-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 10 May 2023 20:35:39 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: s390x Version: 13.11-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: s390x Build Daemon (zandonai) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.11-0+deb11u1) bullseye-security; urgency=medium . * New upstream version. . + Prevent CREATE SCHEMA from defeating changes in search_path (Report and fix by Alexander Lakhin, CVE-2023-2454) . Within a CREATE SCHEMA command, objects in the prevailing search_path, as well as those in the newly-created schema, would be visible even within a called function or script that attempted to set a secure search_path. This could allow any user having permission to create a schema to hijack the privileges of a security definer function or extension script. . + Enforce row-level security policies correctly after inlining a set-returning function (Report by Wolfgang Walther, CVE-2023-2455) . If a set-returning SQL-language function refers to a table having row-level security policies, and it can be inlined into a calling query, those RLS policies would not get enforced properly in some cases involving re-using a cached plan under a different role. This could allow a user to see or modify rows that should have been invisible. Checksums-Sha1: 46110b012518b66ea5433d6ba769be6c5e9f308e 37540 libecpg-compat3-dbgsym_13.11-0+deb11u1_s390x.deb ff748e511e9573ce8205a2c28542faca25ff6c28 24564 libecpg-compat3_13.11-0+deb11u1_s390x.deb 2f51a55a9e4d82e1be6303ff8f996073aec9a1c3 207120 libecpg-dev-dbgsym_13.11-0+deb11u1_s390x.deb a63a1bfc129450db43c9a8ebff758210f40e6f42 269396 libecpg-dev_13.11-0+deb11u1_s390x.deb 668a65a2eb5d7f1c064274af06c2dc1c14600500 111132 libecpg6-dbgsym_13.11-0+deb11u1_s390x.deb 0abbeb8964098b89e51fc81d57bf06f662f2ec92 58368 libecpg6_13.11-0+deb11u1_s390x.deb 2a4ac4d66217d267f9a177012545d034ce45f4d0 89280 libpgtypes3-dbgsym_13.11-0+deb11u1_s390x.deb a1771444e7d62a6b2be13741ef09b039d44ec803 46296 libpgtypes3_13.11-0+deb11u1_s390x.deb f036bdf12e02f74d4b1d5b538c1b456b215c0bc4 135660 libpq-dev_13.11-0+deb11u1_s390x.deb 9e8b0d60d49a654d1670d12d653105a5e1040443 256884 libpq5-dbgsym_13.11-0+deb11u1_s390x.deb e203e3c698f93ad1bc1631b9c6d1741fcc8c0711 171848 libpq5_13.11-0+deb11u1_s390x.deb 073b2ca3075deea62b92956f29a259e8a159ceaa 14842896 postgresql-13-dbgsym_13.11-0+deb11u1_s390x.deb 5a4e6bbe3c387f87313d08724c10fcbf98b47171 16150 postgresql-13_13.11-0+deb11u1_s390x-buildd.buildinfo 2903900034277a895af4423dd53725ab60ce2607 15763104 postgresql-13_13.11-0+deb11u1_s390x.deb aeb8812a81ba2fef37e4877107ba1afef6d3f06d 1871752 postgresql-client-13-dbgsym_13.11-0+deb11u1_s390x.deb 29ff29d0badacee1e7d8ad043083c562998f403d 1462044 postgresql-client-13_13.11-0+deb11u1_s390x.deb 471041abe4031ddd4f83b066253015486f7b80fa 156036 postgresql-plperl-13-dbgsym_13.11-0+deb11u1_s390x.deb 3f2d02ec49948721b19da1e789ab56a41c0782f6 85464 postgresql-plperl-13_13.11-0+deb11u1_s390x.deb eeb60741c2f27afc10d88715e3b82e6e090ec938 156608 postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_s390x.deb 23e75a3a1a06c4c0629fc9fa912788a267c92443 105168 postgresql-plpython3-13_13.11-0+deb11u1_s390x.deb 25c3f58dd9f2b039aae01c34d8670a88c70e27da 73572 postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_s390x.deb 81b971a0553eae80f06ad97d49b80db18c8e0d86 40652 postgresql-pltcl-13_13.11-0+deb11u1_s390x.deb 9ddd7af6f9b6cb36b13616e2f99c758c1bcaf427 1032872 postgresql-server-dev-13_13.11-0+deb11u1_s390x.deb Checksums-Sha256: 4c8b6c634bb48fce15abe1fbea679b5481c78a366ced0895eeba274cf86f56e4 37540 libecpg-compat3-dbgsym_13.11-0+deb11u1_s390x.deb 67ec51d65813518c8f8c45371f255f022ade86f97cebe1c7c89d6506a11d530a 24564 libecpg-compat3_13.11-0+deb11u1_s390x.deb 2a9c0877b9fcfbf185002a1676f260b2b33d7f56da554d42bfeb2145f9fdbb27 207120 libecpg-dev-dbgsym_13.11-0+deb11u1_s390x.deb eaac086c72879ee26fea7d2866bf84718e0a47aff106391ed38bbcd7ab3341bc 269396 libecpg-dev_13.11-0+deb11u1_s390x.deb 69c12a0d77504a82071561a665aa230f849e61d7407095768c0a045a56e1ef3b 111132 libecpg6-dbgsym_13.11-0+deb11u1_s390x.deb 7096fbf54e80edf15b52aa4f7811a31c7cee50ec8895056639676e79189f17a8 58368 libecpg6_13.11-0+deb11u1_s390x.deb 85f6b4cad804c5836cc4bbb850c22d70db71c2537bf8b561e16926ac7459c127 89280 libpgtypes3-dbgsym_13.11-0+deb11u1_s390x.deb 0fb7ecbb8711a0c89f0bf43568d3071cc86ce2fffa5601ffc8e864f4730ee493 46296 libpgtypes3_13.11-0+deb11u1_s390x.deb 83787a3366e4d8b5b7f984c75478c60688c2a8f0e1c0be657295bbd7bdd7c2a0 135660 libpq-dev_13.11-0+deb11u1_s390x.deb d904d5b0151b6847c1a2313a35af7e24f063ae1c173c01498c7f26c719ad7193 256884 libpq5-dbgsym_13.11-0+deb11u1_s390x.deb f260fa3d6f944ab337329747583a1bbd21bd7702d07dfc5276f51ae2d59854d5 171848 libpq5_13.11-0+deb11u1_s390x.deb b0b79b26e5d483a65d685b38e7badadc227bbf9eb062c44fc06e7dbd09e074a7 14842896 postgresql-13-dbgsym_13.11-0+deb11u1_s390x.deb c640bbd32b42aa64c4a34b4f0aa4c1d4bcc95a8f9d1fba205e694cbaabf607ba 16150 postgresql-13_13.11-0+deb11u1_s390x-buildd.buildinfo a431cb1d5381fa1f637533f3850499c3dbf05238ef10eff1fdda1f007788b84e 15763104 postgresql-13_13.11-0+deb11u1_s390x.deb 979db704e7628af06f8c469dcd70e3be3c20b6321e4bb5dc1a9a4a87a985b4a8 1871752 postgresql-client-13-dbgsym_13.11-0+deb11u1_s390x.deb b399835a199593128debf11c31ffee04db3f2f720f87cc0feb916f02950c95a5 1462044 postgresql-client-13_13.11-0+deb11u1_s390x.deb 82903eefaeacfeca813aa46245e902295bbf172229a860be34059d3441ce5a7a 156036 postgresql-plperl-13-dbgsym_13.11-0+deb11u1_s390x.deb d289bacda8f4b6bb886c6859d277fdcee8e8d5cd9a68856828531a6a2327abb3 85464 postgresql-plperl-13_13.11-0+deb11u1_s390x.deb 772e70de852068710334948e692c8909f4a520054ab08952fba5adbf75849d7c 156608 postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_s390x.deb cf24ccbe09ba430872aa7be639d1c2ffdabc2637f3e67a518f29fe1d399d4925 105168 postgresql-plpython3-13_13.11-0+deb11u1_s390x.deb 799e5a5f6c085dbc4978f0b47c8fedab36a3ed966910a0f3d50ef540d01f5822 73572 postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_s390x.deb be3cfb5a5609877857f475e591b1c7ed53177e4f836373a4ea41a69c3d322a7e 40652 postgresql-pltcl-13_13.11-0+deb11u1_s390x.deb 440456683855cf32c22fcb8751cbcf638241b5a25a4a00eb4ae9db21aae737f1 1032872 postgresql-server-dev-13_13.11-0+deb11u1_s390x.deb Files: 9356c3a5cc680f9f4ccfe351e55d049d 37540 debug optional libecpg-compat3-dbgsym_13.11-0+deb11u1_s390x.deb 28562b1206dff6fc2f89ac99adf4079a 24564 libs optional libecpg-compat3_13.11-0+deb11u1_s390x.deb 6a1a2feaed01ff5631cccbab6eecbde0 207120 debug optional libecpg-dev-dbgsym_13.11-0+deb11u1_s390x.deb c78da5dbe7906984d0cf2e7d6c0cc487 269396 libdevel optional libecpg-dev_13.11-0+deb11u1_s390x.deb 300044f568b3199e4d31be60ea70f9b8 111132 debug optional libecpg6-dbgsym_13.11-0+deb11u1_s390x.deb ba6dcc556da21552c91b8a8d5bf7e339 58368 libs optional libecpg6_13.11-0+deb11u1_s390x.deb 973ed06a37b5b47e5c246c695dbd8c2b 89280 debug optional libpgtypes3-dbgsym_13.11-0+deb11u1_s390x.deb cd9d445da69619b322d12c313fd89215 46296 libs optional libpgtypes3_13.11-0+deb11u1_s390x.deb 5a6387a255982686c4d0a24c66119fa3 135660 libdevel optional libpq-dev_13.11-0+deb11u1_s390x.deb 25f7a1f1f958374c2aaf99cde45d77af 256884 debug optional libpq5-dbgsym_13.11-0+deb11u1_s390x.deb ba3c7ac8aef1790489a58a532d104a18 171848 libs optional libpq5_13.11-0+deb11u1_s390x.deb 79f4bf947aa68d66e71962e777affb4c 14842896 debug optional postgresql-13-dbgsym_13.11-0+deb11u1_s390x.deb 17f378b97375b4f6948e5855952c1fdb 16150 database optional postgresql-13_13.11-0+deb11u1_s390x-buildd.buildinfo dfa3c35c1b5c918ec5820a4409f6f3d4 15763104 database optional postgresql-13_13.11-0+deb11u1_s390x.deb a7a50cea57f68b819bf3332535e91d12 1871752 debug optional postgresql-client-13-dbgsym_13.11-0+deb11u1_s390x.deb fa1be0d31e111410a54b20fba979f6aa 1462044 database optional postgresql-client-13_13.11-0+deb11u1_s390x.deb 423819955986dc2b284efb3b2581b9c4 156036 debug optional postgresql-plperl-13-dbgsym_13.11-0+deb11u1_s390x.deb c302687f3cd0988aaf07cae3c4ec050f 85464 database optional postgresql-plperl-13_13.11-0+deb11u1_s390x.deb 7015676b579df7072063abc5d433001a 156608 debug optional postgresql-plpython3-13-dbgsym_13.11-0+deb11u1_s390x.deb 891daca3db4c701fe3291c7c30667267 105168 database optional postgresql-plpython3-13_13.11-0+deb11u1_s390x.deb 2e038e44c9c3a746c873136e2f2bd88b 73572 debug optional postgresql-pltcl-13-dbgsym_13.11-0+deb11u1_s390x.deb 297812cbe610064d98b665f092ef0860 40652 database optional postgresql-pltcl-13_13.11-0+deb11u1_s390x.deb b0d61cfc3afef7d982f0b2dea0ac0c8c 1032872 libdevel optional postgresql-server-dev-13_13.11-0+deb11u1_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEhBjA3afmaHyzk51IFQ1EGN3xM6QFAmRcd+8ACgkQFQ1EGN3x M6R8lw/+NijKh8sAeTvyfDZcWR6S7PzbDAvuoS9MIIRYBj+CHpw9x8VAfT3acWwr EdQ/7t9fxxDM3AAJ/RiN/rnbpHZ5kfuu8S4IT7ilqIjStCzA59y65SQRdDRL/uiw cygnUdCBRfU6awzH1xpcYWAohPsP6DADMlb6P9POfRO9bU2ZO5RklW9i15yZR0DM bmCpbCUi7bV8oM7p9UqhYaQXucfCwwvNqqNuksKNfyxkFd4YPxIi50m21s3DhKEC zOYwdRv3GsLh/Nf2y5JlrKUD+LFwHMGO/mMJLLxFzsLcU5rm1Om7LM1nF1Ek/Mdw N0QN7uW+0Pfl0IJFStpYokYzWzh1X0GGj6z9pxmEveO5VuOuvu5wP/+hYyN/HdPe 1E3ZxffZLgnFMEAOhJ99/t9X6WOMDjTJr6nE1tz7DnHe0d1lsAJa5d5m3ybF6aKf zhfUahSnsi/S6hUdjS8SAqsb5jrvZdrRBh47hL58nmJ1CqWzPORcjkKzYK5AvlmZ pVWSEI77SjqMHqquda9HX6Spul7wgDY9nuzlAovu95VIFSuMnLnucJMZWh5D9G7p qmYQZbQV75RUvefEmXmuNc+tDzzgIW0F2FADY3UOi2gS8qX4NFDBX+zyqb2X4zTN ryQDijFGEhuhSr3oYU3srs853ioLBUz/H/sCEaPc9+9qXWh2VfU= =uThu -----END PGP SIGNATURE-----