-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 11 May 2022 15:15:30 +0200 Source: postgresql-11 Binary: postgresql-doc-11 Architecture: all Version: 11.16-0+deb10u1 Distribution: buster-security Urgency: medium Maintainer: all Build Daemon (x86-csail-02) Changed-By: Christoph Berg Description: postgresql-doc-11 - documentation for the PostgreSQL database management system Changes: postgresql-11 (11.16-0+deb10u1) buster-security; urgency=medium . * New upstream release. . * Confine additional operations within security restricted operation sandboxes (Sergey Shinderuk, Noah Misch) . Autovacuum, CLUSTER, CREATE INDEX, REINDEX, REFRESH MATERIALIZED VIEW, and pg_amcheck activated the security restricted operation protection mechanism too late, or even not at all in some code paths. A user having permission to create non-temporary objects within a database could define an object that would execute arbitrary SQL code with superuser permissions the next time that autovacuum processed the object, or that some superuser ran one of the affected commands against it. . The PostgreSQL Project thanks Alexander Lakhin for reporting this problem. (CVE-2022-1552) Checksums-Sha1: dae40889b436a395fefd06ba85288c450ea39c0d 9478 postgresql-11_11.16-0+deb10u1_all-buildd.buildinfo 6b2c814e56b5f6c925855d422279fef7bb862cad 1864296 postgresql-doc-11_11.16-0+deb10u1_all.deb Checksums-Sha256: d3e9a1ff46f04e578ac762dd7d76861240f1e88a08b07c23453db2dd971d91eb 9478 postgresql-11_11.16-0+deb10u1_all-buildd.buildinfo 709ce6e42af5b79d94b57f254944ef19cee3b1ab0453b7193472cfb8aa51b854 1864296 postgresql-doc-11_11.16-0+deb10u1_all.deb Files: c6b30731a3b98ab6321223c0c31415ae 9478 database optional postgresql-11_11.16-0+deb10u1_all-buildd.buildinfo 1f6a01078b4d67ae92701af044a5cb81 1864296 doc optional postgresql-doc-11_11.16-0+deb10u1_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEeNXCsz+mBQUIYcOwyd+jzxgwoBwFAmJ7vFwACgkQyd+jzxgw oBx7HxAAkxFHKcPQS3KwHd6K0NkEcjRfI8yKp+TFWY8aQtFTjnLFA3Jrold7zXQ5 Igsi5sUNVfPScKXStoWQS+BeMH5v7oVnXA9OqjjFrP0xWDf1lXEiy5ZSxj6ZIAFG gPe7YV/iptEfADKQr4DHTJErhjfshZGIju3TIHdNPsr76JOxkEDkXAYSDUHUof5N YO9yIxxeMNxG1Wh/dGKSeW5GMBr0AKyKiJh4hLBkRigSk/mzVko3V7OG6odZ5I1i zFBTbutc+Yj8btKw7axZ1NvTtn3w4q3caiNMlkiSkAJdo/v/GrwvvGZ8mY+UIomf c5Paw5eg1k3/JCPGPFVnCKsrlkSwlizbkqQymfGoxD9KLbSJWeh3GEtYSucoz4Yh GlxXwarrOo+pm1v181BIZR78NKk25/4qLu0CYZRrPw/59UPZfqz2cHvmpYeZfkXa DE5aokYQKC3qfEsjgfa5Fkf9jkKCK6rSCzuX/oiGMrTnvQ8eKmgu9RWiwYzQNDDQ 2YkRAdADByw9RL7VEId5xCI0tFsNfbxpolpIpNWlKkXSY08z0F4Y1/q9i233sz7M QLK4Sc8W0rRYEr94zM1s6HaHEbKT6+NQZdIPFyyZXTZQLeAoxe3j/g5cngPboC8N QCL+JkeDc+4Ax38u6iIlKxTbinZbi7PFRN5+6qao+ENCRk3AbVs= =g+kl -----END PGP SIGNATURE-----