-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 11 May 2022 15:03:33 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: i386 Version: 13.7-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.7-0+deb11u1) bullseye-security; urgency=medium . * New upstream release. . * Confine additional operations within security restricted operation sandboxes (Sergey Shinderuk, Noah Misch) . Autovacuum, CLUSTER, CREATE INDEX, REINDEX, REFRESH MATERIALIZED VIEW, and pg_amcheck activated the security restricted operation protection mechanism too late, or even not at all in some code paths. A user having permission to create non-temporary objects within a database could define an object that would execute arbitrary SQL code with superuser permissions the next time that autovacuum processed the object, or that some superuser ran one of the affected commands against it. . The PostgreSQL Project thanks Alexander Lakhin for reporting this problem. (CVE-2022-1552) . * Fix default signature length for gist_ltree_ops indexes (Tomas Vondra, Alexander Korotkov) . The default signature length (hash size) for GiST indexes on ltree columns was accidentally changed while upgrading that operator class to support operator class parameters. If any operations had been done on such an index without first upgrading the ltree extension to version 1.2, they were done assuming that the signature length was 28 bytes rather than the intended 8. This means it is very likely that such indexes are now corrupt. For safety we recommend re-indexing all GiST indexes on ltree columns after installing this update. (Note that GiST indexes on ltree[] columns, that is arrays of ltree, are not affected.) Checksums-Sha1: 241835e04c062cb4c83c9860e4bd525fe9d568eb 33372 libecpg-compat3-dbgsym_13.7-0+deb11u1_i386.deb 1a98a8019d74319e6974c9eccdcd090c6af8b419 25492 libecpg-compat3_13.7-0+deb11u1_i386.deb 2e608d5e0ae985847161adc096250ed607cff409 216600 libecpg-dev-dbgsym_13.7-0+deb11u1_i386.deb e77f7042eba3087eab9130a65451d467a806d219 295804 libecpg-dev_13.7-0+deb11u1_i386.deb 6dc9d4c7a534180db03304a4672c1e1e81719986 96956 libecpg6-dbgsym_13.7-0+deb11u1_i386.deb 2b65cfb4cfee1a9bec453b15ac317eccb7edf8dc 64268 libecpg6_13.7-0+deb11u1_i386.deb 59612687420473810888830d802514b756941301 80248 libpgtypes3-dbgsym_13.7-0+deb11u1_i386.deb 609bffc68bca8834af59f531974f286cec227a26 49368 libpgtypes3_13.7-0+deb11u1_i386.deb 219b3f343ad9146db4cc664e388f3d8d404c72af 148272 libpq-dev_13.7-0+deb11u1_i386.deb 2509d136f8b5a2c6f524ee9fc9c05534f73b9eb3 218396 libpq5-dbgsym_13.7-0+deb11u1_i386.deb bae8f8315940e3391ade47e852d22f07c9db499f 188384 libpq5_13.7-0+deb11u1_i386.deb 41c824b4d3a1b7029d6687ce0c5aff7043ccbce0 13438464 postgresql-13-dbgsym_13.7-0+deb11u1_i386.deb 1aa616003e0f9b29300631aaab38c8716418f2c7 15956 postgresql-13_13.7-0+deb11u1_i386-buildd.buildinfo 1cf2a7c0d0a02548d561b64191df78961c6c99a6 15362808 postgresql-13_13.7-0+deb11u1_i386.deb 881e9ea9764291c346099ebf41ec793ed9fa4521 1546592 postgresql-client-13-dbgsym_13.7-0+deb11u1_i386.deb ea3a21acf01c48521f5906331b0d3f270a961eca 1541692 postgresql-client-13_13.7-0+deb11u1_i386.deb 1c7409c1fbb51db84b958245b88cb89b158fcac8 142972 postgresql-plperl-13-dbgsym_13.7-0+deb11u1_i386.deb 10d922a56d5cf80480ecf598f0a9ffc84ee05a5c 90424 postgresql-plperl-13_13.7-0+deb11u1_i386.deb c3b8aa7361b47517b6f4fd7d4376839c17ccf9fb 143320 postgresql-plpython3-13-dbgsym_13.7-0+deb11u1_i386.deb 89cb79f9b67dd4de90e5c06f048c9b9c61af1d90 109576 postgresql-plpython3-13_13.7-0+deb11u1_i386.deb 81789a601c45f42ccad1c688ba1df8b6cad69b05 67888 postgresql-pltcl-13-dbgsym_13.7-0+deb11u1_i386.deb ff99f5a65f509cf6075c98a97cce995a041375e1 42136 postgresql-pltcl-13_13.7-0+deb11u1_i386.deb 56d7640601b5fe819254899568906f06f2617af5 1049240 postgresql-server-dev-13_13.7-0+deb11u1_i386.deb Checksums-Sha256: 76f20b90db375d8b81328847412915c7554e0f91ebdd15ee5f1aa2c7f5b4d99a 33372 libecpg-compat3-dbgsym_13.7-0+deb11u1_i386.deb 1c609e5e458ae556c709ba245012552d9514e30d8f92655530f57a947da43c37 25492 libecpg-compat3_13.7-0+deb11u1_i386.deb 42302e4e4a7850960af8232e2a0364c55336cf8dd9aad26eb744222d2a521422 216600 libecpg-dev-dbgsym_13.7-0+deb11u1_i386.deb 17cf58a07d895b3ee01143b1384f3f09f32741ebc607ee12fab9941a02542322 295804 libecpg-dev_13.7-0+deb11u1_i386.deb d8cdf781edc807116d0c308bd06cc94ca3758db301250c9bc8b41e85cccb8e93 96956 libecpg6-dbgsym_13.7-0+deb11u1_i386.deb 4eece21e7819273d4da2e40e8c26599752e98bd6c1d7e0d083dd10e290bd0e80 64268 libecpg6_13.7-0+deb11u1_i386.deb 36ec01fd7868ceca092ecdbc24e96ec72d2e2cb64fee768cb9cf71b9b3a3e5e1 80248 libpgtypes3-dbgsym_13.7-0+deb11u1_i386.deb 9515631c11a32c8de3f0be669bfbe83a9aaccc01f649fd76eafd492f328c2029 49368 libpgtypes3_13.7-0+deb11u1_i386.deb af34ff8db42b5281642351354e13aaf906e1ff20b87dbddcd432569ba73b730e 148272 libpq-dev_13.7-0+deb11u1_i386.deb 17d42a25488e2882bb24df4bb0964cb6c10f39e40cd9b7bdea374f1457b1e983 218396 libpq5-dbgsym_13.7-0+deb11u1_i386.deb fa8c6a360bb374a15c01154955e9c452e0469b5331db9b61249210b866361cf7 188384 libpq5_13.7-0+deb11u1_i386.deb 4c57049d9f76df999aadaa262640512389612b8c6afb1c2deb93de45f7c809e7 13438464 postgresql-13-dbgsym_13.7-0+deb11u1_i386.deb 72f5137cb3c751c89246dcd11481bfea1b46a79615d4c09e365ce8efd8d5675e 15956 postgresql-13_13.7-0+deb11u1_i386-buildd.buildinfo 3e7036b9ea8bbdb2c3887974c7a58cec03a9328ae6eb0627edfb34c18bbf08fc 15362808 postgresql-13_13.7-0+deb11u1_i386.deb f12107e2d51e534a40924977834820d7a3a0a4b3682d6446a134fd18bb64b532 1546592 postgresql-client-13-dbgsym_13.7-0+deb11u1_i386.deb b8804609ccebfea5c3676c059a996783afa60b3738e8fe491a9b8ee3471dfb72 1541692 postgresql-client-13_13.7-0+deb11u1_i386.deb 2f9bce64390a0bea7fd9769f7a67d8b2d2879aad995242ed1aecf08b43fba3cd 142972 postgresql-plperl-13-dbgsym_13.7-0+deb11u1_i386.deb 5001c2bfc7f8bd5d91f006eda4c840ffdff97609121da30aa5bd1a1854761648 90424 postgresql-plperl-13_13.7-0+deb11u1_i386.deb f56fe3e0d8b8b17fbe92a463f7568c814cdcbee123b91a7d977f1684bbc3b032 143320 postgresql-plpython3-13-dbgsym_13.7-0+deb11u1_i386.deb 18c96562b8ff39dd672b216cd615894dbab4f747566b6bd340b6554e44a3ca55 109576 postgresql-plpython3-13_13.7-0+deb11u1_i386.deb 82375c3c414c6964eb390797a6655000bd39c5d73f1f134d815ba4bdb6339691 67888 postgresql-pltcl-13-dbgsym_13.7-0+deb11u1_i386.deb 8da6922ea90a91f152c7456486a19dcc3b2e7bbc517c638fcf9ed91308fde5a3 42136 postgresql-pltcl-13_13.7-0+deb11u1_i386.deb c90096372838702eed50fb718b8b24ee7a2f0be579f84d19b92ab6cf48bfbc04 1049240 postgresql-server-dev-13_13.7-0+deb11u1_i386.deb Files: 190ae032197e8154fedb013c1e0a0512 33372 debug optional libecpg-compat3-dbgsym_13.7-0+deb11u1_i386.deb e6f14cb2a42d8b52d71fd327c9251368 25492 libs optional libecpg-compat3_13.7-0+deb11u1_i386.deb 25d7b730f42496d0e3a7c555f12998f8 216600 debug optional libecpg-dev-dbgsym_13.7-0+deb11u1_i386.deb 4ef9a7ba47fdb6d8f074f25837da8f65 295804 libdevel optional libecpg-dev_13.7-0+deb11u1_i386.deb 5e99b8e8bab189bc65667c6d0bd6fb32 96956 debug optional libecpg6-dbgsym_13.7-0+deb11u1_i386.deb a62852a2a66ebea4d54c5bdd91a4a241 64268 libs optional libecpg6_13.7-0+deb11u1_i386.deb 57e1b447b5178d4a21b3ed934615eb60 80248 debug optional libpgtypes3-dbgsym_13.7-0+deb11u1_i386.deb bc3299906b1649c13b949fd37f3137ad 49368 libs optional libpgtypes3_13.7-0+deb11u1_i386.deb 8c9a834d905e5a93abaafb0f2e8852be 148272 libdevel optional libpq-dev_13.7-0+deb11u1_i386.deb 26ff417270a19103af9df655633a8b3c 218396 debug optional libpq5-dbgsym_13.7-0+deb11u1_i386.deb ef668a2d1dfa8983d8a72875f9efa617 188384 libs optional libpq5_13.7-0+deb11u1_i386.deb a661a6d1a9fd8e9fe7db6487dbdda4f6 13438464 debug optional postgresql-13-dbgsym_13.7-0+deb11u1_i386.deb 0eaf88618a63eda20efc8e3c0921afe2 15956 database optional postgresql-13_13.7-0+deb11u1_i386-buildd.buildinfo 45478137223d8f4d44f63ff850b2e29f 15362808 database optional postgresql-13_13.7-0+deb11u1_i386.deb 02d71ee3a4be3c92fb8ddc7258d89ed2 1546592 debug optional postgresql-client-13-dbgsym_13.7-0+deb11u1_i386.deb 824b91d4555120b310a5b0ce365de7b5 1541692 database optional postgresql-client-13_13.7-0+deb11u1_i386.deb d9ca2d8d17995bb2cb9752b02c478085 142972 debug optional postgresql-plperl-13-dbgsym_13.7-0+deb11u1_i386.deb aba7621bda6baaf3adfeebb63a5d8519 90424 database optional postgresql-plperl-13_13.7-0+deb11u1_i386.deb 7b66d1e8daef569f0811f0efe988d4bf 143320 debug optional postgresql-plpython3-13-dbgsym_13.7-0+deb11u1_i386.deb 1b2f04fb299b5453dd73fc095acdd571 109576 database optional postgresql-plpython3-13_13.7-0+deb11u1_i386.deb 14972c6f6a1fcdfcdf457945185f7a7d 67888 debug optional postgresql-pltcl-13-dbgsym_13.7-0+deb11u1_i386.deb 3ee3a9d0223ad31988bfed406dd1fb99 42136 database optional postgresql-pltcl-13_13.7-0+deb11u1_i386.deb 088346c9d3ceb9f84cdbe6df94265f9a 1049240 libdevel optional postgresql-server-dev-13_13.7-0+deb11u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEZ+kjGN6s2Ioxmya1SqddLxw5rsoFAmJ7xZ8ACgkQSqddLxw5 rsqg4g/+JSYp3RFtVw/7TQAYq4Ji5LncB3XVw57dk6DtN1hx5mTn2n0HIxa6Yt08 AShKN2PC6Qqwoe5n77m8rgiBq6DfGQTCnxWa9wymvso9NZ73JElsSzxwhNKSSPZP aSxzIpii7cLC2x3OySybtiCkef4+u6OCdM6AtJTZXcK1hCKT5T8/sPshF3OsMtwh a/YSAI+lwkmQ9eYMJ0YHgyZMs5ibWHnZ4BcpJZeuOWVuIlsbVGsNLHBzRWrH+ue5 k/ZuocVy5ZK4hejMlRh064ZydHXcl6rz+DJBI8X3XqleSW+CrktFjPrteTtlJj8A j9CTj83yIAzyfypXn1mmKFYCyQmH4NeTg/uV8LOpyqJ+uT/UkKlaJxDMPVxcu/wH ufuiFMfzwF3yBrK8FZFfF4sQyYCph7oMeK2vGRYEDN8JrxjEG33OsCV09JqgmLp6 705pDuTGHKWwfb1tKjWC/tg0sVB3uMVAbCq7FtEDGVenuD8XMs6JI+DsS8/yyVIn WC3W8DwrrkN3xHfvpathu/q/Ol5vb20hTc0qAh6rnso9PpKGqlQT6hmrdK/2hBHo xqW55Mi3ZCEKA+41FGqPcjVWvXMUYISDr10Go6yqzjR3/Can+Fsq9W3C4po6wSwQ IcjmBPedBIOUDRU10i8oReElkepdLnn9fd+9dPj3HzE2vt/u/Jk= =jiUY -----END PGP SIGNATURE-----