-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 10 May 2023 20:35:39 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: mipsel Version: 13.11-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.11-0+deb11u1) bullseye-security; urgency=medium . * New upstream version. . + Prevent CREATE SCHEMA from defeating changes in search_path (Report and fix by Alexander Lakhin, CVE-2023-2454) . Within a CREATE SCHEMA command, objects in the prevailing search_path, as well as those in the newly-created schema, would be visible even within a called function or script that attempted to set a secure search_path. This could allow any user having permission to create a schema to hijack the privileges of a security definer function or extension script. . + Enforce row-level security policies correctly after inlining a set-returning function (Report by Wolfgang Walther, CVE-2023-2455) . If a set-returning SQL-language function refers to a table having row-level security policies, and it can be inlined into a calling query, those RLS policies would not get enforced properly in some cases involving re-using a cached plan under a different role. This could allow a user to see or modify rows that should have been invisible. Checksums-Sha1: 569ad3a21abb6d7badf9f8c66fffba8091285d45 37680 libecpg-compat3-dbgsym_13.11-0+deb11u1_mipsel.deb 6e72ed29c161cb8577a04fe6f8fd4a0586f07e26 25316 libecpg-compat3_13.11-0+deb11u1_mipsel.deb 6586dfe3b04d55f7cf104c6661d8d4911a095846 236544 libecpg-dev-dbgsym_13.11-0+deb11u1_mipsel.deb 7571daffb6fc8702c061bd30bcc388c8289ecffb 274964 libecpg-dev_13.11-0+deb11u1_mipsel.deb db9e50d0d8ac80d1e8e8040a5023de1c7b24e519 109268 libecpg6-dbgsym_13.11-0+deb11u1_mipsel.deb e76b540b2d9308f58f358ec1cd243ce6ffc925ca 59152 libecpg6_13.11-0+deb11u1_mipsel.deb d236c4129da28b8eb64ea9b2f528747a08a14929 89364 libpgtypes3-dbgsym_13.11-0+deb11u1_mipsel.deb 27157a3b39ed410ac99dee8e2dff0d2c2e30958f 47708 libpgtypes3_13.11-0+deb11u1_mipsel.deb 00e5227f2f17e921df2b091bc585dca58ee999e1 369440 libpq-dev_13.11-0+deb11u1_mipsel.deb 9f046cf2e7afa605d9cb5b4a9e819e0890d6b200 250512 libpq5-dbgsym_13.11-0+deb11u1_mipsel.deb ce27d424a64f0f0bcde49456dc183e9dcd7a60e0 171616 libpq5_13.11-0+deb11u1_mipsel.deb e4597d96c6768e50055f97caf392d19f88f5f4d3 14403160 postgresql-13-dbgsym_13.11-0+deb11u1_mipsel.deb 18ccaa69d83904a56ff37dfadd1ceb5093315a3e 16265 postgresql-13_13.11-0+deb11u1_mipsel-buildd.buildinfo 007ae85e243e69c6952a559e6eba95be2dcf17c3 14647892 postgresql-13_13.11-0+deb11u1_mipsel.deb 5ca387882e2627f59826f8a1e49d9771e22b5194 1864580 postgresql-client-13-dbgsym_13.11-0+deb11u1_mipsel.deb a9fbd023c224bbc8134ce5d4f6bfea72f0723a2e 1466308 postgresql-client-13_13.11-0+deb11u1_mipsel.deb f7f715c63f95dcbe13ac0fb2f077e07067cc58f2 152084 postgresql-plperl-13-dbgsym_13.11-0+deb11u1_mipsel.deb d5ec59dd75e94538e1fa22c3063f507361d0fe7a 83824 postgresql-plperl-13_13.11-0+deb11u1_mipsel.deb e41ad084854d4b165fb6f9cab46c502af244fe0c 154512 postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_mipsel.deb ac8c35b16ba24833c5854602cc5ff0668411c9dd 100932 postgresql-plpython3-13_13.11-0+deb11u1_mipsel.deb 8b7c6014049c614682a55a30227e9c81cb2caf0f 72180 postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_mipsel.deb fabd8268a05fdbb558d18430500e357b6541ba0e 39268 postgresql-pltcl-13_13.11-0+deb11u1_mipsel.deb 59753edb27ddafd1aa5e048faa2dc6ffb42d09f1 1046500 postgresql-server-dev-13_13.11-0+deb11u1_mipsel.deb Checksums-Sha256: 5f88f35e769587644282bfa4b5f8a1dc78227e7a20b357fbb3c6e1239c3d3ef8 37680 libecpg-compat3-dbgsym_13.11-0+deb11u1_mipsel.deb 891b02a48b86e392e1c4ffae69bd01f906c971eb4403948b981dec7c523be417 25316 libecpg-compat3_13.11-0+deb11u1_mipsel.deb 93c11ce96b6bb416a3285f48d4d4a3c0147eccbd9578719b6e4ca7d47b1696ac 236544 libecpg-dev-dbgsym_13.11-0+deb11u1_mipsel.deb 6ecef71e03423eb6d6e820ed36c4c5ae470ba12a1f78e18f755cd4a78f7fec8f 274964 libecpg-dev_13.11-0+deb11u1_mipsel.deb b996840c5403a4eedab2479013c8fe0393fffbaf71e736d13e19b679fc307286 109268 libecpg6-dbgsym_13.11-0+deb11u1_mipsel.deb 03c8076e28ad41a0a065fe9873cb31d0c4a225d1b2d19007d42753a02fe4cbef 59152 libecpg6_13.11-0+deb11u1_mipsel.deb 370872f3049defc874299f0a7b2644d27df1c5c5d27104c3175a4f8f81441977 89364 libpgtypes3-dbgsym_13.11-0+deb11u1_mipsel.deb 0cc33e472c4bbc3e987122ed492580b51b775e2608322f37c2cb5ff7070f3bd8 47708 libpgtypes3_13.11-0+deb11u1_mipsel.deb cbbdaad599bb8e84864979947e634d6c6204490156a9f57ff14271d525bd0122 369440 libpq-dev_13.11-0+deb11u1_mipsel.deb 338d572dff5fc1f5b65c990ce54f8c65849ec88c42aea20d4e36927ad93fbabe 250512 libpq5-dbgsym_13.11-0+deb11u1_mipsel.deb 8f0b817a1ca341bb4de89e1991b749216e1e99e8dc8f0360c5604006a9023ab5 171616 libpq5_13.11-0+deb11u1_mipsel.deb 88987023a330702585ffa183f2281f086cdeea5fd0d013dff84bb572a10e53ec 14403160 postgresql-13-dbgsym_13.11-0+deb11u1_mipsel.deb e233e8b646af5e2cfa7d085f68d8400d0a66e6ef2bb053c3e07a0916e649851a 16265 postgresql-13_13.11-0+deb11u1_mipsel-buildd.buildinfo 11c27a96b87470238a7ca44283da30f2ce4733d88f7839b615052fc2da68c74c 14647892 postgresql-13_13.11-0+deb11u1_mipsel.deb 56b0daece547ac80503f295aa636dfa15ef2f3db10c263efe10862ba9a5cec73 1864580 postgresql-client-13-dbgsym_13.11-0+deb11u1_mipsel.deb dc8465990e8c1e5ffcc4b71341341be7f0e7ef3ecd240f685637bb5b685ccb9d 1466308 postgresql-client-13_13.11-0+deb11u1_mipsel.deb 36eb4c44fa9d47aed6c7ed0e643499ced2222e4cd758ad8336c9ec47db856319 152084 postgresql-plperl-13-dbgsym_13.11-0+deb11u1_mipsel.deb 5f2f2dabdcff46ed62ed7e86b3605c55e2ac447640f315fb95b01880b5730a00 83824 postgresql-plperl-13_13.11-0+deb11u1_mipsel.deb 567f347cf78c8022f889ef63fd7a7592b98404104024ec6d9ad3662680040cf9 154512 postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_mipsel.deb 0ccb0e10d53dc94e14c77ee1a21ca71a7b20206f42904dc8413e8d3101e95f94 100932 postgresql-plpython3-13_13.11-0+deb11u1_mipsel.deb 256fb87a45f0222afe074f0407168f57a8002d3a2c94194dcd174ff7cd5485f0 72180 postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_mipsel.deb 9b20ecbf2ce8ba94ac7a57fb127e3645a43988b5a1a8233a8a1b68a10c8246c4 39268 postgresql-pltcl-13_13.11-0+deb11u1_mipsel.deb 6443e6f2b2bb8757a0f4212b2f89fafcd74fac4ff22e5769896293880ff2f012 1046500 postgresql-server-dev-13_13.11-0+deb11u1_mipsel.deb Files: cf4f55649577d29bbeac6b4f0ad11729 37680 debug optional libecpg-compat3-dbgsym_13.11-0+deb11u1_mipsel.deb 452c36eca84c0b4caec6c48e9a354776 25316 libs optional libecpg-compat3_13.11-0+deb11u1_mipsel.deb d5396e5cf4c8fb66ec84c7946ef3e96b 236544 debug optional libecpg-dev-dbgsym_13.11-0+deb11u1_mipsel.deb 8105b5ba60830bbea570c36429c34a5e 274964 libdevel optional libecpg-dev_13.11-0+deb11u1_mipsel.deb 5bebf9cf91a3b827fb69e255288db0c4 109268 debug optional libecpg6-dbgsym_13.11-0+deb11u1_mipsel.deb 340cb182db997631e40b9ae7513ffaec 59152 libs optional libecpg6_13.11-0+deb11u1_mipsel.deb 47f6fa3c4f738f19931ab99729ae1d8b 89364 debug optional libpgtypes3-dbgsym_13.11-0+deb11u1_mipsel.deb c149504c519a49bfd721c2b43cfa2f3b 47708 libs optional libpgtypes3_13.11-0+deb11u1_mipsel.deb 1a0b2f89fa4ecd83b74f2a7b1f438400 369440 libdevel optional libpq-dev_13.11-0+deb11u1_mipsel.deb 784722eb444ec7a0d17309e6e47fad1b 250512 debug optional libpq5-dbgsym_13.11-0+deb11u1_mipsel.deb ad81c87660d391a3448136016412abd6 171616 libs optional libpq5_13.11-0+deb11u1_mipsel.deb 9633d99b89f6f5a85537f92828433db8 14403160 debug optional postgresql-13-dbgsym_13.11-0+deb11u1_mipsel.deb f81b952d0537b16b1f9423c7a4796680 16265 database optional postgresql-13_13.11-0+deb11u1_mipsel-buildd.buildinfo 085ab22cee95e638096f3009843cba46 14647892 database optional postgresql-13_13.11-0+deb11u1_mipsel.deb 858330ddfcfec5dce96366f5b635deb9 1864580 debug optional postgresql-client-13-dbgsym_13.11-0+deb11u1_mipsel.deb b1ff97bb6ff55b1df04ee05b2d51c741 1466308 database optional postgresql-client-13_13.11-0+deb11u1_mipsel.deb b8af1adc486a074ef86865fa414c11c5 152084 debug optional postgresql-plperl-13-dbgsym_13.11-0+deb11u1_mipsel.deb edf9d912f5f46ffbd636707f3ebf3fb8 83824 database optional postgresql-plperl-13_13.11-0+deb11u1_mipsel.deb ee75653b8cf9968e19422961d98c9e03 154512 debug optional postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_mipsel.deb c86836736ded5008a1ac74a9dcbcf060 100932 database optional postgresql-plpython3-13_13.11-0+deb11u1_mipsel.deb 4c3df89233d84aada97db636e3bd81d4 72180 debug optional postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_mipsel.deb 5510116e070f0a8b2cbe6c437234369b 39268 database optional postgresql-pltcl-13_13.11-0+deb11u1_mipsel.deb b2b6c5e434e414387d81f9af730b1a63 1046500 libdevel optional postgresql-server-dev-13_13.11-0+deb11u1_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7FUbSrfgk+qhJhySoQbzkdO+xGgFAmRcPm8ACgkQoQbzkdO+ xGiHMhAAlsvvzZaln0OUVdNJ24G9qoV70TXWqK3ZzVIjA3Ec8yPVdJ5qi5HBML8x sZf8fierP5o5qywlLY/jxl6zz9U6LqqRm+wRzZq/UtrsPA/dK078qmWZ5mDDUlNF W5QUZBGTLys270atTfOIFF5uA4Z1TCQ8DgMlVceRETdbf6cwnrLBmb3NS1vg2QHV 3hljdL1JTHkTJZRuJSkAPbfLx+LCl6dGPzxdq74KH8+IOP4hEilPvidVvNyB1s6J +0eOWzPrGv5uMAfkmnNd/xLw0HS9My+i+qz70eyO8haHX/hrcfQums1yNGlNv6ze nq16ANjvOjln77djTezZFl1dZ/lbqcj62AjlSrq1pT7xNzwOd4x6xMSegz2s1cbS 0gG0mljd9m4T4wugn77bEkqcNTfWp+dTcD64CLBjOP629S9XsAMgXJm6L+dNMwGH irxhdqV5LHj4Ls/tXVjxhIqA1LZTlexU5w+4J5fddbFEboheqweiJsP/ychZP/BM EWSrbJeKRPpMbOs7VQosqTYqxSxJpTBA1uOHA7/aAJZnVFTniYSii3vde97M7BqJ l0bxsOf3T6loR8KZ7YB853dqCwWMCRLR+Z437rQxDFY3pmqNMP1KJ04VShghBT5C N7kXiakjXAeftcGxB9jDJL2wvrS4+4lmLnqMXip4H34Ckkec1aU= =+Zbw -----END PGP SIGNATURE-----