-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 11 May 2022 15:03:33 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: amd64 Version: 13.7-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.7-0+deb11u1) bullseye-security; urgency=medium . * New upstream release. . * Confine additional operations within security restricted operation sandboxes (Sergey Shinderuk, Noah Misch) . Autovacuum, CLUSTER, CREATE INDEX, REINDEX, REFRESH MATERIALIZED VIEW, and pg_amcheck activated the security restricted operation protection mechanism too late, or even not at all in some code paths. A user having permission to create non-temporary objects within a database could define an object that would execute arbitrary SQL code with superuser permissions the next time that autovacuum processed the object, or that some superuser ran one of the affected commands against it. . The PostgreSQL Project thanks Alexander Lakhin for reporting this problem. (CVE-2022-1552) . * Fix default signature length for gist_ltree_ops indexes (Tomas Vondra, Alexander Korotkov) . The default signature length (hash size) for GiST indexes on ltree columns was accidentally changed while upgrading that operator class to support operator class parameters. If any operations had been done on such an index without first upgrading the ltree extension to version 1.2, they were done assuming that the signature length was 28 bytes rather than the intended 8. This means it is very likely that such indexes are now corrupt. For safety we recommend re-indexing all GiST indexes on ltree columns after installing this update. (Note that GiST indexes on ltree[] columns, that is arrays of ltree, are not affected.) Checksums-Sha1: b08bbbbc5e5eaad5b6c19cb3e6233bd1e6147cb3 37980 libecpg-compat3-dbgsym_13.7-0+deb11u1_amd64.deb 01119c1a4265134c91f29fe58b5d0a7e9ff2697f 24620 libecpg-compat3_13.7-0+deb11u1_amd64.deb 5008300843c7f02abd8c1c078b002e0b4f3fa166 232832 libecpg-dev-dbgsym_13.7-0+deb11u1_amd64.deb 9c70c04e43720f570d1423b93800182f8d4078ea 283380 libecpg-dev_13.7-0+deb11u1_amd64.deb 6c0333c54c0b9f33af671c31d5b142bbeb4acd06 110892 libecpg6-dbgsym_13.7-0+deb11u1_amd64.deb 4ed8ed41bc568b4d70dcee8ceba8aae26d266b0f 60408 libecpg6_13.7-0+deb11u1_amd64.deb 1b92b610732aa18888c3a4890ad3d2c7b96b02a0 88952 libpgtypes3-dbgsym_13.7-0+deb11u1_amd64.deb 83d35de39241da1de6ddd6c395f52af5545214e2 46884 libpgtypes3_13.7-0+deb11u1_amd64.deb f8dbae389051890303b5301bb8e0cd1dd6d6513b 138600 libpq-dev_13.7-0+deb11u1_amd64.deb f7c1c2177fa7b5327f5e2bee5c8c54cecc3ed8d6 253912 libpq5-dbgsym_13.7-0+deb11u1_amd64.deb ed05b26392c5fcc8cb6ad0a4f79c44913b5e49ec 180024 libpq5_13.7-0+deb11u1_amd64.deb e948a8d5694584e263bf35daa0c39f011a7a502b 14867772 postgresql-13-dbgsym_13.7-0+deb11u1_amd64.deb a943f827e32323909ff3e17aaa478a406573e732 16035 postgresql-13_13.7-0+deb11u1_amd64-buildd.buildinfo d09a7d6f6069648504b4d5d77512997822668b0b 15164116 postgresql-13_13.7-0+deb11u1_amd64.deb 5791c0430f29bb25f8629ff327b20565696a3dfe 1844844 postgresql-client-13-dbgsym_13.7-0+deb11u1_amd64.deb f3446b8992934c9e3c4966dd2e2b8449f67bdad2 1517916 postgresql-client-13_13.7-0+deb11u1_amd64.deb b2d1246640328c36d8bc5f78532f8cd33746570a 157252 postgresql-plperl-13-dbgsym_13.7-0+deb11u1_amd64.deb 8a062fef174b46186a1edf14f049de187a25b2ad 86996 postgresql-plperl-13_13.7-0+deb11u1_amd64.deb 425da6aa53cd325fee1a93fd7f702c041465762c 157280 postgresql-plpython3-13-dbgsym_13.7-0+deb11u1_amd64.deb 5712105155138c22af9855d71cc06f8f15d83768 106384 postgresql-plpython3-13_13.7-0+deb11u1_amd64.deb 47d0141cd2f74e5d6d4d6a1d9f75cf6b47e50346 74388 postgresql-pltcl-13-dbgsym_13.7-0+deb11u1_amd64.deb b96330e1020ae14aade8d683bce6ba3ac27ceab6 40984 postgresql-pltcl-13_13.7-0+deb11u1_amd64.deb 755c2a15fbfdfead3d0978f0b9fd2d6670259fac 1035548 postgresql-server-dev-13_13.7-0+deb11u1_amd64.deb Checksums-Sha256: d4d9aba7f4313a4a1f0732562dc81f9121016c744e644f1e9f454f7ea100eb19 37980 libecpg-compat3-dbgsym_13.7-0+deb11u1_amd64.deb 19a270438af7ad5a86ae559bbc253c688810f7f8a6a94559a9b2c1db02c8ebb8 24620 libecpg-compat3_13.7-0+deb11u1_amd64.deb ece739d90073aacb4eeb61ea57765287726bca12c0e3cc7d8788d488775aa2f9 232832 libecpg-dev-dbgsym_13.7-0+deb11u1_amd64.deb 8090a83f24e3a4a30fb318721dc8003d64d2bb9b14d220c2e785933aaf04f188 283380 libecpg-dev_13.7-0+deb11u1_amd64.deb e87e264a540fd6178dc28f36dd0e394555cd1b2523ba0bc358aa97fb7e751ab0 110892 libecpg6-dbgsym_13.7-0+deb11u1_amd64.deb 26dc0cc738e142c5ed38d79214d6cf60ee5f2aca05cbeb8c9b21896beeb101bf 60408 libecpg6_13.7-0+deb11u1_amd64.deb 3ed1b08f4debdc20717df07d69ed9165746d22c7c6e67b0aa4dc0a141b166450 88952 libpgtypes3-dbgsym_13.7-0+deb11u1_amd64.deb 4f1c8a1bf793954fa37605c6935bb39c6431e9f1e6849cab59733fb51c4ce52f 46884 libpgtypes3_13.7-0+deb11u1_amd64.deb 38f4ba1f0d33cd39447c8e51bfb5b547b2f7821bf391c208b77c71aab72fa6cf 138600 libpq-dev_13.7-0+deb11u1_amd64.deb d2ac9f6af01caf487570353f401543d9d2c052cd9dbcd7d0b3ab7d2599972004 253912 libpq5-dbgsym_13.7-0+deb11u1_amd64.deb 323d532c48649b7471ae8a6dcb66d0233999ff30f923f37e101560922ab26c0d 180024 libpq5_13.7-0+deb11u1_amd64.deb 7dbd67678c0fbf0556c0f2220f006bdf245379d711b2e8aabb36c350f3910a26 14867772 postgresql-13-dbgsym_13.7-0+deb11u1_amd64.deb 09df9c7b76a9baaff94707372b77f99d59413cd25966ca98e31dbfbc5a7a4475 16035 postgresql-13_13.7-0+deb11u1_amd64-buildd.buildinfo e6f0e2c31722917c6bc8c96471628153dc21749636bb9b74c67cf2f5a7ba393c 15164116 postgresql-13_13.7-0+deb11u1_amd64.deb 398a97b0f0f7265b3216c62bf1dd09dc3f93a63766bb64fd7011b16477b2f3aa 1844844 postgresql-client-13-dbgsym_13.7-0+deb11u1_amd64.deb cb07fe4c610fc044332ec9c4ff86546ff0a098816572f02d405aefdc1b822e06 1517916 postgresql-client-13_13.7-0+deb11u1_amd64.deb 651427528ae1c9ec57d40bfee1bc38fab4cd73ec859570df385bcd7d7b5dab0f 157252 postgresql-plperl-13-dbgsym_13.7-0+deb11u1_amd64.deb cf5ecbed9e0ad93a26c091b64d0bfd3a8a8f1e844046bc2967d712c240a6397e 86996 postgresql-plperl-13_13.7-0+deb11u1_amd64.deb baf1ab71f409b97d03ec0ee9a6df9f8a5ae547d7adb14b08f0d15013f01bbd65 157280 postgresql-plpython3-13-dbgsym_13.7-0+deb11u1_amd64.deb 1faf4d24b341ad4565c0c084fd93b9181defc8aebc4c2e3c17b190c8915e9f56 106384 postgresql-plpython3-13_13.7-0+deb11u1_amd64.deb 39738c081c7ed7dfac0163b2d6d25c8a2b996e2ef60f3cb656163cd302930c7e 74388 postgresql-pltcl-13-dbgsym_13.7-0+deb11u1_amd64.deb d5906ec4b7dbb8834a5027fb3cd2538df9a644e303395efc98c52b2b4f23a71c 40984 postgresql-pltcl-13_13.7-0+deb11u1_amd64.deb 4a6b4f74f8132e1d618e9a41fc6f0ae43f418c02c2929b224222c17aa632397e 1035548 postgresql-server-dev-13_13.7-0+deb11u1_amd64.deb Files: 4536b8d369b6d84831b9926f651b1020 37980 debug optional libecpg-compat3-dbgsym_13.7-0+deb11u1_amd64.deb 9f0f16c8460c9d49179923931a728c07 24620 libs optional libecpg-compat3_13.7-0+deb11u1_amd64.deb be2b2a7ec7c4dbcc3e467f656db1fc64 232832 debug optional libecpg-dev-dbgsym_13.7-0+deb11u1_amd64.deb 18472360ee4f0365fb7016cfd4a114a8 283380 libdevel optional libecpg-dev_13.7-0+deb11u1_amd64.deb 9330de60a869054efdbd152084b26834 110892 debug optional libecpg6-dbgsym_13.7-0+deb11u1_amd64.deb b5de4038d250b185e96c41cdc9c7f7a3 60408 libs optional libecpg6_13.7-0+deb11u1_amd64.deb 3aecd630d84195fc019b2b10f4efbe6c 88952 debug optional libpgtypes3-dbgsym_13.7-0+deb11u1_amd64.deb 44d52f81ac6065eb478a0d901862ee97 46884 libs optional libpgtypes3_13.7-0+deb11u1_amd64.deb bcfe3a6db2529fe9b1bd01c76d3c2d75 138600 libdevel optional libpq-dev_13.7-0+deb11u1_amd64.deb 5ebdb1737a3fd34a94ec118e4db14207 253912 debug optional libpq5-dbgsym_13.7-0+deb11u1_amd64.deb 891ab205001b7be915b6f7229f26cdbd 180024 libs optional libpq5_13.7-0+deb11u1_amd64.deb e881d4de9501e55555bab2e6fcc8e844 14867772 debug optional postgresql-13-dbgsym_13.7-0+deb11u1_amd64.deb 1ff6651b4e2f219f2d21e0a80ff5d186 16035 database optional postgresql-13_13.7-0+deb11u1_amd64-buildd.buildinfo b95802f0ffb9621596ac3c7f766df1c0 15164116 database optional postgresql-13_13.7-0+deb11u1_amd64.deb 582ad8f1d95c3931bef808827cf6d678 1844844 debug optional postgresql-client-13-dbgsym_13.7-0+deb11u1_amd64.deb 5442f3b2517fa2dc7881883e6f840b7a 1517916 database optional postgresql-client-13_13.7-0+deb11u1_amd64.deb fd280dec8e67de385c758860eb20c5d4 157252 debug optional postgresql-plperl-13-dbgsym_13.7-0+deb11u1_amd64.deb 55ec1b833096a971e29c45d398fc7598 86996 database optional postgresql-plperl-13_13.7-0+deb11u1_amd64.deb fd5bbaed4bf31abf767da570ac77105e 157280 debug optional postgresql-plpython3-13-dbgsym_13.7-0+deb11u1_amd64.deb 12f7ff424e9eb0c59e32c8728e368cea 106384 database optional postgresql-plpython3-13_13.7-0+deb11u1_amd64.deb bd9492358ff18efff8e87cfd4ae0c82f 74388 debug optional postgresql-pltcl-13-dbgsym_13.7-0+deb11u1_amd64.deb 6e1f541e811de46b8802d5838737bb57 40984 database optional postgresql-pltcl-13_13.7-0+deb11u1_amd64.deb da13350dc2287b2ae252bf3692b15cbc 1035548 libdevel optional postgresql-server-dev-13_13.7-0+deb11u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEHhnKQNkF1LuwA8CntGhFlQFFlWsFAmJ7xM4ACgkQtGhFlQFF lWsmXQ/+PebamQA4Mzd3pMWGr+lPESpNW3tEJPvpsx9xHcMNsSn3uNNeMaIe+9lN 88o7vcrCcUgOzB442XDVyQyRi+Ms2DxuTDWDGSsDdvuIo7DIAqQlSVfhuDwJ5r1l Irih4mmx/feG9RYCQvVm4WHt398LkQ4iorMiiyeznjgYn2m3bi+TsL7/dYzaipKP Jq8SgoHW5BXvYVQOUj9A3NdqZGX3LpBoGHfiIflpWBA+byMGkJGM2qn5iLQkNA+a mWqbF3LRryOQwwEtM11HIQpqwTjeuZ1hwsyHZXLsNXmpjcq+j33YOb15IvnXUzCe RGa2kKAgCLefnj5cOLcoERTvHucuNFoKX2ZjZFF8LrmOiCJ9YoLPdJMwFjbUq0Z8 SJpk1QbOyZ1Kwae0Y6XpXtOMFpGA/85C/4Pk2nTF0UdSqY8z+hDMtuXJc8CM5Gxj lf/veb0AdoiDJEOkWYEwRkyH+F/F5kVldOPfan229YwfVNNGNOc3qpWx9La0NPWZ cDL+ORVnZbaupdCw1vxTvwpad6F2DxXB3ANHWLdo4EsLctyA7wedPeuK2CbpNV92 wuPAcgjgx5lm8YYdv8su2HuTblm8GXXrrX05v5OVqyVuvcgBusToqsMtWnMmZSPv fkDrueQsTszvB8N28oFyI/Q0iOBIedqV6Mi4Omu0NOnfJDqIa+k= =909u -----END PGP SIGNATURE-----