-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 10 May 2023 20:35:39 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: ppc64el Version: 13.11-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-osuosl-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.11-0+deb11u1) bullseye-security; urgency=medium . * New upstream version. . + Prevent CREATE SCHEMA from defeating changes in search_path (Report and fix by Alexander Lakhin, CVE-2023-2454) . Within a CREATE SCHEMA command, objects in the prevailing search_path, as well as those in the newly-created schema, would be visible even within a called function or script that attempted to set a secure search_path. This could allow any user having permission to create a schema to hijack the privileges of a security definer function or extension script. . + Enforce row-level security policies correctly after inlining a set-returning function (Report by Wolfgang Walther, CVE-2023-2455) . If a set-returning SQL-language function refers to a table having row-level security policies, and it can be inlined into a calling query, those RLS policies would not get enforced properly in some cases involving re-using a cached plan under a different role. This could allow a user to see or modify rows that should have been invisible. Checksums-Sha1: d530068ad95044ffb4aa8f4879253ab249baf827 37944 libecpg-compat3-dbgsym_13.11-0+deb11u1_ppc64el.deb d54e8c0f9e9c37c172f56ab121c609ee749de145 26520 libecpg-compat3_13.11-0+deb11u1_ppc64el.deb bc7073e5c9afbc23130dd628b489c470a9d1cfe2 221332 libecpg-dev-dbgsym_13.11-0+deb11u1_ppc64el.deb 44722476b2545c65e80ba5d99aae3bcc1b9511bb 286500 libecpg-dev_13.11-0+deb11u1_ppc64el.deb 0dc220814e1cd90c8ed735d2434f919bb6acb82e 110656 libecpg6-dbgsym_13.11-0+deb11u1_ppc64el.deb ff0e0c404d9db079435e4a9a7ba4e40454df91cf 64760 libecpg6_13.11-0+deb11u1_ppc64el.deb 7ecf23b3f2c06cb4531b289a193a57100d006882 91556 libpgtypes3-dbgsym_13.11-0+deb11u1_ppc64el.deb 46290317d55a34f99587523d673dcbffff7160f9 52180 libpgtypes3_13.11-0+deb11u1_ppc64el.deb f53840ef3a7b3a7f933b5ddb93cd957904961573 154404 libpq-dev_13.11-0+deb11u1_ppc64el.deb 9b141c5c25d21d418fabe125fcc9ec62512c39b6 262648 libpq5-dbgsym_13.11-0+deb11u1_ppc64el.deb 823a90104c5ddad9be924afd562c45915085dcd7 193516 libpq5_13.11-0+deb11u1_ppc64el.deb c3817b0ce6f19d71850500969c32d8b083139492 14735176 postgresql-13-dbgsym_13.11-0+deb11u1_ppc64el.deb fa254c95761dfe2c101c33861c75ca4ce84e2dce 16368 postgresql-13_13.11-0+deb11u1_ppc64el-buildd.buildinfo 108d0973d7356390fcfce29b833963d0ade53d69 15537952 postgresql-13_13.11-0+deb11u1_ppc64el.deb 48632ed8d00d6d3bd29d903d6c9e041c69361226 1903732 postgresql-client-13-dbgsym_13.11-0+deb11u1_ppc64el.deb 17cae8c7905bee712fec2dcad4d086b59fb06b62 1533776 postgresql-client-13_13.11-0+deb11u1_ppc64el.deb 5dc13201d66b820d5ada7e5602c8e694401a40ed 157872 postgresql-plperl-13-dbgsym_13.11-0+deb11u1_ppc64el.deb 3daa25996f0333342c002286a53ad4dca5c689ea 89048 postgresql-plperl-13_13.11-0+deb11u1_ppc64el.deb 3eff921c7d28796d21fbeec1fb6d2149f93accbd 159964 postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_ppc64el.deb cbf692364e09f3dcb726081fdecb8e66185d247b 108532 postgresql-plpython3-13_13.11-0+deb11u1_ppc64el.deb 7614dae1b21f370d575a7b655370fd452fe5f3ea 74536 postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_ppc64el.deb 610c27c2932c4fe47892a985a894aa9673ac889a 42312 postgresql-pltcl-13_13.11-0+deb11u1_ppc64el.deb a873bdb5c32107f895305925904320e0b8941aba 1052408 postgresql-server-dev-13_13.11-0+deb11u1_ppc64el.deb Checksums-Sha256: ef436587a7663a33c87693f0961e78f8ee49198828606fbd660581bbf1468e62 37944 libecpg-compat3-dbgsym_13.11-0+deb11u1_ppc64el.deb f6250ce2517b167eb8ac7f604b3e0cb3d551332baa4b559dd35bc37f5e0c2bdf 26520 libecpg-compat3_13.11-0+deb11u1_ppc64el.deb d92215ede434332edbaa6e75e939bf495aaedaf7449710a99be645c5b053da40 221332 libecpg-dev-dbgsym_13.11-0+deb11u1_ppc64el.deb 93c9df89ba0a51ebed41534eac06b449549109a3592a6234d1a8603a0c868ed3 286500 libecpg-dev_13.11-0+deb11u1_ppc64el.deb 717db4881ddecc576f28af508a4ae10913f450909eeca52fe0f0140212572e7e 110656 libecpg6-dbgsym_13.11-0+deb11u1_ppc64el.deb a64418b5e278969f6aa6325737c5cd99d813e9bc0a13aaeb10103438764b9239 64760 libecpg6_13.11-0+deb11u1_ppc64el.deb b4a5dd1973ebd043c3fcc49ee89a2d28f502044daa654b7081774f08f105118c 91556 libpgtypes3-dbgsym_13.11-0+deb11u1_ppc64el.deb 9c771a4851586734a7234b87d0550bdd6fb006556cfcc7d61f50f762aefbd811 52180 libpgtypes3_13.11-0+deb11u1_ppc64el.deb ecaf9b9b9a9198a22f6f978fb7451fc42cd788b9cb47d9152e5ae814f8fc22df 154404 libpq-dev_13.11-0+deb11u1_ppc64el.deb 33099735adecf0b8042041382ecfb18d033ea8229543f8a99b3526a3a5afd504 262648 libpq5-dbgsym_13.11-0+deb11u1_ppc64el.deb 798663744e1cfd42b11fa0e458091129094e10725268234f27b50c2cfe3cc3d8 193516 libpq5_13.11-0+deb11u1_ppc64el.deb 6cf2e4740eb6fc835ecd7629d6c96fdeb31664140cb0841fd61ffa2181797df2 14735176 postgresql-13-dbgsym_13.11-0+deb11u1_ppc64el.deb 16f54fe04c4920003733b584c5c7340cf5f96804fc7c1b966b27022d9450c77f 16368 postgresql-13_13.11-0+deb11u1_ppc64el-buildd.buildinfo adc34f010d227d77b3d7cc848da5fb119db47f1588b9db53aef13c356eb2bee7 15537952 postgresql-13_13.11-0+deb11u1_ppc64el.deb abe9ce96256311b23a2589735818ec29ed4cc962878a5317d6598f54a3985913 1903732 postgresql-client-13-dbgsym_13.11-0+deb11u1_ppc64el.deb 8060340c809b6d9bf6149de016a95251bfafcc0ef3b8aed57a036fd9dcd10316 1533776 postgresql-client-13_13.11-0+deb11u1_ppc64el.deb 07cb2f12f89150e83c3fbfcc033429da8b5bb470eec0d3094bf9fbd9d36d984f 157872 postgresql-plperl-13-dbgsym_13.11-0+deb11u1_ppc64el.deb 02e74d9709dbe7fd48f62cbdd193e7c41c14046c190ddc9bedd56f5f279770f9 89048 postgresql-plperl-13_13.11-0+deb11u1_ppc64el.deb 31dc351cd2815ad65a54a0c14694a01c41cdde70c1d0d996b4c4208f43534a51 159964 postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_ppc64el.deb 05b2bf68923df98edb9f1763de0d48f5f51ff137198992c990c7df5e4c005b79 108532 postgresql-plpython3-13_13.11-0+deb11u1_ppc64el.deb 1bb559cf3872fd9dee340253d75114d845659389961eb8f596e71569da13ad5e 74536 postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_ppc64el.deb e7a89539b52a5850c3e357344e3246d1779034a749db276951b6486ec457eea9 42312 postgresql-pltcl-13_13.11-0+deb11u1_ppc64el.deb b21606d5339b0f1a18f0cd1fb3b2a868540509819a0a068b062fa538cc9140b1 1052408 postgresql-server-dev-13_13.11-0+deb11u1_ppc64el.deb Files: 93240efadf9b7aca776b230d046f549d 37944 debug optional libecpg-compat3-dbgsym_13.11-0+deb11u1_ppc64el.deb edfcd53f5f4dfc4ea4d529bbfb95df11 26520 libs optional libecpg-compat3_13.11-0+deb11u1_ppc64el.deb f9fa90c13fea808713bf7974fc54d016 221332 debug optional libecpg-dev-dbgsym_13.11-0+deb11u1_ppc64el.deb 564aa5c9280ffa664f54390f23f6fd38 286500 libdevel optional libecpg-dev_13.11-0+deb11u1_ppc64el.deb 8e4d2b6b4b92825088e189ae6e94830f 110656 debug optional libecpg6-dbgsym_13.11-0+deb11u1_ppc64el.deb 1721c0cf49a93159fc074c0cdf18023e 64760 libs optional libecpg6_13.11-0+deb11u1_ppc64el.deb 013892b75d748ad02b48484e9cfeec6b 91556 debug optional libpgtypes3-dbgsym_13.11-0+deb11u1_ppc64el.deb 4f544c87bdafb0358adc42bb5f465a15 52180 libs optional libpgtypes3_13.11-0+deb11u1_ppc64el.deb 6186efc3a3c68313cfd6d5d6238fd024 154404 libdevel optional libpq-dev_13.11-0+deb11u1_ppc64el.deb 502680a737a347bd30f753dd1de87cba 262648 debug optional libpq5-dbgsym_13.11-0+deb11u1_ppc64el.deb 809b5245e44fe4b41841e7891d349b97 193516 libs optional libpq5_13.11-0+deb11u1_ppc64el.deb 8595a37fe6113e163a9c00bee7882460 14735176 debug optional postgresql-13-dbgsym_13.11-0+deb11u1_ppc64el.deb 00ef418fa49df5477f9c24ae3562a0fc 16368 database optional postgresql-13_13.11-0+deb11u1_ppc64el-buildd.buildinfo 9a989fd25f890e343f8046660f551ba7 15537952 database optional postgresql-13_13.11-0+deb11u1_ppc64el.deb 3053fd51560d0e6b5d6377766623cede 1903732 debug optional postgresql-client-13-dbgsym_13.11-0+deb11u1_ppc64el.deb d585669907651532198126855bf31022 1533776 database optional postgresql-client-13_13.11-0+deb11u1_ppc64el.deb d3d04b70dbf60e34d006e540e73635bc 157872 debug optional postgresql-plperl-13-dbgsym_13.11-0+deb11u1_ppc64el.deb 3d90104cb863cd5b44b5f8a471c5fe1d 89048 database optional postgresql-plperl-13_13.11-0+deb11u1_ppc64el.deb 58c416c50b1f08e69a92e9ff95478c81 159964 debug optional postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_ppc64el.deb dc2e284241bd1a22211040624688b4e3 108532 database optional postgresql-plpython3-13_13.11-0+deb11u1_ppc64el.deb a45e29ae6ae2845f706a66bb593600e1 74536 debug optional postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_ppc64el.deb d659faaea86b485631c273839363cef7 42312 database optional postgresql-pltcl-13_13.11-0+deb11u1_ppc64el.deb 0be6343968d8997672222cb0ed5eb2ac 1052408 libdevel optional postgresql-server-dev-13_13.11-0+deb11u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEG6HwUrz8cgTg6xaPZnETzaamDSwFAmRb/j4ACgkQZnETzaam DSzx6A//V9jQ4kbMk7D53USsOIUq9EAcTCcVvCCkCU2+/C0hGHdzA9BkZErr+HlI jHXJ6c2BAf6nijRx1tdZbpUaiv0//e2/L339/VXjfwWTcjPYJqT34WkWYt0APA1y 8cH46CjzBzPsrjqYqvPbxvWMlB1cvfKKUwR9qfcxpKHkwJyU2M5JDKIKiBZLIz3Q HVD2d6om0NtochSVwRXaDxcDGwCW0zxF7Ln0iiR1Det3Z47nGiKWMiLFhk2SjN6S qlekZtQIMHoxsW78C+mdan+mqSze6FCAzlXi3/zSuYZzuJZL0CNGFcqvvLd0HlIQ AMjfJz/HO/aZSiNNA5Gzcn1m+//G/ZP0uvt8446ICgIWGTWMJKmMKJx5uMUVYw3v vKHc/gF0DEnzmw95A5JgP2P+bRvn2osq4fCZJ/Mn3J9YffBDvsmPzxpWI6jHYicP CBZ95I7E/wMhcJP12rl29v3sNzkUL/O0k391/c28oidDaPXnB9C6W9jkTNCv++FN n9tzOwGNGyxh2zdhnD24gzRg35h0mHDDK5NrSHDdF1DkCbNmsCaM9CW4ySNs8CBI Q64mkDiLE6ktT3jg0WYavCJDrDnFpxGWvml1bO0vIXUCMk78+kLjSUktxm5SYTxC kYRPwL2hVoI3N/tEgVrV99rNSKwGMcRoFSdj2Tw0O+8djGBvASc= =/ybn -----END PGP SIGNATURE-----