-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 11 May 2022 15:15:30 +0200 Source: postgresql-11 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-11 postgresql-11-dbgsym postgresql-client-11 postgresql-client-11-dbgsym postgresql-plperl-11 postgresql-plperl-11-dbgsym postgresql-plpython-11 postgresql-plpython-11-dbgsym postgresql-plpython3-11 postgresql-plpython3-11-dbgsym postgresql-pltcl-11 postgresql-pltcl-11-dbgsym postgresql-server-dev-11 postgresql-server-dev-11-dbgsym Architecture: arm64 Version: 11.16-0+deb10u1 Distribution: buster-security Urgency: medium Maintainer: arm Build Daemon (arm-ubc-02) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 11 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-11 - object-relational SQL database, version 11 server postgresql-client-11 - front-end programs for PostgreSQL 11 postgresql-plperl-11 - PL/Perl procedural language for PostgreSQL 11 postgresql-plpython-11 - PL/Python procedural language for PostgreSQL 11 postgresql-plpython3-11 - PL/Python 3 procedural language for PostgreSQL 11 postgresql-pltcl-11 - PL/Tcl procedural language for PostgreSQL 11 postgresql-server-dev-11 - development files for PostgreSQL 11 server-side programming Changes: postgresql-11 (11.16-0+deb10u1) buster-security; urgency=medium . * New upstream release. . * Confine additional operations within security restricted operation sandboxes (Sergey Shinderuk, Noah Misch) . Autovacuum, CLUSTER, CREATE INDEX, REINDEX, REFRESH MATERIALIZED VIEW, and pg_amcheck activated the security restricted operation protection mechanism too late, or even not at all in some code paths. A user having permission to create non-temporary objects within a database could define an object that would execute arbitrary SQL code with superuser permissions the next time that autovacuum processed the object, or that some superuser ran one of the affected commands against it. . The PostgreSQL Project thanks Alexander Lakhin for reporting this problem. (CVE-2022-1552) Checksums-Sha1: dfed4e0179ed7e0e01af7e0ac86afe534ad0948d 19176 libecpg-compat3-dbgsym_11.16-0+deb10u1_arm64.deb 13ce5f2fe82aae8485b2dee7dc838f9d300a3d62 20576 libecpg-compat3_11.16-0+deb10u1_arm64.deb 5eb503235b67509b2979a1662249468e4624e843 220540 libecpg-dev-dbgsym_11.16-0+deb10u1_arm64.deb 56459927a2ef75285a20b66c30218c38646c6328 227116 libecpg-dev_11.16-0+deb10u1_arm64.deb 757f62788a2c6dc4db6687f23ea5103ff9be4ff8 112012 libecpg6-dbgsym_11.16-0+deb10u1_arm64.deb b0ec17f4938b14e4844019d77958b3d77c42588d 87872 libecpg6_11.16-0+deb10u1_arm64.deb 601e5bac48f38046a0237814ca9acd3286a117e9 77124 libpgtypes3-dbgsym_11.16-0+deb10u1_arm64.deb b82575d3c201a93819bc0b14d536ad9ef58dc116 41684 libpgtypes3_11.16-0+deb10u1_arm64.deb d8325c25934527f59fba90ed41c0fb526079d9fe 163976 libpq-dev_11.16-0+deb10u1_arm64.deb dda5792428b3839fd84db6aa0eaeb3ef3bd39c30 296076 libpq5-dbgsym_11.16-0+deb10u1_arm64.deb 3f1d52d63647f952e8cd64a9c5ec70a63a80d7ab 165584 libpq5_11.16-0+deb10u1_arm64.deb 2dd613cea2fc4bc4d9bb903151701d7fb17628d9 19377044 postgresql-11-dbgsym_11.16-0+deb10u1_arm64.deb f5cbac46fdedf87391669a71f17407a0b96fead8 16549 postgresql-11_11.16-0+deb10u1_arm64-buildd.buildinfo 749d601da86b33d36f1aa40f310ae601e7c46a87 13774660 postgresql-11_11.16-0+deb10u1_arm64.deb 984a9274c61fcdd2a7a98c7ed8ebc9885757a6b8 1924364 postgresql-client-11-dbgsym_11.16-0+deb10u1_arm64.deb fb9bd009e50cc705d180b0aa38d56cee6fbea9eb 1382952 postgresql-client-11_11.16-0+deb10u1_arm64.deb b7085c7567530a21255e769affd2d66566490d23 245996 postgresql-plperl-11-dbgsym_11.16-0+deb10u1_arm64.deb 8e2be0051d82a4dc2da353e7219c7d308bfe643f 65884 postgresql-plperl-11_11.16-0+deb10u1_arm64.deb f6d599208c7db5c745fed1f3cc525b6436416bb3 306964 postgresql-plpython-11-dbgsym_11.16-0+deb10u1_arm64.deb c667beaddb0c60f0af47cd1542102daef383d516 56148 postgresql-plpython-11_11.16-0+deb10u1_arm64.deb f72674675bf1b7e68a9742023dad92d09f0085e9 334592 postgresql-plpython3-11-dbgsym_11.16-0+deb10u1_arm64.deb 7c6808fc0ae7a69c42fe7984fd03bc13597726cb 72208 postgresql-plpython3-11_11.16-0+deb10u1_arm64.deb ca971eea9ceadee9b1207237d7d6efd2198557ef 99616 postgresql-pltcl-11-dbgsym_11.16-0+deb10u1_arm64.deb 51e53d6b7ff3157394cbec1c66dcc7f717712cb3 40396 postgresql-pltcl-11_11.16-0+deb10u1_arm64.deb 725c082f4c8905c39c91adfb04b55ff36082cc01 104480 postgresql-server-dev-11-dbgsym_11.16-0+deb10u1_arm64.deb e7e20bf0b10c76c44aa983ed144ffa43f4cddb03 1005840 postgresql-server-dev-11_11.16-0+deb10u1_arm64.deb Checksums-Sha256: e9d7052ef789b40854d02c036fc85bd8bd81218e1720ed5a3dc91bccf9d8d09a 19176 libecpg-compat3-dbgsym_11.16-0+deb10u1_arm64.deb afd044d9792bfbe1b3896b942af1c8f5c7571b083f17b762ce5d7ef26063945a 20576 libecpg-compat3_11.16-0+deb10u1_arm64.deb 9990ec2c93bf176022730bca9bc58d4bbdc88314e0291ca3f089ab5f6a8fbaf9 220540 libecpg-dev-dbgsym_11.16-0+deb10u1_arm64.deb 63008c936ca38b59532ebe9ae96d8f8be9b8d3cb05c2fd6785fa4b313dd77300 227116 libecpg-dev_11.16-0+deb10u1_arm64.deb 3dd5f3df81b2c8594a1ea9f05f7066300e50c637be4313abac85d03b166f989b 112012 libecpg6-dbgsym_11.16-0+deb10u1_arm64.deb 7daad842d8c6fc68e456a93f98388c2a4f8c1aa74060f1c2901581e069dc72af 87872 libecpg6_11.16-0+deb10u1_arm64.deb a8c53671589334d44104973e1a220ba6dc899efe177dee2b2ddf3bdfe5ca7988 77124 libpgtypes3-dbgsym_11.16-0+deb10u1_arm64.deb 4aa44687456f43b796f3d1e0c99ce777ea02848ba74d0e2b715e80f9f75ddf00 41684 libpgtypes3_11.16-0+deb10u1_arm64.deb f5838a3d109f0fdac06129c58bba4b34e21b69ff21377b8b8dd300dedc7a3b12 163976 libpq-dev_11.16-0+deb10u1_arm64.deb 33b8cd69107ae7580a667e75cad291f2a58982bc7aa50c2b88514e8469b8a950 296076 libpq5-dbgsym_11.16-0+deb10u1_arm64.deb df684ce9ff8412672666e2d838b3635e1539a11aa672c0b95b91fe3693346c5b 165584 libpq5_11.16-0+deb10u1_arm64.deb a9773ce332060f3d5f88f9093d9b9d4777a75089c208b88c08de78c9d1aeae31 19377044 postgresql-11-dbgsym_11.16-0+deb10u1_arm64.deb 4ff112e6c78b05ec65081f1d49cb925dcc0f36b608b5984fb3576dfb3c8d7432 16549 postgresql-11_11.16-0+deb10u1_arm64-buildd.buildinfo 4592791f40f9ab8cb5d7648b98cfa200a9fa546102e807759823633238bf12eb 13774660 postgresql-11_11.16-0+deb10u1_arm64.deb b005d826f1bbeede43cf7394d5c1c990588262b09e9e0f2352f82cff146a7904 1924364 postgresql-client-11-dbgsym_11.16-0+deb10u1_arm64.deb 826ea1c65457f92e7b4d5df657d61b2797a730ae1675ee7734c07e42f9541c47 1382952 postgresql-client-11_11.16-0+deb10u1_arm64.deb 204d57e23e35ef859081671d375d03d00af712a2dc8fb81eae7f40bcb599fee1 245996 postgresql-plperl-11-dbgsym_11.16-0+deb10u1_arm64.deb 02b8f2096428a8d317b456c9e936349131f41f33b810394384e4e79b6985ffd7 65884 postgresql-plperl-11_11.16-0+deb10u1_arm64.deb 26cdc4d4110f45a827a01befa07c1fe2e732cfe6e1aa9e13d240d7a47f887868 306964 postgresql-plpython-11-dbgsym_11.16-0+deb10u1_arm64.deb 67bc85329f3d58519abf1437e648a0fe492c1a6ff5988b742e19fcff527b662e 56148 postgresql-plpython-11_11.16-0+deb10u1_arm64.deb d4b7c8fa1956c35a62c7c339e5160dc64c80eec0745ce79d616ed459cd452b71 334592 postgresql-plpython3-11-dbgsym_11.16-0+deb10u1_arm64.deb 4658d67d499281dec114c9f4aef407c23e6980a1bb1ef562743b4c14dfe887f7 72208 postgresql-plpython3-11_11.16-0+deb10u1_arm64.deb ecc8e664b1b5488a664d1a573a437c1019735bd485fbf7c8729080ceec817717 99616 postgresql-pltcl-11-dbgsym_11.16-0+deb10u1_arm64.deb f3a8750ad478d4fc53b05ad6ce5933aa3608d0a1a35012c0508991b64b8a21e2 40396 postgresql-pltcl-11_11.16-0+deb10u1_arm64.deb f5d10ccfc1fd3f2e26f0997d3233ec0f1022fff3c96b2af41609f922c5d297a8 104480 postgresql-server-dev-11-dbgsym_11.16-0+deb10u1_arm64.deb 609c1a960883262aad9f6c221a120d15831eb848b08709ff6e0d12da3d580f65 1005840 postgresql-server-dev-11_11.16-0+deb10u1_arm64.deb Files: cb4f937e33034f94a7b357d84697bae8 19176 debug optional libecpg-compat3-dbgsym_11.16-0+deb10u1_arm64.deb b78d40a9b33d165de80542844c86d2b6 20576 libs optional libecpg-compat3_11.16-0+deb10u1_arm64.deb 99918c21b5ee4c2d9615b4e27bc4425e 220540 debug optional libecpg-dev-dbgsym_11.16-0+deb10u1_arm64.deb 4ab4bca38db7f6d737e91992dbf190ef 227116 libdevel optional libecpg-dev_11.16-0+deb10u1_arm64.deb 18277bc5844d0ede836db80871456458 112012 debug optional libecpg6-dbgsym_11.16-0+deb10u1_arm64.deb e7da075764da7de0712ece43211d625a 87872 libs optional libecpg6_11.16-0+deb10u1_arm64.deb d28398ff2517b3d02b243cff2aacc20b 77124 debug optional libpgtypes3-dbgsym_11.16-0+deb10u1_arm64.deb 7e7e009f800dbbd4b554d0965aa87660 41684 libs optional libpgtypes3_11.16-0+deb10u1_arm64.deb 9c12fd7513d4cca84cbdb989d2bbde81 163976 libdevel optional libpq-dev_11.16-0+deb10u1_arm64.deb a4cbd9f6d2c3d766f38808d97c9931d1 296076 debug optional libpq5-dbgsym_11.16-0+deb10u1_arm64.deb eea835a333b6333f2a7421fd02788e65 165584 libs optional libpq5_11.16-0+deb10u1_arm64.deb 8f60f9e71cbf20c9b13979b48f9de141 19377044 debug optional postgresql-11-dbgsym_11.16-0+deb10u1_arm64.deb 10f3667f7db4670e1ed43e2f5bc13cca 16549 database optional postgresql-11_11.16-0+deb10u1_arm64-buildd.buildinfo 9a5e73b932471eb7e390c0b3c5031d8f 13774660 database optional postgresql-11_11.16-0+deb10u1_arm64.deb f0e2a594758070d4ebaf64b59835c6a0 1924364 debug optional postgresql-client-11-dbgsym_11.16-0+deb10u1_arm64.deb 441ec34e8596d505ae4b62ea4f471a66 1382952 database optional postgresql-client-11_11.16-0+deb10u1_arm64.deb 4173297933d606996f887a3a823bb464 245996 debug optional postgresql-plperl-11-dbgsym_11.16-0+deb10u1_arm64.deb 405ff35a6f72ac0cfd6f930df606251f 65884 database optional postgresql-plperl-11_11.16-0+deb10u1_arm64.deb 0b5908f655a063ce21acedd6b7f4c4bb 306964 debug optional postgresql-plpython-11-dbgsym_11.16-0+deb10u1_arm64.deb e721adba8b9c9e3dc059ee1e499996e8 56148 database optional postgresql-plpython-11_11.16-0+deb10u1_arm64.deb f4eea05070e4d19c9219c37d381a95ab 334592 debug optional postgresql-plpython3-11-dbgsym_11.16-0+deb10u1_arm64.deb 4ca65842cf9aaa701865cafa2e454ae6 72208 database optional postgresql-plpython3-11_11.16-0+deb10u1_arm64.deb ed9b62ab613c6a86d934eb11272f6dc4 99616 debug optional postgresql-pltcl-11-dbgsym_11.16-0+deb10u1_arm64.deb 9cc4de67767929e7cfaae92d4650eba8 40396 database optional postgresql-pltcl-11_11.16-0+deb10u1_arm64.deb 8d0a470aa0c38c7e4f356866a41af702 104480 debug optional postgresql-server-dev-11-dbgsym_11.16-0+deb10u1_arm64.deb 3c274823c95821e18279073c53e91c0c 1005840 libdevel optional postgresql-server-dev-11_11.16-0+deb10u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEk6cQMJtJmFPeb+VMFbDY0NpL5FYFAmJ7yTIACgkQFbDY0NpL 5FaDSQ/8DTByFLBZlSzKD5n6Zc411Grjm+qcEin38qHm2AhECuRlv7iUjnqegk1X dZEATnCcN2Zlt27yTk4gY1Tvn3Ka/XkT5IOFVd6BlEo4EeU9pt57SB2iD/Zy8Dws Ld5X49dx2pktDt/K/8obQmqcCvhdlfB8WqZvRSw6yHRQ+gO8GzVglgRSTVRZsxUa gW5bcNeWirdznYa/G6omG4h1sEYBnp20QN1FC9DsEXC8X4jRXOakoxz5oUPrsyig VPVYGZgWib0PXhuS7KlphKNG20gO115ZTFXYJjKUIw5bzQA8aWkb6vfW7IMAGoej mu9y6R0KzDO+Pm04GQfzbSFOlPPvD6iln2YwizMOzYD175xhfi2JV4eujo+j7VHe KhyK+0Qg7JymG5YZ/CoAo6YRQCHfi+qvg1w4wiwqvzwolwFIRXKiV2bdGp1DeKK7 8tCd755WjusORCOaNPKdhULGX5w3weWDsV3iNuaTy9slPwASHinYl7+hLM7BlLJb D+zhfgKtqVeAF+ucRuGHS/JFo/krQWzHCf3aZO/1ZQ0dPmDjkIGUSpEfsrXBczAu xLlAQBnX5xR2zavXjbngiuIrbnODnpdDFzZ4t8416eSOWjkVu1UZCvF8qdPxBgkU TUkuWiD8kqM1GkhssItfq2Lrw1KQnBdb94SSHlYQ5xLWn1TEcLc= =3aWl -----END PGP SIGNATURE-----