-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 10 May 2023 20:35:39 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: armhf Version: 13.11-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: arm Build Daemon (arm-arm-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.11-0+deb11u1) bullseye-security; urgency=medium . * New upstream version. . + Prevent CREATE SCHEMA from defeating changes in search_path (Report and fix by Alexander Lakhin, CVE-2023-2454) . Within a CREATE SCHEMA command, objects in the prevailing search_path, as well as those in the newly-created schema, would be visible even within a called function or script that attempted to set a secure search_path. This could allow any user having permission to create a schema to hijack the privileges of a security definer function or extension script. . + Enforce row-level security policies correctly after inlining a set-returning function (Report by Wolfgang Walther, CVE-2023-2455) . If a set-returning SQL-language function refers to a table having row-level security policies, and it can be inlined into a calling query, those RLS policies would not get enforced properly in some cases involving re-using a cached plan under a different role. This could allow a user to see or modify rows that should have been invisible. Checksums-Sha1: af68390711615fea2d0e240596a3979a636cec12 37380 libecpg-compat3-dbgsym_13.11-0+deb11u1_armhf.deb c52b2fe4da1b44d61e64ae314dd1f15431ec2ef6 23264 libecpg-compat3_13.11-0+deb11u1_armhf.deb 07b388f5157f1092b3a2f5d789887ae43dad21a8 214836 libecpg-dev-dbgsym_13.11-0+deb11u1_armhf.deb 98191fb26e103cab7adb3f11eab92e052c1a3ff0 266204 libecpg-dev_13.11-0+deb11u1_armhf.deb add644c08af0916cbc329d6ea112e800750da74d 108400 libecpg6-dbgsym_13.11-0+deb11u1_armhf.deb 7aeb09f386c255aaca3d1325fae41c31d84e2f38 53576 libecpg6_13.11-0+deb11u1_armhf.deb c3e062a003feee7dfed9a60b23307eedd399309b 86488 libpgtypes3-dbgsym_13.11-0+deb11u1_armhf.deb 45cb4d0b45ca667f89d9eeeb84dddfe5a0699da3 42708 libpgtypes3_13.11-0+deb11u1_armhf.deb b5eb630c34332535b6d4e288bac94a24a1f3a6ee 129536 libpq-dev_13.11-0+deb11u1_armhf.deb 8f958566468e6596e3b9196ef35632e5875998c2 248228 libpq5-dbgsym_13.11-0+deb11u1_armhf.deb a49c96c3c6e815c387a3beafce5c0089cdf7e61b 163424 libpq5_13.11-0+deb11u1_armhf.deb 7072f4bf426506552e10c4be64fb9ba758e830f4 14165436 postgresql-13-dbgsym_13.11-0+deb11u1_armhf.deb 05534272ff82c7652c0ebd2ce81e8f1d1c5f17ae 16131 postgresql-13_13.11-0+deb11u1_armhf-buildd.buildinfo 13c2c4630875d0d0ed8770af14d86c7c3ce34795 14505688 postgresql-13_13.11-0+deb11u1_armhf.deb 73844d6c843f783c8568fe66d3db52dda1ef75f5 1827140 postgresql-client-13-dbgsym_13.11-0+deb11u1_armhf.deb 11884521284f37c71d66270a62d189ccb3bd8251 1446664 postgresql-client-13_13.11-0+deb11u1_armhf.deb 797d9e3786660eaae785e691eb5f648cf1b617da 153180 postgresql-plperl-13-dbgsym_13.11-0+deb11u1_armhf.deb e719f05b84c3e5cdc04cbf93245530f28aafaed7 84088 postgresql-plperl-13_13.11-0+deb11u1_armhf.deb 45b8207a11acdb4dbed1b4537329cdf6c8dd6007 154704 postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_armhf.deb 0ec5c297977b3d2022ac6b284a18e44e0e60986e 101900 postgresql-plpython3-13_13.11-0+deb11u1_armhf.deb 153de516eadb20e2ea3f31196addbdae48d5a147 72684 postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_armhf.deb a5c41af379a841c66517ce898fe5875570650e20 39252 postgresql-pltcl-13_13.11-0+deb11u1_armhf.deb 2f115f5a9d74f47ed2134012e29b3f45bd587f4d 1026652 postgresql-server-dev-13_13.11-0+deb11u1_armhf.deb Checksums-Sha256: 1f68dadea85a3d9e7aa06f8c3652000a607f50fcec10f61f43af9149fe697660 37380 libecpg-compat3-dbgsym_13.11-0+deb11u1_armhf.deb 096404307c0b225eba34f4d2f0af25b8742bf1660a59c9575e29f944e6d1a547 23264 libecpg-compat3_13.11-0+deb11u1_armhf.deb f33b967561110cb5f5dc287c3a6848566d1994eed874a80faebb6604bfe5cb59 214836 libecpg-dev-dbgsym_13.11-0+deb11u1_armhf.deb 7948cf50b05a2365a33697dfd9a144a6ab28ce10839b5b9a73a05e48dd01d290 266204 libecpg-dev_13.11-0+deb11u1_armhf.deb 8739af06cb35d71b42f2cbc043d973a5a4e42669713c42f71dad7baa931bdf7c 108400 libecpg6-dbgsym_13.11-0+deb11u1_armhf.deb 1b231c3e9e6fe3bae88152fc9c3d890a57029b998f9101388bd792c5c0948f35 53576 libecpg6_13.11-0+deb11u1_armhf.deb f651588efc8fd3c3e2e2796e801b3f0c10f8efc0518ee3fe5d074ffe87b62ec4 86488 libpgtypes3-dbgsym_13.11-0+deb11u1_armhf.deb f017f5660d7fbedc16dd2bcb377edfd9760032149c3bd65b63d0646bf1dcdd4a 42708 libpgtypes3_13.11-0+deb11u1_armhf.deb 7531e524749bd0192d6c5d7ba4eb5175fd105cf512708c2901f6ceac828d7000 129536 libpq-dev_13.11-0+deb11u1_armhf.deb 9ed254937c6a2009f384280d2294753cb05de9c4f24877785bf57697617e6108 248228 libpq5-dbgsym_13.11-0+deb11u1_armhf.deb da6cfba66703b846b4cf22e78fdc8566f609927751d3deb59e24ec7f0deaaf28 163424 libpq5_13.11-0+deb11u1_armhf.deb 19e668882583fba520205c5b4451385d26fd8b423af8a0c0335ea638e4762858 14165436 postgresql-13-dbgsym_13.11-0+deb11u1_armhf.deb c7b108acc0d14f225354aa5980babf2fc795fb5630e927746b78098b4a9c6702 16131 postgresql-13_13.11-0+deb11u1_armhf-buildd.buildinfo 972ca8a9e7b5037880b8cf8c5f8599e19e75130ebd2115d15cdf6ec3b1a4fd4e 14505688 postgresql-13_13.11-0+deb11u1_armhf.deb 75b1812d61846a093d4c96e22fde11538e11eec0a531ecd572a83983fac98af9 1827140 postgresql-client-13-dbgsym_13.11-0+deb11u1_armhf.deb d71b3f2ec0993a7f78cff0a12f2d03aea4df22c7420fc24d08a7e19f2d5207c3 1446664 postgresql-client-13_13.11-0+deb11u1_armhf.deb 7ced754bf029a8f8649a552e02b66a96ef2b04122b0f5a08753715226e290cd3 153180 postgresql-plperl-13-dbgsym_13.11-0+deb11u1_armhf.deb 3780e29808a123f88d00f130201a450ad3e5cdeb1c8a1343cf135728ab8c568a 84088 postgresql-plperl-13_13.11-0+deb11u1_armhf.deb 63a6bfd417d2b226f82bc650ac717fddce00cfcc17b6546606cb5a4cdc6659f4 154704 postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_armhf.deb 1adfb26e9b6474d60662685a0a6ac0f0c3b43ba0f5dd9f0738c2ded3fe321b38 101900 postgresql-plpython3-13_13.11-0+deb11u1_armhf.deb d9ab6a7dc8a0edd3182e976caa0c9cdb28ea09a5b19278b5b724d54fff91cbf7 72684 postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_armhf.deb a414c140047c462eb873c5cd981843d595544fbf14a2228cfbfd097ebf5516a2 39252 postgresql-pltcl-13_13.11-0+deb11u1_armhf.deb 2d0e2e63bab0d0b59177e6d2de4ca1768556b0be473e35fcb6e7cc7c50ade556 1026652 postgresql-server-dev-13_13.11-0+deb11u1_armhf.deb Files: 69ae84afe7292cb8f30cd2517b08e874 37380 debug optional libecpg-compat3-dbgsym_13.11-0+deb11u1_armhf.deb f003a80f6a34157f9a9e0e5d48919434 23264 libs optional libecpg-compat3_13.11-0+deb11u1_armhf.deb 3897a58e7b36880474a9bc727a875aef 214836 debug optional libecpg-dev-dbgsym_13.11-0+deb11u1_armhf.deb e4d25dcd7b23b13ca5a93c049ffec3e8 266204 libdevel optional libecpg-dev_13.11-0+deb11u1_armhf.deb 492fb20fee6d9505446481a6886ca81d 108400 debug optional libecpg6-dbgsym_13.11-0+deb11u1_armhf.deb 449e5c2f2634bcc8df8b54d4e3507fb3 53576 libs optional libecpg6_13.11-0+deb11u1_armhf.deb cd4f88e5ff708c14e306307aa3e6be4e 86488 debug optional libpgtypes3-dbgsym_13.11-0+deb11u1_armhf.deb b237a0217ab7c5dcbb07bbed1c2459bb 42708 libs optional libpgtypes3_13.11-0+deb11u1_armhf.deb 6ce3ba3a4bd1d6ee8c51efd3d5eec311 129536 libdevel optional libpq-dev_13.11-0+deb11u1_armhf.deb 9e48d5797ecff200c42a7ecfe8c6b1e2 248228 debug optional libpq5-dbgsym_13.11-0+deb11u1_armhf.deb 13ddbaa72532a6508f29c179bbed7123 163424 libs optional libpq5_13.11-0+deb11u1_armhf.deb 363d9301317f4d1bb3fa070f4a423936 14165436 debug optional postgresql-13-dbgsym_13.11-0+deb11u1_armhf.deb 203df3c202a079d18956ba59c7fb1fa9 16131 database optional postgresql-13_13.11-0+deb11u1_armhf-buildd.buildinfo 69400bc575af1a056f29cd610c192308 14505688 database optional postgresql-13_13.11-0+deb11u1_armhf.deb b960b8a654de3c871eaf7f8df0367570 1827140 debug optional postgresql-client-13-dbgsym_13.11-0+deb11u1_armhf.deb d6cb7adcf26c0d49aa02d49796d742c6 1446664 database optional postgresql-client-13_13.11-0+deb11u1_armhf.deb 6c4cd8d125d5853e12097cd4c1725c05 153180 debug optional postgresql-plperl-13-dbgsym_13.11-0+deb11u1_armhf.deb 431f1f25809a34819c496a3a58f553ad 84088 database optional postgresql-plperl-13_13.11-0+deb11u1_armhf.deb 801f23f7e0b3935c23e5bfa8ba2a9775 154704 debug optional postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_armhf.deb e5bece72a672107c6ad6e81748d696a6 101900 database optional postgresql-plpython3-13_13.11-0+deb11u1_armhf.deb 4cc4d04f59047a8ae39e9ad1a87cf90e 72684 debug optional postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_armhf.deb c80eb10b3b418db8c1b8c3ceded4fe93 39252 database optional postgresql-pltcl-13_13.11-0+deb11u1_armhf.deb ea48dc18890f3a52c9b84add1027806b 1026652 libdevel optional postgresql-server-dev-13_13.11-0+deb11u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE4Prg5L5o4koxD5sKbi61NfD5HDwFAmRb/OQACgkQbi61NfD5 HDwktw//Sv/f0EH9VkeXMmKNlWvnDVEhdN1uJaZm+hJn5vfYZ6ts6IpEpCHKhyM5 5m1YTdWhn0u4sN7xvORx29MlJBTez39PRMhSnOP06IVPQgcODv0jNMZDglIOMazd 4qo5hD/K5MxtHaOvSgpWCe2pUF07L0IAzzmlrSArekvwOJXBOTROyrYlw3lnDWFe MLg8B1YyWYuehixOBVtnOatJg7gQMo4NxwkNP9D8BXRlqHBFpI3ZOSYlBy0Dkkx2 5XGQ8xOaWlQOhQvVhmId1nYZs1JgvQoADv+juWV6h7bvp2+FvNZW5RKeQD7MV31M fu2h8Jo0LWncoCd7zd3bW1A2f4Okeyaa5TsBzxFg4GwuGb1OXbO4DAXmyx16aTkV ZlsVpqZqfd1dgOiNtvGOYqPhFVwj4hmUR1Dh898ykkbTnlP8WDFhfC4EMKPRP1Kl GaGS/Q/pVBwEPj9eTYcNhQd7Rqkz+lEW0LyKgqJr80BnYqBjlaLLDRWhpIzfIlZM qOodNV9EBRgWHwfBJqk+HZaK2I8YaVISGF+Qe5L9Op9azNyIiHqOECwev4uqGiSz k8bOn09m82a6UgfFeXeTAmL8vEOtKbyV7YqSutPLMytGW4vcoFu33yl+pdoytAN6 s1yVjqxKeo9g22mBPnKs+EjN2D5u+O/HlQ5OCoFowuI1dZI5J+4= =yRxZ -----END PGP SIGNATURE-----