pltcl-13-dbgsym_13.7-0+deb11u1_armel.deb 6f6ec456d1d8c8e362ff22f6219382c26b8a2343 38172 postgresql-pltcl-13_13.7-0+deb11u1_armel.deb a86e27995f8eb77974a39d08eef4ac3e674ba5c4 1023320 postgresql-server-dev-13_13.7-0+deb11u1_armel.deb Checksums-Sha256: e137b53ff652bf133054a1d5f9184bf0d91dd8d7ccd400e0ee8e05c3d0f086a0 36304 libecpg-compat3-dbgsym_13.7-0+deb11u1_armel.deb 37eeb62d4d8cfb68d12b5a54ffa374695fc705e6f97302f475607b3c90679b31 22564 libecpg-compat3_13.7-0+deb11u1_armel.deb 6eb2a8595fe20be9845019afd118ab64ead4da01e2badfbb674e0b069cd7acef 225612 libecpg-dev-dbgsym_13.7-0+deb11u1_armel.deb eaca09876df53b38b9937ea2308b51c3a6f0df71499e8fda2615ca846ab42f75 258860 libecpg-dev_13.7-0+deb11u1_armel.deb c68063fae50d9f993e764ac2f5ed83f220d3780a0dba9115887459e58f8515a2 106788 libecpg6-dbgsym_13.7-0+deb11u1_armel.deb b8d53f3915bf84d008c95a7d008848f9ade08e604f8b15b2845bdfd675964de0 53840 libecpg6_13.7-0+deb11u1_armel.deb 4b2fce2278ad526ee249faa9f6e2a92d4c4f24e6ef7215aebbcdb9c5fc5f232d 84160 libpgtypes3-dbgsym_13.7-0+deb11u1_armel.deb 0cd4bcd82ea863f2f03fcf895415934f1ba5c8c6e039adfa0907a51bd7880a9c 42660 libpgtypes3_13.7-0+deb11u1_armel.deb 30d0a952305fa01429ceb92e7cd02acb132a6320a40c355bf34e7ef238a8eaaa 127740 libpq-dev_13.7-0+deb11u1_armel.deb a5bdb646da8b1b33206fc04f8435fb36c6784bf473be4a9a191ef768ac5dacae 242368 libpq5-dbgsym_13.7-0+deb11u1_armel.deb fc0a51570a1843b1e286b482aa3c5483371c4a15cd3bcb725327fbcaec5c79f9 162080 libpq5_13.7-0+deb11u1_armel.deb 8940515bfda5089611c408233a05c6f17a74d6451899e2164c31bbf88138ed5a 14029028 postgresql-13-dbgsym_13.7-0+deb11u1_armel.deb 9b396f9f667796a94d8f043e30026a9ed1dd9eb6cf5f62ce8568f54edfa3c2ed 15824 postgresql-13_13.7-0+deb11u1_armel-buildd.buildinfo 634a41d42af9e1246f96199f36bdec74db2dc42fe3d7fee34b1514f43cc8cf0e 14527772 postgresql-13_13.7-0+deb11u1_armel.deb 3d144a9708eacbf7445a0db78252f1185f15e6577187b9f44ae9b4aae1318373 1794328 postgresql-client-13-dbgsym_13.7-0+deb11u1_armel.deb ec8357d59c2ddb255acb066f9a741408f921c8fe2b9df7f6cc38e0c5fa474ba1 1437416 postgresql-client-13_13.7-0+deb11u1_armel.deb a8387d1913c30d062180658263a42ba4291d81e51233a82248c2a1707f649c78 151508 postgresql-plperl-13-dbgsym_13.7-0+deb11u1_armel.deb 50e16cced1625fd40734a2d32d0d83cfccc7d913e229d0bd2079aec6e155e28e 83492 postgresql-plperl-13_13.7-0+deb11u1_armel.deb 59998e558fcfe60a932ffa49577ed3b78bfebb9bed3c81af04366811b0ded9f4 153468 postgresql-plpython3-13-dbgsym_13.7-0+deb11u1_armel.deb 74825798e4916cdbfb69b74ae2581d0116d8d22b19f0a3e40f1880467bb073e2 101328 postgresql-plpython3-13_13.7-0+deb11u1_armel.deb 80f40f88a4bfe4182a225fe4904297bd8962180a6964d68b61b91d1675834915 71848 postgresql-pltcl-13-dbgsym_13.7-0+deb11u1_armel.deb 16ac1050b3fac0a2c64a251dfb9cb3322b2e91fb78e624c90d2912befbc51208 38172 postgresql-pltcl-13_13.7-0+deb11u1_armel.deb 4a174ea56fc7580512e17c499df60f622ff1fe0be215610e0fdb965c5c68e038 1023320 postgresql-server-dev-13_13.7-0+deb11u1_armel.deb Files: 9f1d08397c83c5598f1ceee1c7cbca05 36304 debug optional libecpg-compat3-dbgsym_13.7-0+deb11u1_armel.deb f468d6f0903fe6b066234fcd19f696cb 22564 libs optional libecpg-compat3_13.7-0+deb11u1_armel.deb 595a178d33ceb42392b6780e4ed20bad 225612 debug optional libecpg-dev-dbgsym_13.7-0+deb11u1_armel.deb 633c67c1348435878a72cbc542434f8e 258860 libdevel optional libecpg-dev_13.7-0+deb11u1_armel.deb 85ae6255f069b2af013a4f5a66417f17 106788 debug optional libecpg6-dbgsym_13.7-0+deb11u1_armel.deb 9a2be716f64e3a0fdc17dc81c87f5707 53840 libs optional libecpg6_13.7-0+deb11u1_armel.deb ad3debfa3b1949584c3a50c8523e3d68 84160 debug optional libpgtypes3-dbgsym_13.7-0+deb11u1_armel.deb 5bad107086ac36430e31465e084bcdc8 42660 libs optional libpgtypes3_13.7-0+deb11u1_armel.deb 598af4c410380eeea16f85435241670d 127740 libdevel optional libpq-dev_13.7-0+deb11u1_armel.deb b3e3bcf08dca1174556a59add5100a2e 242368 debug optional libpq5-dbgsym_13.7-0+deb11u1_armel.deb 0529c12492114b4df076819abc29e50d 162080 libs optional libpq5_13.7-0+deb11u1_armel.deb 1a40a6c534912c52f7ff6cf9ec673353 14029028 debug optional postgresql-13-dbgsym_13.7-0+deb11u1_armel.deb 526ad1a47d0a8653dca9cd588e3feaf3 15824 database optional postgresql-13_13.7-0+deb11u1_armel-buildd.buildinfo 163c683ef82fb0a07dfaac567a157ee5 14527772 database optional postgresql-13_13.7-0+deb11u1_armel.deb 48621806307ff96b0d8c0fb17f06f8b4 1794328 debug optional postgresql-client-13-dbgsym_13.7-0+deb11u1_armel.deb 331059f4bce9311ff42353d3fcdd5db3 1437416 database optional postgresql-client-13_13.7-0+deb11u1_armel.deb ede3a125fcc3fea7995a10320d7105cb 151508 debug optional postgresql-plperl-13-dbgsym_13.7-0+deb11u1_armel.deb b65f872197289856c4d7b3177b0293cd 83492 database optional postgresql-plperl-13_13.7-0+deb11u1_armel.deb 121913d7a7c6fa1cab80d8c42b7659cd 153468 debug optional postgresql-plpython3-13-dbgsym_13.7-0+deb11u1_armel.deb dee62601729f3158dcf508d2c3371122 101328 database optional postgresql-plpython3-13_13.7-0+deb11u1_armel.deb cdc0be8c62575bc905eabd052a586129 71848 debug optional postgresql-pltcl-13-dbgsym_13.7-0+deb11u1_armel.deb bb45fd1f9a95b9136204cc4b9f86de3e 38172 database optional postgresql-pltcl-13_13.7-0+deb11u1_armel.deb 610e0c545d0ed98b8c9dd776eccf8fec 1023320 libdevel optional postgresql-server-dev-13_13.7-0+deb11u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEbnebi1aZTKY54oji/NUSQB8TXIgFAmJ72p8ACgkQ/NUSQB8T XIiiuA//XXQqBxku6v5mesUGXYVrsQu9dcH+iXvyK7xoX3dPyJK1mVRnQN9x3HLA HD8/kPS+DSz1sO3LM3AZ6F0MRONKhrBWah2QiNHjWbmIyFAowJ6Byy2kOPlg9GJ1 a0pNXfoGO2TqL0KgYgpV7iQzNBdH93/H3TMouvXo83ZPr9x5Pkz8+8m9eCcuNxxK D38om10j1iOFGNJW8ObhGFvT7xR/W4i5Yyz4KM46BSH5PsEoRMq/HBJz/zSvdOZV ZfqeNUSCHyOXtbxMQmWPizRd4mgu87/5sQU86slCDgD84UZPzplm5rGOigDrTPLg 80Xw67jPn1W08ecIV174YTVIOucc0GuWSQSmZ9fQu54L+g/Di7tZVZv4BTOazAqy TRRZ+Q9IYHenZlOMv9LJO3x8L2nW0zJm4TAeCqLmIVwsgrrpgllGcnfjJ8uV83sj qcZnnhHGOGkaYgi4UkjKANdIVcEWCM7NyAqIEonlh8Jw9UNh28U8BtXtM0miQcC2 BzIaK5wO3t8Zzx6S7/2uErRI5nLaRYx9tkjCX8YZbIRLdsEQd6UAXOlgNfGtbmeb Xl+C4QHAs/X+CpdlwpuOwWjuj1u3s48EbPCTbkDtHfU9mroo4JLaXb/xkd2kYZBz 7zu2i4z8xo8+FNjgP15QEGPwfF/EBlw1JCbaQjnRLo50G/gT3Ho= =hgz2 -----END PGP SIGNATURE-----