-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 11 May 2022 15:03:33 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: arm64 Version: 13.7-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: arm Build Daemon (arm-ubc-03) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.7-0+deb11u1) bullseye-security; urgency=medium . * New upstream release. . * Confine additional operations within security restricted operation sandboxes (Sergey Shinderuk, Noah Misch) . Autovacuum, CLUSTER, CREATE INDEX, REINDEX, REFRESH MATERIALIZED VIEW, and pg_amcheck activated the security restricted operation protection mechanism too late, or even not at all in some code paths. A user having permission to create non-temporary objects within a database could define an object that would execute arbitrary SQL code with superuser permissions the next time that autovacuum processed the object, or that some superuser ran one of the affected commands against it. . The PostgreSQL Project thanks Alexander Lakhin for reporting this problem. (CVE-2022-1552) . * Fix default signature length for gist_ltree_ops indexes (Tomas Vondra, Alexander Korotkov) . The default signature length (hash size) for GiST indexes on ltree columns was accidentally changed while upgrading that operator class to support operator class parameters. If any operations had been done on such an index without first upgrading the ltree extension to version 1.2, they were done assuming that the signature length was 28 bytes rather than the intended 8. This means it is very likely that such indexes are now corrupt. For safety we recommend re-indexing all GiST indexes on ltree columns after installing this update. (Note that GiST indexes on ltree[] columns, that is arrays of ltree, are not affected.) Checksums-Sha1: c24994bc91e0b0aa2a2ffd1d44c80937d94275ff 39220 libecpg-compat3-dbgsym_13.7-0+deb11u1_arm64.deb be2cc291a30bef690e14af02e2829cb4bbd7007e 23864 libecpg-compat3_13.7-0+deb11u1_arm64.deb 6960e0b90ab98a2f3d9e20e1fa5d792f6086922b 227476 libecpg-dev-dbgsym_13.7-0+deb11u1_arm64.deb 6b4d8c0dd6b9bfb004f34a3fcf1a003b28e78c68 268836 libecpg-dev_13.7-0+deb11u1_arm64.deb 95dccbcc19947ac5b21cfa2eb4be56f04401842b 113060 libecpg6-dbgsym_13.7-0+deb11u1_arm64.deb 28436f35ba109b1529fe0ce0e5e9598a4406361c 57672 libecpg6_13.7-0+deb11u1_arm64.deb 3fc8782b98ee03973abc73f8bf240cd7bdc15996 88996 libpgtypes3-dbgsym_13.7-0+deb11u1_arm64.deb 46b650bb64260fe921ef4bc74f2f13e2e910567e 44288 libpgtypes3_13.7-0+deb11u1_arm64.deb ebd37be27916f51ec7d8f5cadb91d11e6f23b226 136032 libpq-dev_13.7-0+deb11u1_arm64.deb 23a35fd89754621085aa820bea5feed1bf4dacbb 255868 libpq5-dbgsym_13.7-0+deb11u1_arm64.deb 87860e63511d033e279cc51708a74144eae24582 173584 libpq5_13.7-0+deb11u1_arm64.deb 831ac6a66d8c35f2161f0750138ceb87d192dce8 14516316 postgresql-13-dbgsym_13.7-0+deb11u1_arm64.deb 09b4dae5f8c8727abd90a0fd4cc7643fe6b8b386 15895 postgresql-13_13.7-0+deb11u1_arm64-buildd.buildinfo 4c4401ed8483353f2b3be14734291929aec33a78 14718496 postgresql-13_13.7-0+deb11u1_arm64.deb ed6c0199e470ff1ac0673cbd772e71ce94205d89 1878652 postgresql-client-13-dbgsym_13.7-0+deb11u1_arm64.deb 7652b6d8b8eadc1da25490975060af90bfe26eb5 1479988 postgresql-client-13_13.7-0+deb11u1_arm64.deb a75b87853a108a179986bdce59506ffe9e88aa30 154992 postgresql-plperl-13-dbgsym_13.7-0+deb11u1_arm64.deb 57b485fb7cfa9d7c12f07400387896d8e5f1d12d 83812 postgresql-plperl-13_13.7-0+deb11u1_arm64.deb 7f4a94bb884cf006540379d714192b12fce9fe5d 156520 postgresql-plpython3-13-dbgsym_13.7-0+deb11u1_arm64.deb cfc88a90e728ff057a9f05e56db917e95a7cd8a2 103292 postgresql-plpython3-13_13.7-0+deb11u1_arm64.deb 137171436cb3b3e4a62b8efd848837d52f1e80aa 73544 postgresql-pltcl-13-dbgsym_13.7-0+deb11u1_arm64.deb 6bd0ca883e293ba4ffe9d18085964bb5ff0dc105 39648 postgresql-pltcl-13_13.7-0+deb11u1_arm64.deb 47ad546581fbd2f47d8ec06e456a546cf1d67e5a 1031904 postgresql-server-dev-13_13.7-0+deb11u1_arm64.deb Checksums-Sha256: 4afb976d0e83a60767314dc943de1ff3e5c70aa7593410268f392cb489e84217 39220 libecpg-compat3-dbgsym_13.7-0+deb11u1_arm64.deb ad4d77e506b3a740df5e8c90d6c9723f5896a4c753942fbe730e223df7b00ff6 23864 libecpg-compat3_13.7-0+deb11u1_arm64.deb 3dcf7b4ddf2ffea9721a3ae10d051835a1237ad9c6b347765a244f25bedbd705 227476 libecpg-dev-dbgsym_13.7-0+deb11u1_arm64.deb b2d8e15f77e0af2194ed0e9075cda1ffc097563dbd1363fdc5d288661cd32611 268836 libecpg-dev_13.7-0+deb11u1_arm64.deb c375369400a67a1d94f11b255f85961dc1334ea82dc230c27c356689818efdd0 113060 libecpg6-dbgsym_13.7-0+deb11u1_arm64.deb 1e23d4b7fc6db4e329f8bc0e7f0185fa72c67b9c88cb3308e46f3007bfaf6602 57672 libecpg6_13.7-0+deb11u1_arm64.deb 9dddf89c813f94c5f919e90bcc4cd7e2464c04c85b22c8154c36e2174e30ea85 88996 libpgtypes3-dbgsym_13.7-0+deb11u1_arm64.deb 58f37691483f11acfe24ad0aef1178d5bbf6492d2d65472af5a01296770dde99 44288 libpgtypes3_13.7-0+deb11u1_arm64.deb 89267f9d72126c574fe202a3c3846669c5f1136330c13c23d513a61857834615 136032 libpq-dev_13.7-0+deb11u1_arm64.deb e71929b5f00f2c042fe2cbfd7c4d6bf4ea3dbbbb9d8040b5d87e8bc62e2f4990 255868 libpq5-dbgsym_13.7-0+deb11u1_arm64.deb 64808df3e8a9020d242b15bfae645c85f1bc6dd8afdcaad27fbff4c7d9928316 173584 libpq5_13.7-0+deb11u1_arm64.deb e9b5172f2185e7f66ca84874561ef5f5f049152cbb4135a18ec50e64f357fca9 14516316 postgresql-13-dbgsym_13.7-0+deb11u1_arm64.deb e603d95c5935c6925775939270dddee3ced5986090ef9118f41f5941dd0ea2de 15895 postgresql-13_13.7-0+deb11u1_arm64-buildd.buildinfo 6d14bb688bff80b6b40d7b1abddeaa721924786934e3ed6c43b50fc899006376 14718496 postgresql-13_13.7-0+deb11u1_arm64.deb e102380b78412534497d447532620eb3515d0fa493a53ae88e19a85b6b930c3a 1878652 postgresql-client-13-dbgsym_13.7-0+deb11u1_arm64.deb 334aa343114487756cc4527d078f9d3155d64bd50ef11ffd88b393d345b664ad 1479988 postgresql-client-13_13.7-0+deb11u1_arm64.deb b59d2fceb50dd0bf73414cd7fe190d152b100f1a5f2b11d6f0d44695a352c4f3 154992 postgresql-plperl-13-dbgsym_13.7-0+deb11u1_arm64.deb f32b07ff50ba1cbc508d898bb7cdb82fca72c2efef7caf43262e60c13eecd42a 83812 postgresql-plperl-13_13.7-0+deb11u1_arm64.deb 7e2feef8ce7cfd88aed52e81d71b0d5a9f0b8514c2006da8e9e078fbf9c4e82d 156520 postgresql-plpython3-13-dbgsym_13.7-0+deb11u1_arm64.deb 939f7132c40a3b7144c470e5500f73f13c46c99b55f3092b70055d6b7bc397b6 103292 postgresql-plpython3-13_13.7-0+deb11u1_arm64.deb 20277c9960c89925e777df98ee941fdb145018ca3c00ec00f03176c621fa0605 73544 postgresql-pltcl-13-dbgsym_13.7-0+deb11u1_arm64.deb fe793603c30a0109a0b0cd3654ac9dc8ba486fc58ea80fdf741c693881b09604 39648 postgresql-pltcl-13_13.7-0+deb11u1_arm64.deb 7108e73a0e2148f026ec3d7f79dacc9613d9b48cf84eac100cab906757dc8622 1031904 postgresql-server-dev-13_13.7-0+deb11u1_arm64.deb Files: 01e2ec8b92ad4126e8d28a83cebca463 39220 debug optional libecpg-compat3-dbgsym_13.7-0+deb11u1_arm64.deb b8332de336cc23922488357770afd1c3 23864 libs optional libecpg-compat3_13.7-0+deb11u1_arm64.deb 7492564a7927ebb328a13093223da213 227476 debug optional libecpg-dev-dbgsym_13.7-0+deb11u1_arm64.deb f40c29bf063d2d0d19f65998c6c09d0f 268836 libdevel optional libecpg-dev_13.7-0+deb11u1_arm64.deb 7b0d02fdee1b6491ba4d9e58285ef5ee 113060 debug optional libecpg6-dbgsym_13.7-0+deb11u1_arm64.deb 3f0d6840b80692fd056a587302cc1ee4 57672 libs optional libecpg6_13.7-0+deb11u1_arm64.deb 9699f1cfbbeea8dfbf7b20c3ee4da3e4 88996 debug optional libpgtypes3-dbgsym_13.7-0+deb11u1_arm64.deb 55ed242746d7dfa33d4af4586230f744 44288 libs optional libpgtypes3_13.7-0+deb11u1_arm64.deb 69a49ae7c16931a739af614e7603c4a2 136032 libdevel optional libpq-dev_13.7-0+deb11u1_arm64.deb 6828c949203a1fc1c1a9f865888ecd5d 255868 debug optional libpq5-dbgsym_13.7-0+deb11u1_arm64.deb 3904111388cf8414773f2c2a57945d9a 173584 libs optional libpq5_13.7-0+deb11u1_arm64.deb 609bf0102aaf9090f05851ad321cb7b4 14516316 debug optional postgresql-13-dbgsym_13.7-0+deb11u1_arm64.deb 9915403d065e91e744dd5f9ca98c74b6 15895 database optional postgresql-13_13.7-0+deb11u1_arm64-buildd.buildinfo 68f9731c03fd34d3d6e58e4a765fd1aa 14718496 database optional postgresql-13_13.7-0+deb11u1_arm64.deb d690678cc42382a5d823c739cabdc4f3 1878652 debug optional postgresql-client-13-dbgsym_13.7-0+deb11u1_arm64.deb 4d0ab49ddf492a63b265321439be0c45 1479988 database optional postgresql-client-13_13.7-0+deb11u1_arm64.deb d347871ddef4ac5b84c072dc660b6d43 154992 debug optional postgresql-plperl-13-dbgsym_13.7-0+deb11u1_arm64.deb 62a3f3bf5106bb53e54dcad6a357a8e0 83812 database optional postgresql-plperl-13_13.7-0+deb11u1_arm64.deb d7477ce88b584d334396357db71b0157 156520 debug optional postgresql-plpython3-13-dbgsym_13.7-0+deb11u1_arm64.deb f0cc6b53580078ee42dfd8dbb655925c 103292 database optional postgresql-plpython3-13_13.7-0+deb11u1_arm64.deb 4c5ea22b6ca4056aa136d6bfbddd9f89 73544 debug optional postgresql-pltcl-13-dbgsym_13.7-0+deb11u1_arm64.deb 738f6fd76e7b7e52376e4c1e5da2d4c0 39648 database optional postgresql-pltcl-13_13.7-0+deb11u1_arm64.deb db06b5ad0f82c8a4c98e12102da53dff 1031904 libdevel optional postgresql-server-dev-13_13.7-0+deb11u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5k6f7vRIX6Csgn8TDG7yygv882sFAmJ70PUACgkQDG7yygv8 82u53RAAsyE0jeFFHwdCyJUU0w4/4Nlcfp2WqpOGJygrjiZjVjRLRY+2/Ynv0RFR dmcB1zRKhr3ZFVzDnyIrZcvtICuf+xIGqHNOCcdFY8p/64aaAOCNX18WGqBx1MWb btUc8g5bT9SKVvEUjWBc9wF8+Wq19lQTYjqujrksA8YyBpCSYmqudF2OoYbPts3V gpHQmJypmXSPZsXLO8H/YYCKw3Ah5Rif660BJkYjvaoUyCN0bKVA9/ZMa350AAnJ FZMFvy2Cs55F2IEs26Bbe1zaMv4MK8PlA/h1Yaum2Zs4w7w6iFxU4CblTax4Onvh 6D2Rd8w9OqSbcwUSJslOf7ChwKjnXTt0/f+roryKoBAdR4++LzUUJQvjwrY64KSU jK7PwDdTa/3kQVSXQ6uyYf93jE29ZkIUWIgEbyasOUtgRQaGBt8xGq3VG0Js+AC6 PhIIL8nUjy/vq+dRgK77ktU949sRRXZhBusvnWUaWWimZoH/ErskTSnw+STT7HqU EZ7Xk3dfQXai7tbx5oRH4t8awe6VZ8qtfFRBlNqlJ8D5lCuNlmCmsANpVv516FuO 0I4q9MXApgcb+Z55y24StSLjY/mqVDeRX/euGfV95oO6OkKl5RzD/xl1Z7PEqB9l JWyiPNVMfQxeGbB4ov7ymSBdFVvkMKjNraiKXzhu1gbHGzUm+aA= =teuC -----END PGP SIGNATURE-----