-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 11 May 2022 15:03:33 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: s390x Version: 13.7-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: s390x Build Daemon (zandonai) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.7-0+deb11u1) bullseye-security; urgency=medium . * New upstream release. . * Confine additional operations within security restricted operation sandboxes (Sergey Shinderuk, Noah Misch) . Autovacuum, CLUSTER, CREATE INDEX, REINDEX, REFRESH MATERIALIZED VIEW, and pg_amcheck activated the security restricted operation protection mechanism too late, or even not at all in some code paths. A user having permission to create non-temporary objects within a database could define an object that would execute arbitrary SQL code with superuser permissions the next time that autovacuum processed the object, or that some superuser ran one of the affected commands against it. . The PostgreSQL Project thanks Alexander Lakhin for reporting this problem. (CVE-2022-1552) . * Fix default signature length for gist_ltree_ops indexes (Tomas Vondra, Alexander Korotkov) . The default signature length (hash size) for GiST indexes on ltree columns was accidentally changed while upgrading that operator class to support operator class parameters. If any operations had been done on such an index without first upgrading the ltree extension to version 1.2, they were done assuming that the signature length was 28 bytes rather than the intended 8. This means it is very likely that such indexes are now corrupt. For safety we recommend re-indexing all GiST indexes on ltree columns after installing this update. (Note that GiST indexes on ltree[] columns, that is arrays of ltree, are not affected.) Checksums-Sha1: 4640f83c75ad15fff40464bb45641df18e3ee8ee 37388 libecpg-compat3-dbgsym_13.7-0+deb11u1_s390x.deb ca15a4abcc75540e7779d4f3dc7622d64664caaf 23476 libecpg-compat3_13.7-0+deb11u1_s390x.deb 0ee30abc2890e0f71abd4ab8f45068c24cf992a5 243104 libecpg-dev-dbgsym_13.7-0+deb11u1_s390x.deb 0fda6bb83dd730115316e90da3576d83ac5cda67 267848 libecpg-dev_13.7-0+deb11u1_s390x.deb 70e366d01f2340a850dd618e54d705408b64c900 110816 libecpg6-dbgsym_13.7-0+deb11u1_s390x.deb 01c29330ce779c61896dbad8d1d5d731daea2ee3 57416 libecpg6_13.7-0+deb11u1_s390x.deb 5bfca94172f171cacb16aecb115f4170a6188b2f 89152 libpgtypes3-dbgsym_13.7-0+deb11u1_s390x.deb 6e8b3a0d8434852c997fe906125b41dc286b0413 45252 libpgtypes3_13.7-0+deb11u1_s390x.deb a1f4f3f87eebc2f7fe9b63c11e735bc5b69c37ca 134236 libpq-dev_13.7-0+deb11u1_s390x.deb 744a52a600d6dbf00dc633b856c6c9f55ca9952a 256676 libpq5-dbgsym_13.7-0+deb11u1_s390x.deb 08f76fcd84326cb714aca678618a756fa2f2633d 172528 libpq5_13.7-0+deb11u1_s390x.deb 7beafa98e46d314aa1c81ba92df6fa2a88ccc85d 14791552 postgresql-13-dbgsym_13.7-0+deb11u1_s390x.deb d2b32d7699f7876692c51f0f662c74cd4ee807e9 15845 postgresql-13_13.7-0+deb11u1_s390x-buildd.buildinfo 738b761dd1a82b123688b131b90ce3ed338ef8c1 15802028 postgresql-13_13.7-0+deb11u1_s390x.deb d5c2cfe791df74cbd3020e98cbf1a2413f26a4af 1859240 postgresql-client-13-dbgsym_13.7-0+deb11u1_s390x.deb 019d4bc339bc04f5c0592c72ac1e5717c52c05c2 1468244 postgresql-client-13_13.7-0+deb11u1_s390x.deb 752cbd6762e37451f2d15612d60603c8fb6059a5 155688 postgresql-plperl-13-dbgsym_13.7-0+deb11u1_s390x.deb dd0d4ac095a691a851ac9b4fc6e57c929a43be25 84428 postgresql-plperl-13_13.7-0+deb11u1_s390x.deb 7e21f9cf6c53d201c96041340338faeb27516f6a 154560 postgresql-plpython3-13-dbgsym_13.7-0+deb11u1_s390x.deb 62bf9b3005914781533590915bae6567c7f45227 103580 postgresql-plpython3-13_13.7-0+deb11u1_s390x.deb 0d1c4ba23c648e5749809cc31acee41de733dc25 73284 postgresql-pltcl-13-dbgsym_13.7-0+deb11u1_s390x.deb 078a34948776c686659db537a4a8cd529d78923e 39532 postgresql-pltcl-13_13.7-0+deb11u1_s390x.deb 5b62693546ff7df9a42043260e71d025b7410bd9 1029320 postgresql-server-dev-13_13.7-0+deb11u1_s390x.deb Checksums-Sha256: dcf103ce61ac34bc931c8b371a821dec1d36df47e710a36f65ea92c070b2947a 37388 libecpg-compat3-dbgsym_13.7-0+deb11u1_s390x.deb c2d89970cddf170475e629b43f19b3b87e107bfbb6bfa8280d6d260df5d76e3e 23476 libecpg-compat3_13.7-0+deb11u1_s390x.deb 2220ffc0520db7062b9ed4684865fab7e913ff20bc81879fc1ef950095fa1b25 243104 libecpg-dev-dbgsym_13.7-0+deb11u1_s390x.deb 61ed30ee6bde458f960f8a4af0f1005dec35bb16f9cbca29ca663c72717cff71 267848 libecpg-dev_13.7-0+deb11u1_s390x.deb a110dd7ff23c6f59c7b7ddd84332a2e1e62eaa2a7b9dce11962705078396a646 110816 libecpg6-dbgsym_13.7-0+deb11u1_s390x.deb fe42c04b6097d14c0868654663194dbc5e9426936f58f0bbd9597e4bfe355f56 57416 libecpg6_13.7-0+deb11u1_s390x.deb ce8382b95af1d3497a1795e85319aba608c5cdf8e45dc1c0b8c9b16f75a05f5f 89152 libpgtypes3-dbgsym_13.7-0+deb11u1_s390x.deb fb3aac2298ea451349946c971515cc185e7e39a3c6bec74d191ae9b4c4a3cea4 45252 libpgtypes3_13.7-0+deb11u1_s390x.deb 03aa670053b4f7822a141348c7acf02533b58a7560eb70278ec0d9bed1623570 134236 libpq-dev_13.7-0+deb11u1_s390x.deb 863ac8f7382603293c5bc554c0645762dd1eaeb76e2c867e1a410b313c23b503 256676 libpq5-dbgsym_13.7-0+deb11u1_s390x.deb 846cfc4da569e71d240cfd7b5e98c1c7971b67a940da89e7449429e7643f9445 172528 libpq5_13.7-0+deb11u1_s390x.deb 86791a144f98fdaa81bfb93527891a694a1b72f2d0fac43499cf1687300e37c9 14791552 postgresql-13-dbgsym_13.7-0+deb11u1_s390x.deb 4eb413ce68bd687b94e1fbe50dca1244d93ee39d1294de544b006a565424dff9 15845 postgresql-13_13.7-0+deb11u1_s390x-buildd.buildinfo 2d4dd410845f2a403148d0b1b06366a6108b34ac658a146d09a207666af74cda 15802028 postgresql-13_13.7-0+deb11u1_s390x.deb 1a534008ef6ed2569a43f929a139544f43bb189e49a2f18843597c9a6a2fba05 1859240 postgresql-client-13-dbgsym_13.7-0+deb11u1_s390x.deb d86b16095b4ea990fdc53e25d7c034ea690b4343716421fdf26821206807ec13 1468244 postgresql-client-13_13.7-0+deb11u1_s390x.deb 6bfdd18df1b65a3391f30fbc982c0485627f2308cf212f753efa3e83e0689b44 155688 postgresql-plperl-13-dbgsym_13.7-0+deb11u1_s390x.deb 01d645c3e39e236ce709a0ddcb2e2994bf8964d58a0205da72891d7e415897c3 84428 postgresql-plperl-13_13.7-0+deb11u1_s390x.deb c1d9023fb83d849377f224455cb95ba49042315d3223ce9cb9be3a49db579030 154560 postgresql-plpython3-13-dbgsym_13.7-0+deb11u1_s390x.deb 7d9fe8afcdb72bf2588c18d492d5b2ede796b35a4e227fb8b48da3c0f6a915b3 103580 postgresql-plpython3-13_13.7-0+deb11u1_s390x.deb f69d3397f1daa11b52bc9633ec10c098a99ce4cf7af07e07d5ea3cd07e230eb6 73284 postgresql-pltcl-13-dbgsym_13.7-0+deb11u1_s390x.deb 8b819405f13d7639b4adadc3a7bed84446fcf046fd944621158db71cb4b6794a 39532 postgresql-pltcl-13_13.7-0+deb11u1_s390x.deb ac43c5e32e195a9b0b2248fdab0e4289d875f9d9ccc9622b532c3b87bdeb2407 1029320 postgresql-server-dev-13_13.7-0+deb11u1_s390x.deb Files: 2b2d7599df93feb1aceff767e70cfd52 37388 debug optional libecpg-compat3-dbgsym_13.7-0+deb11u1_s390x.deb e057e2aeef6956fa198267ed161faaa4 23476 libs optional libecpg-compat3_13.7-0+deb11u1_s390x.deb d841cb71a95df12d70b3100ab1fbbee0 243104 debug optional libecpg-dev-dbgsym_13.7-0+deb11u1_s390x.deb 3fb6d68ac85161689cbd00d7803f2b0e 267848 libdevel optional libecpg-dev_13.7-0+deb11u1_s390x.deb 22ee437d4cf3cb25092a672d12757437 110816 debug optional libecpg6-dbgsym_13.7-0+deb11u1_s390x.deb cd665bfa3e06b1d67f8b2b4776b6b61c 57416 libs optional libecpg6_13.7-0+deb11u1_s390x.deb d63f319ade5f06564ccaa44d3f424c0e 89152 debug optional libpgtypes3-dbgsym_13.7-0+deb11u1_s390x.deb 329fd1cc1096bc8bba91f61ff6799c44 45252 libs optional libpgtypes3_13.7-0+deb11u1_s390x.deb e447baaab2e71fa1eb337ea13eab3ffa 134236 libdevel optional libpq-dev_13.7-0+deb11u1_s390x.deb 558fc141da8d9d8a5e52685399979029 256676 debug optional libpq5-dbgsym_13.7-0+deb11u1_s390x.deb eca7defcbd6d8159b1685767636f06dc 172528 libs optional libpq5_13.7-0+deb11u1_s390x.deb e88bd29ac42d667a36edaec4fbd1b11b 14791552 debug optional postgresql-13-dbgsym_13.7-0+deb11u1_s390x.deb 8d2898976da673e88e86f045b468d080 15845 database optional postgresql-13_13.7-0+deb11u1_s390x-buildd.buildinfo e88a0c7860a4978a319c7f285fe30ca0 15802028 database optional postgresql-13_13.7-0+deb11u1_s390x.deb 2bcdf0c1fa0e9febf8ade70ceb93484f 1859240 debug optional postgresql-client-13-dbgsym_13.7-0+deb11u1_s390x.deb 9f1eab1cfd4c19b86a643e3e3c9ad3ba 1468244 database optional postgresql-client-13_13.7-0+deb11u1_s390x.deb fdc5ba6898d5d5cc065bac254792d503 155688 debug optional postgresql-plperl-13-dbgsym_13.7-0+deb11u1_s390x.deb 23b46ed750bc6798471436058abc6a63 84428 database optional postgresql-plperl-13_13.7-0+deb11u1_s390x.deb 776dc4f008422f5941002346f920b5a6 154560 debug optional postgresql-plpython3-13-dbgsym_13.7-0+deb11u1_s390x.deb a4709b8efeca7b8c64e318d2c512ca5a 103580 database optional postgresql-plpython3-13_13.7-0+deb11u1_s390x.deb edcbb2ef3aa287fd6cf7fa5008f520d1 73284 debug optional postgresql-pltcl-13-dbgsym_13.7-0+deb11u1_s390x.deb 3bab70f88c18a0762328320e17e51057 39532 database optional postgresql-pltcl-13_13.7-0+deb11u1_s390x.deb 485384439adb84be2c968302104e87a2 1029320 libdevel optional postgresql-server-dev-13_13.7-0+deb11u1_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEEwflLi3dfm21PN8mA0zNy/MAOYMFAmJ7wigACgkQA0zNy/MA OYOtPw//THVo1cigzMrgW6hM9PJBNkx77lbR+b1GauaQUT62/nJec48m0dOewhSc YRmHgw9Osc8KMsxtZiEHc0FDWaFxmv9zqjcb6NAtHGKhfYPVur/zgcyTcjG584Pf 3C6G3nSg0OCXpgETHdLXC3LqSLPoE0FExYPXGRxiQIQmF6tF01xJ+04agJvhL0Zz U6gA8Idl2mVbPYLoXsr/a8TEjvedrbvbsvDgLFJBB5Lg2AjnRt2ww5xn5m2G098O FoMbmmUINhYlWRiuYLC1jSpanxXBI3WsbuJszqT/3xPC7RCWfSEfImdXbufRO+kF JOMhy6LgD6hkAnvJr7idfx65QRb/JeL1WzzkR6rTvqGCNa/t2SMqxdB3DEMT0nnt +tldpi2nle0jT/ST4x616sikdivQESwLjVcxQdcOe5yTqntkS6Tv4mFih2LtQtlG xclv+Z57Y+i5+lUFDSvjiLNeXpghr0tJbLGqfnwYjYPTl5Oonb4IuF8PZXqqHDFa pSstCt01yv9TmxJn+TGs+KCYIyEKtN+dUXmIsAo8kgl5fzJAtk/MJE9VeXflg4m8 +PIoV79sJIMI/xjaKzgsYPSRvCi/weoWcpQwpHNqHyT0kYesb+5+ie8VmDLRM5XM lx5Do9dLqaOl5r6DmzAzjP7tuLmfPUU6ZPRTq/Ios5uJMrgsqUM= =Qnm2 -----END PGP SIGNATURE-----