-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 10 May 2023 20:35:39 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: mips64el Version: 13.11-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: mips64el Build Daemon (mipsel-osuosl-02) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.11-0+deb11u1) bullseye-security; urgency=medium . * New upstream version. . + Prevent CREATE SCHEMA from defeating changes in search_path (Report and fix by Alexander Lakhin, CVE-2023-2454) . Within a CREATE SCHEMA command, objects in the prevailing search_path, as well as those in the newly-created schema, would be visible even within a called function or script that attempted to set a secure search_path. This could allow any user having permission to create a schema to hijack the privileges of a security definer function or extension script. . + Enforce row-level security policies correctly after inlining a set-returning function (Report by Wolfgang Walther, CVE-2023-2455) . If a set-returning SQL-language function refers to a table having row-level security policies, and it can be inlined into a calling query, those RLS policies would not get enforced properly in some cases involving re-using a cached plan under a different role. This could allow a user to see or modify rows that should have been invisible. Checksums-Sha1: 42e9438255be680dfe6ba9b1d54bfed9041a016a 38464 libecpg-compat3-dbgsym_13.11-0+deb11u1_mips64el.deb 883d2ddf0d45ef9dde8ab71efc22f25f68800ff8 24416 libecpg-compat3_13.11-0+deb11u1_mips64el.deb c1c61017464bd56610d175bc054a941d83ef4560 230908 libecpg-dev-dbgsym_13.11-0+deb11u1_mips64el.deb b95fcb16a5162bb8e3529c062b10add05f8b8a50 276604 libecpg-dev_13.11-0+deb11u1_mips64el.deb 0ae81198504456f82d780b7be03a37dc11995d36 113952 libecpg6-dbgsym_13.11-0+deb11u1_mips64el.deb 397da8b172473a380683c0135b66a61f6acafe74 58000 libecpg6_13.11-0+deb11u1_mips64el.deb 76d4ddbb8ca16176c2890a569c762883cdb31812 92120 libpgtypes3-dbgsym_13.11-0+deb11u1_mips64el.deb 59f192e87870dd28e2a07989aca596a766ff9634 46148 libpgtypes3_13.11-0+deb11u1_mips64el.deb b22aecddcdf273ebd2333f19770188a58189508e 146628 libpq-dev_13.11-0+deb11u1_mips64el.deb 3835de3417229c2c3d9ad24df135762405c00452 263996 libpq5-dbgsym_13.11-0+deb11u1_mips64el.deb 35eaeae6f811ff0cffef461f86b72176b9342a5c 170872 libpq5_13.11-0+deb11u1_mips64el.deb 0ccb22b6aa4730d7403a9a32bbc384fc378c0a94 15093568 postgresql-13-dbgsym_13.11-0+deb11u1_mips64el.deb 540d7168cc1a3ba6a35c8fecf29986bbd9dda5da 16268 postgresql-13_13.11-0+deb11u1_mips64el-buildd.buildinfo 3a1b5e2d595955ab1018ac8227984de4f1b0b937 14723284 postgresql-13_13.11-0+deb11u1_mips64el.deb 82a47ba971f87252cda99f93f9f67f6cd604a5b9 1954460 postgresql-client-13-dbgsym_13.11-0+deb11u1_mips64el.deb 0034644d75428d19e3371129a725d6ccc4464721 1463412 postgresql-client-13_13.11-0+deb11u1_mips64el.deb 42a204bab58d8fc298789c7c560e71b7817fa637 162556 postgresql-plperl-13-dbgsym_13.11-0+deb11u1_mips64el.deb 4354cde1c30b7f37a6d1c75dd10f7fc631651fe6 83496 postgresql-plperl-13_13.11-0+deb11u1_mips64el.deb d49ccbe9854d3bd3875beee0f02045473845fd53 165876 postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_mips64el.deb c67f115987d1d132b694afac2867a216af7520a2 101408 postgresql-plpython3-13_13.11-0+deb11u1_mips64el.deb f974b020307f4527a5dfa6a11d328ee89f90b696 76228 postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_mips64el.deb 8343aa6a7b1985d98525dd13b68eb5cb5902dfcd 39356 postgresql-pltcl-13_13.11-0+deb11u1_mips64el.deb cd1c61eb22b6b5429386f46587ee19ac99766605 1046576 postgresql-server-dev-13_13.11-0+deb11u1_mips64el.deb Checksums-Sha256: 0eb3a2207350c0787645f575398649eeff19686784e9cceffbabb68f33bc8c86 38464 libecpg-compat3-dbgsym_13.11-0+deb11u1_mips64el.deb 874fe385c8f8891385374552b0cf8e2b5f2dea1493103f3d9492b883abc0612e 24416 libecpg-compat3_13.11-0+deb11u1_mips64el.deb bca35ed0490bc91054f353f11ccb4ce704549e929b1b457e8d71be35837e77ec 230908 libecpg-dev-dbgsym_13.11-0+deb11u1_mips64el.deb 40cdaf34465ce4cf7a534081b5fcb3f97fca143e1a13c1bdf04fb2cd8c046874 276604 libecpg-dev_13.11-0+deb11u1_mips64el.deb aeb934537d0f8139d5d60c4c2ce6754fabc96290833da63a204aa557ecf8b565 113952 libecpg6-dbgsym_13.11-0+deb11u1_mips64el.deb a14b3ed588909c0b320441358031d53183b58c984d40a33e92c042849d447f2b 58000 libecpg6_13.11-0+deb11u1_mips64el.deb 3c68738918817c1bf8ab31fc9ab4479c78e9cf2fbdbb8e334f03bd088e46039d 92120 libpgtypes3-dbgsym_13.11-0+deb11u1_mips64el.deb dc5b4bbb57aa09aa599a286f836d5d7087fab08c03f583fbc46f4bea9efadabb 46148 libpgtypes3_13.11-0+deb11u1_mips64el.deb c38f88fa61e57e365c257b151e7b4f8bf55095927987ecceb25968a8e4fbaecf 146628 libpq-dev_13.11-0+deb11u1_mips64el.deb a463c8eda8de7ff35099cf61a7a6f2d32b2f501ff9c4f783d1aff22ac0ceb53b 263996 libpq5-dbgsym_13.11-0+deb11u1_mips64el.deb 4336fc3e2420230ec8f3dbbc47c9c2ac6b3d6e6be07c934ce92c1ece98d68faa 170872 libpq5_13.11-0+deb11u1_mips64el.deb f4b45a5ca799457d85321df440cd40f049960fbc69ffeb39ce0d40e36291a244 15093568 postgresql-13-dbgsym_13.11-0+deb11u1_mips64el.deb cf360d9b2434149133c9c5a0004d77a1bf59bc23c33461feadaa650694867506 16268 postgresql-13_13.11-0+deb11u1_mips64el-buildd.buildinfo 90c613d06aa723cc8f9177095174477b6200cd70526314a77145ce10a40a87a5 14723284 postgresql-13_13.11-0+deb11u1_mips64el.deb aaa139f7771f3636cae57d8d63a7e1846ec70ed1b605dac338a4176908b51d28 1954460 postgresql-client-13-dbgsym_13.11-0+deb11u1_mips64el.deb 672ef2bb612616cc363f4f08b592c13da2ff9b3842ff858b5dce14b890a77353 1463412 postgresql-client-13_13.11-0+deb11u1_mips64el.deb 01c87135a8e29d066a981e4b11af6fed6babf2f4f6d7629664ab799d275779d7 162556 postgresql-plperl-13-dbgsym_13.11-0+deb11u1_mips64el.deb cd8fa58b8eb60b086b61576ae4ed4ff1ba2c25fe068c034971c027cede5faea8 83496 postgresql-plperl-13_13.11-0+deb11u1_mips64el.deb e520be958a139bbae4c25e593baeb8094e173cfa572ab4a96850e4204013d196 165876 postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_mips64el.deb 6eea519bd752cc6f63cab558c3c6705e6078e648799c417e4818f3bd3f0c66c4 101408 postgresql-plpython3-13_13.11-0+deb11u1_mips64el.deb 6f132688adcce1405bb08a7141f695fbf57dc3d06b46c6c46ac7756aa6d1c6ae 76228 postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_mips64el.deb 519475065dc221c455a41ebdae504233f3faa7b57d28701d9726a937c2b21332 39356 postgresql-pltcl-13_13.11-0+deb11u1_mips64el.deb 5fdb120d8aecfec4039a879641ddb0ba792fbd94cf2a191024686bfef2393c1d 1046576 postgresql-server-dev-13_13.11-0+deb11u1_mips64el.deb Files: f5028cee444413c1f1474880d840cd0a 38464 debug optional libecpg-compat3-dbgsym_13.11-0+deb11u1_mips64el.deb 8f8165ba4a50ab88619b9d7582ca05e5 24416 libs optional libecpg-compat3_13.11-0+deb11u1_mips64el.deb 0e141592be142e06d3c35cc954f6e81b 230908 debug optional libecpg-dev-dbgsym_13.11-0+deb11u1_mips64el.deb edfd498a1de82a51931e53c65147a876 276604 libdevel optional libecpg-dev_13.11-0+deb11u1_mips64el.deb 33eeeab34ba18e34396ed4ca08cbdc42 113952 debug optional libecpg6-dbgsym_13.11-0+deb11u1_mips64el.deb 884ecb9fe8a804077deb895bd0e30012 58000 libs optional libecpg6_13.11-0+deb11u1_mips64el.deb 44206de9c44b961e452b5a0a7e57860b 92120 debug optional libpgtypes3-dbgsym_13.11-0+deb11u1_mips64el.deb 304f681c637fdb62abd9ebe1860fa4b8 46148 libs optional libpgtypes3_13.11-0+deb11u1_mips64el.deb 314cb3c5900846892d87f096aac66f4e 146628 libdevel optional libpq-dev_13.11-0+deb11u1_mips64el.deb 4e2bbc320afb3f6e85be9d57369d8ccd 263996 debug optional libpq5-dbgsym_13.11-0+deb11u1_mips64el.deb e8f5c9dfe96267b860052f899842b91c 170872 libs optional libpq5_13.11-0+deb11u1_mips64el.deb f5bf2efcb0f3e14b000593126fb2fe8b 15093568 debug optional postgresql-13-dbgsym_13.11-0+deb11u1_mips64el.deb 7ea136e5416036c6f16601b753b56ba6 16268 database optional postgresql-13_13.11-0+deb11u1_mips64el-buildd.buildinfo 29915c54900d7b6e6edfab9784213795 14723284 database optional postgresql-13_13.11-0+deb11u1_mips64el.deb 954244eaa5a2ccf6ed17073c5d94f692 1954460 debug optional postgresql-client-13-dbgsym_13.11-0+deb11u1_mips64el.deb 3f2f48d48041d4743b89ddc487d868ef 1463412 database optional postgresql-client-13_13.11-0+deb11u1_mips64el.deb 79b446007568250c9646df0485709fce 162556 debug optional postgresql-plperl-13-dbgsym_13.11-0+deb11u1_mips64el.deb 059b216e8d36b443dde418884014532c 83496 database optional postgresql-plperl-13_13.11-0+deb11u1_mips64el.deb 752d83ee6346c7dd4df6c633474696ef 165876 debug optional postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_mips64el.deb db739052abe12a46e7332dddbfcfb0e3 101408 database optional postgresql-plpython3-13_13.11-0+deb11u1_mips64el.deb ccbfa8a2387002e10ecb15103bd1353b 76228 debug optional postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_mips64el.deb e6650fa3fd3256a10725aabcb728cd60 39356 database optional postgresql-pltcl-13_13.11-0+deb11u1_mips64el.deb fab09daeb4b624694ae1eaf0696c13c5 1046576 libdevel optional postgresql-server-dev-13_13.11-0+deb11u1_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE2zbpcZa+qSgfG9hJJ+DnhBlDinIFAmRckLQACgkQJ+DnhBlD inJkwQ/+P8NqWhVkcdtu3vhb2BmFjrndFhbVhs6uOCRiVa1Zxpt+Mka9nYvBPKMg EJVIjpIjCfKNY1VMatU21BkmZrOv5Wk+wfPEC47hqPNwlrMxBt+FfnKBt1vToqyt OzEdOft++VizK2lfWWenpuSdLNMb3Uo4kUrNexD2Ut+iLKzNHs1Orac/o2cJ4w0R 5VfyXwXcSPV6Rv29D1Wc4sSqUzUpjcJAF11k+PLx1VO9G5wiTZqAAWv3sgXdakds X6oT6q/gjsDDCUbj3y3t/FZnRqJofeIEzWDjVrUjyguTIKvL2RjIB+UU8jEyHRfO xfztDhJNO0rZDfqWzaoAwCdB1Km6JeLlL13j7i6eHF3MpchI660HnX4YicNwl3gV OJGgF9eDeXdvXhuTHIM1DkOrN2VYlioCNNNKaXT7DuwIiBDzmcrogrEt9jA7mShi xXn3x98odnsHkYlVB4ZoehmLAoupsx+uaucfRazD7C0+IkLVwiOTvZVdFdwgJbtM xzGSm1nzZAN339CKZXK+9sbhgdgBiuUDDszx3kxnmQlvFEN1DIOU/jtnfLzBV1gs /ljs4Z4HAgfSpR20/b5AK/McvkVBpbPlogK9LwpFs5Xaz41JiN6k2w4cEfC7jpSj +VNir89EZWdIaDNwP7J1fVONaZDRjwoOuiCRl4e5EUt3zr/JrBY= =b9mU -----END PGP SIGNATURE-----