-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 11 May 2022 15:15:30 +0200 Source: postgresql-11 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-11 postgresql-11-dbgsym postgresql-client-11 postgresql-client-11-dbgsym postgresql-plperl-11 postgresql-plperl-11-dbgsym postgresql-plpython-11 postgresql-plpython-11-dbgsym postgresql-plpython3-11 postgresql-plpython3-11-dbgsym postgresql-pltcl-11 postgresql-pltcl-11-dbgsym postgresql-server-dev-11 postgresql-server-dev-11-dbgsym Architecture: amd64 Version: 11.16-0+deb10u1 Distribution: buster-security Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 11 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-11 - object-relational SQL database, version 11 server postgresql-client-11 - front-end programs for PostgreSQL 11 postgresql-plperl-11 - PL/Perl procedural language for PostgreSQL 11 postgresql-plpython-11 - PL/Python procedural language for PostgreSQL 11 postgresql-plpython3-11 - PL/Python 3 procedural language for PostgreSQL 11 postgresql-pltcl-11 - PL/Tcl procedural language for PostgreSQL 11 postgresql-server-dev-11 - development files for PostgreSQL 11 server-side programming Changes: postgresql-11 (11.16-0+deb10u1) buster-security; urgency=medium . * New upstream release. . * Confine additional operations within security restricted operation sandboxes (Sergey Shinderuk, Noah Misch) . Autovacuum, CLUSTER, CREATE INDEX, REINDEX, REFRESH MATERIALIZED VIEW, and pg_amcheck activated the security restricted operation protection mechanism too late, or even not at all in some code paths. A user having permission to create non-temporary objects within a database could define an object that would execute arbitrary SQL code with superuser permissions the next time that autovacuum processed the object, or that some superuser ran one of the affected commands against it. . The PostgreSQL Project thanks Alexander Lakhin for reporting this problem. (CVE-2022-1552) Checksums-Sha1: de9c96d90d08eeae80373274e8d6ce075b33e13c 19256 libecpg-compat3-dbgsym_11.16-0+deb10u1_amd64.deb 62ad3958c20c53ee30c4e083998c18959d393520 21156 libecpg-compat3_11.16-0+deb10u1_amd64.deb 8b9c94277657c0cbf795e37c8d9e1d17b57209fe 233952 libecpg-dev-dbgsym_11.16-0+deb10u1_amd64.deb 0d14310c63b22028a733fafb49376ddab6619236 240800 libecpg-dev_11.16-0+deb10u1_amd64.deb 4d7db5e62fe02b4a40a8479be383119961e51f1b 111712 libecpg6-dbgsym_11.16-0+deb10u1_amd64.deb 8c806f4da5e1ab43d4588f7eec1da2a09a0579a2 90328 libecpg6_11.16-0+deb10u1_amd64.deb b1bcf5ba9ac05d6dec94be5b32e7a0d0931d93c3 77560 libpgtypes3-dbgsym_11.16-0+deb10u1_amd64.deb 18d1dca1c561136d11f0ef9add951cb4fad01a52 43252 libpgtypes3_11.16-0+deb10u1_amd64.deb 6838f6ae9c3ea1e59adf2797d620db2a89f4d3d1 166636 libpq-dev_11.16-0+deb10u1_amd64.deb 7a2a0aefa32820dd2297e44295efd0dc6ee058b5 295628 libpq5-dbgsym_11.16-0+deb10u1_amd64.deb 46f6aa2b774403cee7f4a09f1ccd3258ee156c44 171952 libpq5_11.16-0+deb10u1_amd64.deb 5a0a1f1f5d2a7c1deb476e3655990f76dac89349 19558772 postgresql-11-dbgsym_11.16-0+deb10u1_amd64.deb d345515ce741cbfb7867047560a1807646aac8ea 16710 postgresql-11_11.16-0+deb10u1_amd64-buildd.buildinfo 7af5dc855393f9ea9c8ec0d50cd347bd8616efa1 14152924 postgresql-11_11.16-0+deb10u1_amd64.deb 4f3f5de378f0cbf971f85bbffe6f528a4f2084b3 1903336 postgresql-client-11-dbgsym_11.16-0+deb10u1_amd64.deb 3d446e4862e3b2265d0206de575e33ba8e0b28ba 1413416 postgresql-client-11_11.16-0+deb10u1_amd64.deb 4b18c91ac5d425797286b38b89653990e6965605 247324 postgresql-plperl-11-dbgsym_11.16-0+deb10u1_amd64.deb 1b0ca18d507499f5aece9c4e9caaecc3fdc8c8a6 68744 postgresql-plperl-11_11.16-0+deb10u1_amd64.deb 41161eacafd4ccdbf021d137ff2f55e85f4d1bd2 308148 postgresql-plpython-11-dbgsym_11.16-0+deb10u1_amd64.deb dfa6f6c50fd25360b7724070ad5c89763fdde2bf 59292 postgresql-plpython-11_11.16-0+deb10u1_amd64.deb 8323eaff55a26458ea590c53ee628534bf7b2481 335832 postgresql-plpython3-11-dbgsym_11.16-0+deb10u1_amd64.deb 27a8d7b88787f43e5acb8463b55b8bfe6055d984 75196 postgresql-plpython3-11_11.16-0+deb10u1_amd64.deb 3bf7b6f88673b30917c87fce94cca85cf312c2f3 99860 postgresql-pltcl-11-dbgsym_11.16-0+deb10u1_amd64.deb d76a38a8f3b60e01c53ae7663fa85184c23ae918 41956 postgresql-pltcl-11_11.16-0+deb10u1_amd64.deb 0b9f681824153f54666f71c9bfd43a4d45b97aa1 102296 postgresql-server-dev-11-dbgsym_11.16-0+deb10u1_amd64.deb 4d604e2585c6dacc79e17d182b3f73f16274d845 1006120 postgresql-server-dev-11_11.16-0+deb10u1_amd64.deb Checksums-Sha256: f4f9d2f9ac5ce10afb25c8bda3c4870173f0f09360859a7bcc7b7bb2f706c5a8 19256 libecpg-compat3-dbgsym_11.16-0+deb10u1_amd64.deb 4bc463891a046310c5abc2bbbe51a10d2cd9b7af2b1c920f40923abba43a702a 21156 libecpg-compat3_11.16-0+deb10u1_amd64.deb e63f64210d4eb1fd604d293f7a548a4fd33e01fcd5ea05d2937128b3ce14d9d7 233952 libecpg-dev-dbgsym_11.16-0+deb10u1_amd64.deb 0a44ed95cabca07982ecd39bf3fafe1f5b9c6f214f577ed17863480c1ed2797a 240800 libecpg-dev_11.16-0+deb10u1_amd64.deb a0e6defa2a73713005e417511b2a07a7f943541938b182a46cddb9e3636ab735 111712 libecpg6-dbgsym_11.16-0+deb10u1_amd64.deb 3d2c2d1ee99264f37793fa7bdbfc890ea9656a3bb690a1ff23473970c47f5995 90328 libecpg6_11.16-0+deb10u1_amd64.deb 057b67f987b90a3bd50ff813ad5334db26faa890973eacefd76c899dbadc4a98 77560 libpgtypes3-dbgsym_11.16-0+deb10u1_amd64.deb 1baf226d8c6b9ae7be81575f49cb2251f302d02183bdafa0a60d4a95739a8ec9 43252 libpgtypes3_11.16-0+deb10u1_amd64.deb 7dd4b68154e02ce8b88a3573b7e7125bd4b1969036ec798202e96802ac8cde5c 166636 libpq-dev_11.16-0+deb10u1_amd64.deb 30dab35a8a5b7ca5b5e21df7bd57322cbf46ab287d1d47cdb58da6bfc9d1ea94 295628 libpq5-dbgsym_11.16-0+deb10u1_amd64.deb f03e1948e7d21673c4a09e63e4793a918a78a0c64965cea021c3dbcb859b8dbf 171952 libpq5_11.16-0+deb10u1_amd64.deb 86466ee4849d4ab25afd32c50d7e6b4660bbcfad01d5f4f56dd40844b1b55c30 19558772 postgresql-11-dbgsym_11.16-0+deb10u1_amd64.deb 3a426c4a847a13f27bae672a97b56d72b79099c7489f878f2876ac58715a012a 16710 postgresql-11_11.16-0+deb10u1_amd64-buildd.buildinfo aad43ef4479b887d04ba2f595d5e3146630413c29d96f878d83df11b981a8c3c 14152924 postgresql-11_11.16-0+deb10u1_amd64.deb f1aa8d09e5ed62320e36882bc165875871de0f894baec35846c7f45acca7e384 1903336 postgresql-client-11-dbgsym_11.16-0+deb10u1_amd64.deb 85667632357856403ca134f20fbecc0f19adf4daad37e02c5ac13e27b3b3e8d1 1413416 postgresql-client-11_11.16-0+deb10u1_amd64.deb 98d34de4527217be937164dcb19d2c483ff7dc387ebe2166d05e5b1b6ed184d2 247324 postgresql-plperl-11-dbgsym_11.16-0+deb10u1_amd64.deb 893c49f542cfde47817dd93470cf3594eb14bb6acb87f76df7b7f6e29304d63b 68744 postgresql-plperl-11_11.16-0+deb10u1_amd64.deb 56b789660027f779379c6adbbc7fd1dd2e09bd66cc209a0483d40846432e6a1c 308148 postgresql-plpython-11-dbgsym_11.16-0+deb10u1_amd64.deb 3e34001733f63937a04df9b50fa51a3baa6cef9f48e7b1f54aea7bf1676e5766 59292 postgresql-plpython-11_11.16-0+deb10u1_amd64.deb 3e9b6ebd1f5459d44ce05540b30afd6b85c28038b845899ad9167e6be1c04edc 335832 postgresql-plpython3-11-dbgsym_11.16-0+deb10u1_amd64.deb 83a902570eb7b31607730824f9c4e52412b414053ab5311130022559436abada 75196 postgresql-plpython3-11_11.16-0+deb10u1_amd64.deb 1c0bd360f7ca8a07a821716a30add048a6ceb581f9a3a37b6866e361f32281d9 99860 postgresql-pltcl-11-dbgsym_11.16-0+deb10u1_amd64.deb 5096af89551bbf574496509ff55679b9b1fed6c3527cba2cb69b6ca19980c75d 41956 postgresql-pltcl-11_11.16-0+deb10u1_amd64.deb db14dfbceb7193f644d5a0f60edce52cef5e08477d4dc0f7da8cb0cf333282d1 102296 postgresql-server-dev-11-dbgsym_11.16-0+deb10u1_amd64.deb 2e8ae8097697eae2d4c5a37e03d2d5aebcfc0e166764fb05a33f37919b9d04c5 1006120 postgresql-server-dev-11_11.16-0+deb10u1_amd64.deb Files: 0df7d138d0e72c00f2bb86e9dd8e2768 19256 debug optional libecpg-compat3-dbgsym_11.16-0+deb10u1_amd64.deb ae1ac8ecacc1e85c96d9bb9bf2fe2bc8 21156 libs optional libecpg-compat3_11.16-0+deb10u1_amd64.deb 154b82b4e85873e5feca8b9c12a8a25b 233952 debug optional libecpg-dev-dbgsym_11.16-0+deb10u1_amd64.deb dc32506683e84a4b4b2bb23f104c9917 240800 libdevel optional libecpg-dev_11.16-0+deb10u1_amd64.deb bd730f0e23746c37d5f92cc584982b31 111712 debug optional libecpg6-dbgsym_11.16-0+deb10u1_amd64.deb 68ab2f429938bca610b9255811b92931 90328 libs optional libecpg6_11.16-0+deb10u1_amd64.deb 2ededfb38f5772e983f6e0cb0b0b2d38 77560 debug optional libpgtypes3-dbgsym_11.16-0+deb10u1_amd64.deb 60ba99dac931c92344a713f8b175b618 43252 libs optional libpgtypes3_11.16-0+deb10u1_amd64.deb 5566a88207a3bf55b73fefc727c82f03 166636 libdevel optional libpq-dev_11.16-0+deb10u1_amd64.deb 314891797283a60c886f4a2a80f299f3 295628 debug optional libpq5-dbgsym_11.16-0+deb10u1_amd64.deb ec5dcd8aa19dde189a42613d04fca0f9 171952 libs optional libpq5_11.16-0+deb10u1_amd64.deb 7fad18e253abac0e07248a3b0208eeba 19558772 debug optional postgresql-11-dbgsym_11.16-0+deb10u1_amd64.deb c87df6096986cf400fb331263695ac33 16710 database optional postgresql-11_11.16-0+deb10u1_amd64-buildd.buildinfo 832221e3a76909ed6b3bb6569213590d 14152924 database optional postgresql-11_11.16-0+deb10u1_amd64.deb ac904fa1f8dd52788c9a5ec1950a339d 1903336 debug optional postgresql-client-11-dbgsym_11.16-0+deb10u1_amd64.deb 860dfb45eaa90323f88365c8288c94cb 1413416 database optional postgresql-client-11_11.16-0+deb10u1_amd64.deb 96fa681ff533d763661b16439d57d807 247324 debug optional postgresql-plperl-11-dbgsym_11.16-0+deb10u1_amd64.deb c3343c73bbf68b800a9b82015ebfbb40 68744 database optional postgresql-plperl-11_11.16-0+deb10u1_amd64.deb 26e88444495abe90d45b3fb239684053 308148 debug optional postgresql-plpython-11-dbgsym_11.16-0+deb10u1_amd64.deb 79a8d01f22db4bace629d35656088686 59292 database optional postgresql-plpython-11_11.16-0+deb10u1_amd64.deb ef7efeb177f995dd5e46ed638c687849 335832 debug optional postgresql-plpython3-11-dbgsym_11.16-0+deb10u1_amd64.deb 721c26cad40cdd12cf13e3b8c321a5d3 75196 database optional postgresql-plpython3-11_11.16-0+deb10u1_amd64.deb f4f31ce54b9d021ba6323b1fe1e0a82b 99860 debug optional postgresql-pltcl-11-dbgsym_11.16-0+deb10u1_amd64.deb eec6fdbbf0aa828048ace9938e64ee64 41956 database optional postgresql-pltcl-11_11.16-0+deb10u1_amd64.deb 390da6a09cd3764cfc7440ccff6b9f71 102296 debug optional postgresql-server-dev-11-dbgsym_11.16-0+deb10u1_amd64.deb e268e8c29929c12838907a8d9f655233 1006120 libdevel optional postgresql-server-dev-11_11.16-0+deb10u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEVvgiDm0iTi84B8TiOTy2rP5qAaMFAmJ7wt0ACgkQOTy2rP5q AaMqjg/9E/IlndBBsCyqqjbXpl29FGsqj/zdIUcq/jLoMDkI3QSzJW3Tx0DKb8ft tWiVCbHS47xoFVekq995w4m1lOCh3+LjRak0tdZNo3JiCsnWwDuvGlGNjm2UTAtI uJoePDKpR41ERdQ8b/2zOI3Lyo99X693k2LvZTdfGKdWOWX68hTd0VisxqyTVz6X 8d2MQlg4c/KM1+vBuy3c1XGqiXrWoS/WWn9zOa8MMGP58nD1rvGW33UxVfNNktdi 2KDV7LEwWlpCcL/oGn4xrtOO9VexfdpzdkLuFgNbqr20NvZTbrgsKd809cewTXpx +3oCcINGXYMM9iX4qLAfYf9SA7ePW7Gs3Q9Jlj1hcnD0a114MO6XtCjGivpGVa92 t/f3SbWwqtO27+Kn+Dc52DGLNU/Jcy4iGdMqVcfWIMfGB1hbQY73i9ekYOj/t9Ht oKXNnntuCm2wyqA/28Q9xRqSSRuN0LfXZ7zGc0jhWqBSzNV3go6s6JB+PEnC4coJ SCr7t3+DD/NjIVBmlm+Py5OaPhvlNRRmB4fEXx+T26s88A4FIzbyK9bZCMpeAZv6 df5F8RKbSnqTaKzpDP6Oew+PZuKDM58O6jeJUQu07kIdQUsc1SAyPKKAu+yo8AnS 2T7U1YBmkrzNug0E2X0px9FioMVfudPSrXduVrdg6mN9q0VDspc= =+Rko -----END PGP SIGNATURE-----