-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 10 May 2023 20:35:39 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: armel Version: 13.11-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: arm Build Daemon (arm-ubc-06) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.11-0+deb11u1) bullseye-security; urgency=medium . * New upstream version. . + Prevent CREATE SCHEMA from defeating changes in search_path (Report and fix by Alexander Lakhin, CVE-2023-2454) . Within a CREATE SCHEMA command, objects in the prevailing search_path, as well as those in the newly-created schema, would be visible even within a called function or script that attempted to set a secure search_path. This could allow any user having permission to create a schema to hijack the privileges of a security definer function or extension script. . + Enforce row-level security policies correctly after inlining a set-returning function (Report by Wolfgang Walther, CVE-2023-2455) . If a set-returning SQL-language function refers to a table having row-level security policies, and it can be inlined into a calling query, those RLS policies would not get enforced properly in some cases involving re-using a cached plan under a different role. This could allow a user to see or modify rows that should have been invisible. Checksums-Sha1: 72bf64ffc6f7fb30d61f1636086854bbf1bb1450 36352 libecpg-compat3-dbgsym_13.11-0+deb11u1_armel.deb 76cd52647372e7e2e9a0cc025a29d84841f045b0 23588 libecpg-compat3_13.11-0+deb11u1_armel.deb 5012eba1bcd7a26f3ec7cb33b1b62a48bfe64728 216532 libecpg-dev-dbgsym_13.11-0+deb11u1_armel.deb aab32be79695e8a2028c07b16eb8db549482a85a 260764 libecpg-dev_13.11-0+deb11u1_armel.deb 5d128cbffa74b56620a699d4d397d78fcab9551f 106976 libecpg6-dbgsym_13.11-0+deb11u1_armel.deb d5aad07e686d944d2e431932da2cb4f33887ea3b 54828 libecpg6_13.11-0+deb11u1_armel.deb a18fdcc18fd37fae3e23e5aa1bf57ee5258b5135 84224 libpgtypes3-dbgsym_13.11-0+deb11u1_armel.deb 9d9974e7ce3e2f28da27407d9c5fe8e42508e86f 43700 libpgtypes3_13.11-0+deb11u1_armel.deb cdb83b9bff8091857e664094bc58e59509e1b779 129040 libpq-dev_13.11-0+deb11u1_armel.deb 05631ff8cb6b16f99df6876b020d4f27a0224379 242496 libpq5-dbgsym_13.11-0+deb11u1_armel.deb d8587effe9b9c6e4298f3d658a57d3e8d5f162b2 163908 libpq5_13.11-0+deb11u1_armel.deb f330b23a9efecae368dac1a7aca01e43962a5de9 14058600 postgresql-13-dbgsym_13.11-0+deb11u1_armel.deb d9057a07db6e14752234603bd8f455a1a5fa359f 16129 postgresql-13_13.11-0+deb11u1_armel-buildd.buildinfo 19aa2f7baad74e1c067a742d1b54596a845415bc 14489336 postgresql-13_13.11-0+deb11u1_armel.deb b1b0cc04a6221a7e3472c351fe59f2cbc295d144 1799212 postgresql-client-13-dbgsym_13.11-0+deb11u1_armel.deb 3454f28d2448913a75bdd80f115a859ba010b398 1430896 postgresql-client-13_13.11-0+deb11u1_armel.deb 2a5ba21f582106a0f5044cdb43bb2193237def42 152132 postgresql-plperl-13-dbgsym_13.11-0+deb11u1_armel.deb 2ed706b0eb75d36c8f8f5aeb508d868ff42a0cc0 84540 postgresql-plperl-13_13.11-0+deb11u1_armel.deb fcfe0f8cb42918d11f8019518db5b6ea77289959 154232 postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_armel.deb 6c80c59f260dca1e739543fdfd55ad2426afe43d 102744 postgresql-plpython3-13_13.11-0+deb11u1_armel.deb 3e51b597e52fec48cca34626586cfa89e7ed27d0 72212 postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_armel.deb 58f857e96c49e0dd5bbc805f7167498ef3506154 39264 postgresql-pltcl-13_13.11-0+deb11u1_armel.deb e4533b75ed68e04dcead5c4ca8726534d70f99b2 1026648 postgresql-server-dev-13_13.11-0+deb11u1_armel.deb Checksums-Sha256: 21651fd4d3ebdb1a742686ef69e7b88a1ac66a7f4c66a26b0187030a40a1fff6 36352 libecpg-compat3-dbgsym_13.11-0+deb11u1_armel.deb 91b06f069e7646d39072929e6e9f636a76875e6999aaca4318838337ab61a34d 23588 libecpg-compat3_13.11-0+deb11u1_armel.deb 4305382217fbbfdf708b0ef42b9a58e865554c6c007a64d7f66a6e4509bb734a 216532 libecpg-dev-dbgsym_13.11-0+deb11u1_armel.deb 644603f40e1a9a36f00f0b560100d714c501bebb30027e2b2d217f77f25f3cca 260764 libecpg-dev_13.11-0+deb11u1_armel.deb 9736f257f23672017444690ee65439c1c7a03e4130d6d9b86e032387a6166682 106976 libecpg6-dbgsym_13.11-0+deb11u1_armel.deb 4e42b0a8c0b2044fb54dbbde3adae89a18dcddbd1665e97b97a54aff3ffe7580 54828 libecpg6_13.11-0+deb11u1_armel.deb 16a5a96faeb7671eba5148f4541fd80d5cd68f3d3aee2fc2bc186fca36eba823 84224 libpgtypes3-dbgsym_13.11-0+deb11u1_armel.deb 8ddf89fa187b03b74e79efbae8eba09aa9b76057f6cd5ab67822cc679b159cd7 43700 libpgtypes3_13.11-0+deb11u1_armel.deb 9ebc3923de6bc6dcbe979bd3a62df2240adf8e5ae143fb9c6bd83719feabb5ce 129040 libpq-dev_13.11-0+deb11u1_armel.deb 391d56f63b922315f5296147005d3b29f14e9a4796005d6bbeb698dd3eb14c00 242496 libpq5-dbgsym_13.11-0+deb11u1_armel.deb 59dc6ad09f896daa1bb1c1dfe52b202b03c01a440bfa9a679cdeff9a8712c550 163908 libpq5_13.11-0+deb11u1_armel.deb 0dbed3a5488d90580ba5fcf9fea4dd16d8947f516dc2fb64ee2eaa54df2c8c99 14058600 postgresql-13-dbgsym_13.11-0+deb11u1_armel.deb 8d70c678ca81edb45c13dc3e3bbd5f23c591a26bfdf1af64ec430d532d4ae664 16129 postgresql-13_13.11-0+deb11u1_armel-buildd.buildinfo 6b131c3e3f993f7535ff21db07635eac9de2f88cb6566783b55f429719a0d7b1 14489336 postgresql-13_13.11-0+deb11u1_armel.deb 0d01f8a8ae6e10df89e87c7812f576ef4dd2189b5f242c48ae10322cecf892d5 1799212 postgresql-client-13-dbgsym_13.11-0+deb11u1_armel.deb 43b5da58f86e3c70ae33be3a5da2e564e3fa4fa2bec2077865379a50ad56ae72 1430896 postgresql-client-13_13.11-0+deb11u1_armel.deb 8f03395ef48e8b9fad3d7ec654a74ce5900bd7286476a980ddc9a3fd78f55cde 152132 postgresql-plperl-13-dbgsym_13.11-0+deb11u1_armel.deb 1f563ff5fe98cd4e238913c597e01b4932c19c5a5a722aa66e0a1472c285039b 84540 postgresql-plperl-13_13.11-0+deb11u1_armel.deb 3df78a0136d341a3efdd6458e73cac951697e7c98e52d5c18e04f4bd6e901a01 154232 postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_armel.deb c764b2604c1c1a244d88cce93878f9533331e1b4cf6ff8a30899f20050083502 102744 postgresql-plpython3-13_13.11-0+deb11u1_armel.deb 62ad2b1ce4dfb0e3fc9b594506d4964c6b25af3126ee8ba16d38688502ee55ca 72212 postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_armel.deb 9df933778496a721258b21bbddc4be8164ca1ef22d1c71d2bfb867df9086f084 39264 postgresql-pltcl-13_13.11-0+deb11u1_armel.deb e5dc489253182460d79dd3f273f896ae254ca1afb7dc54b5d96d519e650a2764 1026648 postgresql-server-dev-13_13.11-0+deb11u1_armel.deb Files: 90765d116300a95ae11263010337991f 36352 debug optional libecpg-compat3-dbgsym_13.11-0+deb11u1_armel.deb 912631bdbddfb9f82b9359655c7559d5 23588 libs optional libecpg-compat3_13.11-0+deb11u1_armel.deb 8deede52aa7e11836e4f38afd57f64b5 216532 debug optional libecpg-dev-dbgsym_13.11-0+deb11u1_armel.deb 82fae8a41e1c81d0115834c17101e984 260764 libdevel optional libecpg-dev_13.11-0+deb11u1_armel.deb b3988c6890d37e2f7a6e7663d24ea574 106976 debug optional libecpg6-dbgsym_13.11-0+deb11u1_armel.deb 54aad40cb9f0cd4d32c3af3fbfee7a3a 54828 libs optional libecpg6_13.11-0+deb11u1_armel.deb 82886a962b0d0b985905220c944db3d9 84224 debug optional libpgtypes3-dbgsym_13.11-0+deb11u1_armel.deb 5055fe199fc6b346fd4b31549b5992cb 43700 libs optional libpgtypes3_13.11-0+deb11u1_armel.deb 9a20b1d532010dc0a7e284d3007a3d1a 129040 libdevel optional libpq-dev_13.11-0+deb11u1_armel.deb 74d2a9d677b0242204570ec61cd2fade 242496 debug optional libpq5-dbgsym_13.11-0+deb11u1_armel.deb 7dcbfd9c755eefbe2557fadfb8eb4613 163908 libs optional libpq5_13.11-0+deb11u1_armel.deb 52d506957493293d28dc25b1475f9d4a 14058600 debug optional postgresql-13-dbgsym_13.11-0+deb11u1_armel.deb 07b1934ccc5ca2fdcfcf74021781441e 16129 database optional postgresql-13_13.11-0+deb11u1_armel-buildd.buildinfo 4caa6223bd066a042b8982c58365e7bf 14489336 database optional postgresql-13_13.11-0+deb11u1_armel.deb 9ea532151f10305c0074530355b1dd6c 1799212 debug optional postgresql-client-13-dbgsym_13.11-0+deb11u1_armel.deb 0ff109a2941967e6490fe493d7b97f76 1430896 database optional postgresql-client-13_13.11-0+deb11u1_armel.deb bd19b223ec82cd677ff0eedf1110415d 152132 debug optional postgresql-plperl-13-dbgsym_13.11-0+deb11u1_armel.deb 9bf4b45fcb5d09492b3f022cecc4f9b0 84540 database optional postgresql-plperl-13_13.11-0+deb11u1_armel.deb 0463d5012c5eef7231db384c60b9270d 154232 debug optional postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_armel.deb e0e9e28e0a8b45f8df2ffac9c4730e7f 102744 database optional postgresql-plpython3-13_13.11-0+deb11u1_armel.deb e9c2653db7fa312927d47685e9c9751d 72212 debug optional postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_armel.deb cd4f7722cf93935e5314f7a8f3e86c65 39264 database optional postgresql-pltcl-13_13.11-0+deb11u1_armel.deb 157ca547c5d1151a5acea315a6e5bc4c 1026648 libdevel optional postgresql-server-dev-13_13.11-0+deb11u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEdkvJoTVAIZVYaO9cyYck2apzqqMFAmRcC2wACgkQyYck2apz qqNB8hAAuKrtZhLxC5cW4wRiZSBFz+ovu7DruoWWf7XvyaDf1g+BX+k6FwA+Code vQ+la24GeErJaL23lfPi+h02fGerp/5+nzxzHdf3E7KEFj+NllVF8yjnbiNqTnDD X4O3lU5we8W3cKyQbeLkaKyc8nBFuljosTk2yFgia9PvpE0X2cQB9Ks4FEkg7oNc tBVW8wrpCqghAOlJy64R+vOwllKIhTuP/ezq+wg3+I78+JoGjXVXlCVE26p8FMb/ w+Rk0zenC3J9OtBhW/4D4tonqK0nhjBMiLG8WVdWgtkMcm+ZF9nzOa/Olv0Uiihf 6JbVp0Fe+mjYX3Oz7/DKbWeduN4FMQQL6he5ak15H/oLvWWTa8v2k2TLq6B+rWpS mGengvvIGcWVoJSCw03vU5U03t1uxsbb4pf1RisYdIHmkK5VOB3yJul80TF3WzY4 wXknvY1PBScwYqxFKRICgV1D5aRlunGU+HQUF72dVv8t3ZuSDu465Qxb0nJ7dT9B JGVtoLo6s1cnkrdfJ0hqRvCLBd/nzE8vdfZUn5hdXB20rEa/1N4saRgwZrzC2usu xJqpJOS/ek+6gXq+8Cmqyk0VLE/nYT6jBSYR4P0hZO8MYrOmSmZjfi43Y08Sidwi Y5a3fFdJF8KgSGntVG6K0u1POaxjBVtIA5DgT3BWCVdjNvZA+v8= =Tz/s -----END PGP SIGNATURE-----