-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 10 May 2023 20:35:39 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: arm64 Version: 13.11-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: arm Build Daemon (arm-ubc-02) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.11-0+deb11u1) bullseye-security; urgency=medium . * New upstream version. . + Prevent CREATE SCHEMA from defeating changes in search_path (Report and fix by Alexander Lakhin, CVE-2023-2454) . Within a CREATE SCHEMA command, objects in the prevailing search_path, as well as those in the newly-created schema, would be visible even within a called function or script that attempted to set a secure search_path. This could allow any user having permission to create a schema to hijack the privileges of a security definer function or extension script. . + Enforce row-level security policies correctly after inlining a set-returning function (Report by Wolfgang Walther, CVE-2023-2455) . If a set-returning SQL-language function refers to a table having row-level security policies, and it can be inlined into a calling query, those RLS policies would not get enforced properly in some cases involving re-using a cached plan under a different role. This could allow a user to see or modify rows that should have been invisible. Checksums-Sha1: 5d7da1edd7bb9681776a2da65f15b41cdb35f6bb 39304 libecpg-compat3-dbgsym_13.11-0+deb11u1_arm64.deb a5607687a776638492c4bc8c2fb8f3d4dacefab3 24872 libecpg-compat3_13.11-0+deb11u1_arm64.deb 2d02d097fb00f904aa2d7d242c610775ec05f90b 221568 libecpg-dev-dbgsym_13.11-0+deb11u1_arm64.deb 9e90c25c7b8fcfa074253d10423e6c231ef710d8 269640 libecpg-dev_13.11-0+deb11u1_arm64.deb 19f7f7cac6e640a983fab77d8b03eaa90b67cc2b 113656 libecpg6-dbgsym_13.11-0+deb11u1_arm64.deb 611f904a5f41a62e4116df02cae927e1a510d30c 58844 libecpg6_13.11-0+deb11u1_arm64.deb dd20ec39ce91972026731a6ce774fe7201d8d824 89008 libpgtypes3-dbgsym_13.11-0+deb11u1_arm64.deb 0c2c4f128de19c0c9dfcdf42de83cd4d96a003e7 45332 libpgtypes3_13.11-0+deb11u1_arm64.deb a1654a15ce999b6d1783d7e54b3f132c98c0f627 137496 libpq-dev_13.11-0+deb11u1_arm64.deb 93da9adf52b8cb99fd6be0efb1e920382afdaa9a 255916 libpq5-dbgsym_13.11-0+deb11u1_arm64.deb 84c791d4fcf85b9e3aa8fc36cf0e4c455c29c517 173816 libpq5_13.11-0+deb11u1_arm64.deb 122bdebb96094f85ba11f01a5a3c0f4de5b8aec0 14544400 postgresql-13-dbgsym_13.11-0+deb11u1_arm64.deb a0d18335c1808e60a8266296e9e1a6b1eea18ee6 16200 postgresql-13_13.11-0+deb11u1_arm64-buildd.buildinfo 07b6ff531987008dc1b6e7b6ec6d4af5cf294e45 14684020 postgresql-13_13.11-0+deb11u1_arm64.deb a062cb5da3ebcc3a887daa83aa89fa5828473600 1883400 postgresql-client-13-dbgsym_13.11-0+deb11u1_arm64.deb 1ff5bc11dc917e32e60d02c1fd95f80989408d21 1472640 postgresql-client-13_13.11-0+deb11u1_arm64.deb bdcd4feffabd52c00716e27921b2039606db3039 155344 postgresql-plperl-13-dbgsym_13.11-0+deb11u1_arm64.deb 557c3fc484fbd03e405b76eb982325a0504cebad 84940 postgresql-plperl-13_13.11-0+deb11u1_arm64.deb 0e94c7e2c2835fe73f8cc422e9e1f2cd39ff6f37 158168 postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_arm64.deb d87f288cd7fefb86331cfede118a5338a23400db 103968 postgresql-plpython3-13_13.11-0+deb11u1_arm64.deb 68ea03e2b1653d13bd213852ad4598cff36e813c 73904 postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_arm64.deb 49f8f6286b6f076eb9c87482238eeef3a365e625 40684 postgresql-pltcl-13_13.11-0+deb11u1_arm64.deb 393fc106db13f073ed28a8de851cde0bdb96209c 1035628 postgresql-server-dev-13_13.11-0+deb11u1_arm64.deb Checksums-Sha256: 35d86ac2b8a4b10a14f5e6cc0cb1095da2d83bfab4c45348d673dedb6c1a8b4e 39304 libecpg-compat3-dbgsym_13.11-0+deb11u1_arm64.deb fd80146dce7c1cee78e4e568bb8e08e0ed3706efb20c143a0c1b36466bb9a4e0 24872 libecpg-compat3_13.11-0+deb11u1_arm64.deb 5a6f62b8c115f089c300a42199a9e17c235e3ec58a0f16623daf11ea72a687c8 221568 libecpg-dev-dbgsym_13.11-0+deb11u1_arm64.deb 0ec2032a46f919a58d590947ae5de816bcc98ded62a834b8ee047960b0301f43 269640 libecpg-dev_13.11-0+deb11u1_arm64.deb 9e84ccd7ebba32d3684ed7986997da9cf65d108c3eccfb1c8253282236e1dd12 113656 libecpg6-dbgsym_13.11-0+deb11u1_arm64.deb 7f2f48c4edc990a10cac8145b667f37833467be892d3536be2366f6f62a0632d 58844 libecpg6_13.11-0+deb11u1_arm64.deb 014e59308e32af20a8c0ec6a6d918663fd8d73cc086dab2366e90ddc2ef9c51b 89008 libpgtypes3-dbgsym_13.11-0+deb11u1_arm64.deb 3b066876ac0efc89261ff7a8673c6b89520e2611f5be990583df469ee3a72515 45332 libpgtypes3_13.11-0+deb11u1_arm64.deb 8df7cda2d17d7cfcda45c49c249f36ad251e1bcbe565005e877027ee8d918490 137496 libpq-dev_13.11-0+deb11u1_arm64.deb 37829c6f7cfcd800f36748dabbf2a2ee5fe958af8393edd42897dd6f15dae326 255916 libpq5-dbgsym_13.11-0+deb11u1_arm64.deb f780256bf39cb172e7379a77c0d8c34da2ef5b7e623ed914670e046864811b57 173816 libpq5_13.11-0+deb11u1_arm64.deb c7c83cf91d8458cf09c8b504775c5dfccd4d93998be614196f4732dab7da31ad 14544400 postgresql-13-dbgsym_13.11-0+deb11u1_arm64.deb 4b7c0b99472a9adc2219138a16cd41c807bda2cb7ce739bb8a53d77527a1bb3a 16200 postgresql-13_13.11-0+deb11u1_arm64-buildd.buildinfo 3fb621e8f3c44ab42e8311dbb5980d7398fda5ccbdf4e1187c65fe969cfb6ef2 14684020 postgresql-13_13.11-0+deb11u1_arm64.deb 17d27c99083df4e68a83cc443478fd9e38e2a8bb48738894efa2912745b7b313 1883400 postgresql-client-13-dbgsym_13.11-0+deb11u1_arm64.deb 1a277679b1efc972b2e36773f617806157e3baa3970325453add63329a3b187d 1472640 postgresql-client-13_13.11-0+deb11u1_arm64.deb 7d8b8882eac02c5e8ebe6d02d43a8115dbdade01639f7c4bae9ccf4430759070 155344 postgresql-plperl-13-dbgsym_13.11-0+deb11u1_arm64.deb 3353120c494e22e795488a031506083c3f4a6369ab80c6e6caa7f6d8380636f6 84940 postgresql-plperl-13_13.11-0+deb11u1_arm64.deb 66a7f1539804a42c2d116b3e5be54d918d268118a145931a1564858b4e59ebb4 158168 postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_arm64.deb d6dcbaf09eae03643f63691fe2bce20473e0940d14215a3f587b2dfe13a33a0e 103968 postgresql-plpython3-13_13.11-0+deb11u1_arm64.deb 0e676ef0fb1e006949a2b86897d4d2a5728846fc909cfa363ebf2e28a7b914a1 73904 postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_arm64.deb fb12079b3ab4cbe3808e653e4f8bcf30751b707dff93e672022ee2b3948084cf 40684 postgresql-pltcl-13_13.11-0+deb11u1_arm64.deb 0b600de5ca379b688c129a56b527b0fb5422a54e1cff2f7328250e8c8f3168ea 1035628 postgresql-server-dev-13_13.11-0+deb11u1_arm64.deb Files: ea6f97542380653cfed63b64f4eb84c7 39304 debug optional libecpg-compat3-dbgsym_13.11-0+deb11u1_arm64.deb 2884d9bf68a4c098e307d1ffbba16778 24872 libs optional libecpg-compat3_13.11-0+deb11u1_arm64.deb 9b87a89ee7309872fca928617a1a9f4a 221568 debug optional libecpg-dev-dbgsym_13.11-0+deb11u1_arm64.deb c7cf0f8f0956877ee6d0b3401ff4211a 269640 libdevel optional libecpg-dev_13.11-0+deb11u1_arm64.deb 258c6b9898f49e33ed2e1c1073bbfd73 113656 debug optional libecpg6-dbgsym_13.11-0+deb11u1_arm64.deb b9722a1c540aedb5adbbb6449cde26ed 58844 libs optional libecpg6_13.11-0+deb11u1_arm64.deb 0dcccbe11029054d339e31508973fdf8 89008 debug optional libpgtypes3-dbgsym_13.11-0+deb11u1_arm64.deb dd994f786985b14fe92663628f7520b9 45332 libs optional libpgtypes3_13.11-0+deb11u1_arm64.deb f5f40d32affa592d207da7318ef381d8 137496 libdevel optional libpq-dev_13.11-0+deb11u1_arm64.deb a2273c7da6ed2ddc5e913e8a39a43e3a 255916 debug optional libpq5-dbgsym_13.11-0+deb11u1_arm64.deb 910edaa6f4fceb90cacda11c4965febe 173816 libs optional libpq5_13.11-0+deb11u1_arm64.deb 3a666af13b3ab3fa6215a22992e596f5 14544400 debug optional postgresql-13-dbgsym_13.11-0+deb11u1_arm64.deb 63ffebe35ba147f0dfaaa9ad616fdac5 16200 database optional postgresql-13_13.11-0+deb11u1_arm64-buildd.buildinfo bd36afe5672c8429a09a7bf98e820d88 14684020 database optional postgresql-13_13.11-0+deb11u1_arm64.deb 6b2ee8a944af195b63abbe9be74e38b8 1883400 debug optional postgresql-client-13-dbgsym_13.11-0+deb11u1_arm64.deb 8fc9d240d8711e8740b7004a932e5b14 1472640 database optional postgresql-client-13_13.11-0+deb11u1_arm64.deb e63ec282874c4021bfefa6705d6a0dd6 155344 debug optional postgresql-plperl-13-dbgsym_13.11-0+deb11u1_arm64.deb 300aa80869cc24fb9dcb363cb0f4ec7a 84940 database optional postgresql-plperl-13_13.11-0+deb11u1_arm64.deb ceed2d3d432be5bce0a68236c22cf350 158168 debug optional postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_arm64.deb 8f47d65218ca4dce1604807e8eafcb98 103968 database optional postgresql-plpython3-13_13.11-0+deb11u1_arm64.deb 72af2060c674b4fc6457ca168996aaf7 73904 debug optional postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_arm64.deb 5056eda52908fd4f250249ec0adf4a81 40684 database optional postgresql-pltcl-13_13.11-0+deb11u1_arm64.deb 80d6ffdc9aae66297c943d70ae260f5f 1035628 libdevel optional postgresql-server-dev-13_13.11-0+deb11u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEuIolmszDbgxUhBbrMZO3llZhjs8FAmRcA90ACgkQMZO3llZh js8LMg//fAUsjdRQRz/E6IKNrzAzLDrpDMI/oz1AZvvCg6C101udZAh+Iko+NnxX 3K0/Npb9Y19sja98W3ICYjifRwE+CWBqT0YjADAi3iVdsbfqdUhr1mXbUWkBor27 P/yxBxAStGdAn+lbdqJNfd6WHRDXyCtQDmE2mi58updUcBP6pXyltz8gV7datBsP TNFAaMsq892Z4jwigmjRszTyShZsCIs7UMT2CCZJ4mZe3yEi/I7GLBqoi0Jx2mGi 4Lv1Lmjawxh4oXPaag/HgR00YD3V5LQaBAbiOtOQEfWysoexgozXGH+RYP2p8h5v 78WPAjloYOS47r3yLKRQi/ceFgBi7SOn+hn6tPgnm5JYo6Up2spUNUnBLQEDGWz2 BPIjjctw+5BipMNRTuDdeGjUC3uXps8jKrk+/JZejU9G5XSUcvkUk4Hmfa/MuOc8 1obGJXQJEGGzPF+qrJ21Km+AbrVMO9SDlCq8iTAySGzBgL8eWuRAd+bYbtc7u6f9 KTgsOZ75bbTsX01IjNmWnjK4pjh2c5mcKldrqO/fbYFrsoVeTnthn3jWlrD6u5Sc NXFNkGRKXbRQQgIhXglM6d7/i95jMd01j7aN0MuZbt1lWgpomICqz7+ClsdwW0wH l2kUED/zvhtzv/ifROoYUbQ/D31QCWiEZqijeqUTKyqIrX8ylBA= =HlYd -----END PGP SIGNATURE-----