-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 07 May 2024 11:24:26 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: mipsel Version: 15.7-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.7-0+deb12u1) bookworm; urgency=medium . * New upstream version. . + Restrict visibility of pg_stats_ext and pg_stats_ext_exprs entries to the table owner (Nathan Bossart) . These views failed to hide statistics for expressions that involve columns the accessing user does not have permission to read. View columns such as most_common_vals might expose security-relevant data. The potential interactions here are not fully clear, so in the interest of erring on the side of safety, make rows in these views visible only to the owner of the associated table. . The PostgreSQL Project thanks Lukas Fittl for reporting this problem. (CVE-2024-4317) . By itself, this fix will only fix the behavior in newly initdb'd database clusters. If you wish to apply this change in an existing cluster, you will need to do the following: . In each database of the cluster, run the fix-CVE-2024-4317.sql script as superuser. In psql this would look like \i /usr/share/postgresql/15/fix-CVE-2024-4317.sql Any error probably indicates that you've used the wrong script version. It will not hurt to run the script more than once. . Do not forget to include the template0 and template1 databases, or the vulnerability will still exist in databases you create later. To fix template0, you'll need to temporarily make it accept connections. Do that with ALTER DATABASE template0 WITH ALLOW_CONNECTIONS true; and then after fixing template0, undo it with ALTER DATABASE template0 WITH ALLOW_CONNECTIONS false; Checksums-Sha1: 628920d7a2ffc337268ed089e08cd86bdb924d3f 39460 libecpg-compat3-dbgsym_15.7-0+deb12u1_mipsel.deb 1ac748a8b9e7681c57b0f41e60b611db3ec9473e 21036 libecpg-compat3_15.7-0+deb12u1_mipsel.deb c41c87e9b3a418644e29e9469519c8d315f75d9e 260860 libecpg-dev-dbgsym_15.7-0+deb12u1_mipsel.deb 4c21613eade7c46583a99a639b0d6e059df04b9c 281592 libecpg-dev_15.7-0+deb12u1_mipsel.deb 166de1a6298984b617610d88d9911d7b7e8234b9 114968 libecpg6-dbgsym_15.7-0+deb12u1_mipsel.deb 2c3cfdee7ac52ec17c824566ea6ef88964c659a3 57500 libecpg6_15.7-0+deb12u1_mipsel.deb c48e185ef2e16591c9107fc50ccf2a09124e2720 91628 libpgtypes3-dbgsym_15.7-0+deb12u1_mipsel.deb 123506fc14165e689a966c4815aec9033304d31d 42800 libpgtypes3_15.7-0+deb12u1_mipsel.deb 65401bc97ab28a7ab2ad2453c3768973046b7230 148372 libpq-dev_15.7-0+deb12u1_mipsel.deb 85b466913882eb2dec271fc9322260162c38e2bd 282968 libpq5-dbgsym_15.7-0+deb12u1_mipsel.deb ac13e0771fe93e0c9ba853e32eb981bb4b94982e 175404 libpq5_15.7-0+deb12u1_mipsel.deb d13b959e2e7fe2db73e1ed923772f9d0e2bafd0a 16608924 postgresql-15-dbgsym_15.7-0+deb12u1_mipsel.deb b4cb8bcb41a9a29aa8135c6130a51c63960e9c1f 16813 postgresql-15_15.7-0+deb12u1_mipsel-buildd.buildinfo 3179bddde9f8b26191c98e39da4e5d38ebb53221 16270920 postgresql-15_15.7-0+deb12u1_mipsel.deb 566462c48390863b40b7f490ad89de12b64d0f38 2332136 postgresql-client-15-dbgsym_15.7-0+deb12u1_mipsel.deb 41365dd9fd3b95701c9dea1b9b3d4f28de058eef 1643156 postgresql-client-15_15.7-0+deb12u1_mipsel.deb 12a358a78cab97540487e61cc70c3c5262ee63a0 184560 postgresql-plperl-15-dbgsym_15.7-0+deb12u1_mipsel.deb 44402d73d68a62889d50e25b532e40846bf07c48 84216 postgresql-plperl-15_15.7-0+deb12u1_mipsel.deb e0be7fdf84fd2a0a23945a53867442f7fa001c6d 174916 postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_mipsel.deb 9c1fed8ac736e170340a6e43b34336c95d7c2344 102824 postgresql-plpython3-15_15.7-0+deb12u1_mipsel.deb f36c41f631aa7176055b886cf4818f74bd1c9ad1 79984 postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_mipsel.deb 719c465555235a336f7805dfbbce056f6b9cb617 38428 postgresql-pltcl-15_15.7-0+deb12u1_mipsel.deb 6df6d416691d97d2d54d285d4ec7f23457fa6fc1 1148876 postgresql-server-dev-15_15.7-0+deb12u1_mipsel.deb Checksums-Sha256: 2c80465ed9c27007efa3bf85e2a06ad0c730d1d14eb4eb3423949a47f28437b3 39460 libecpg-compat3-dbgsym_15.7-0+deb12u1_mipsel.deb 72e27dd7a19d958730a6298ac1ea696e6d09db01c5a7343309a736c96dcc2d00 21036 libecpg-compat3_15.7-0+deb12u1_mipsel.deb a0d4943f346aa1af5acd66f7bba815d3f01da7f6b4728211f36a9fad309d5ff3 260860 libecpg-dev-dbgsym_15.7-0+deb12u1_mipsel.deb 18f8ecb2b7104042874d9d1ee484d6e29358f545ab4686929afe51462cb8392d 281592 libecpg-dev_15.7-0+deb12u1_mipsel.deb 32d5ad2e5eaf52d7f300ee3962bc164b72cd909eaf9534c542840bccd9f7428b 114968 libecpg6-dbgsym_15.7-0+deb12u1_mipsel.deb 7807106ebbf027f207f79ee8e5279205b5bfe2f5cefcc4dba83dd6a09c8676b3 57500 libecpg6_15.7-0+deb12u1_mipsel.deb ec55acb786fa04f2a509c01828c5e9074f6f235968f09ef62ce3545cef67351a 91628 libpgtypes3-dbgsym_15.7-0+deb12u1_mipsel.deb 810866e1a7f48fc0366a3d9cb6bbb5c0df85c4b2c4427b611ab4654fdb0ac7c9 42800 libpgtypes3_15.7-0+deb12u1_mipsel.deb 51e6eb4f8dcc7e74a21d0f4f649a21960dde184107f23fe1045cfeeb91d30d71 148372 libpq-dev_15.7-0+deb12u1_mipsel.deb 91037917f21411916b83bc070eb11f87ed683cf0f731fceda55e92ce492c94d4 282968 libpq5-dbgsym_15.7-0+deb12u1_mipsel.deb 1be8f1edf75973e7d4f7d525afec1141d96020ee609fa7ad6a9c8d2afb2856b7 175404 libpq5_15.7-0+deb12u1_mipsel.deb 7edc4c16912bf07c29d4781cdb1e1c92d9603162bfc07d611799d9a22e814811 16608924 postgresql-15-dbgsym_15.7-0+deb12u1_mipsel.deb 7f04d558aed8d4856e80543c9807675d486f967b8d81acb387fe7203cb18aad4 16813 postgresql-15_15.7-0+deb12u1_mipsel-buildd.buildinfo 89cd3b849e9bd498391c98dc5ff0b4fd96b4e8d04621e3a7df65137a0c79554d 16270920 postgresql-15_15.7-0+deb12u1_mipsel.deb 064ca0e447c5d62716f014e8806875337ce58daf054c5770a057bc7ceaac432f 2332136 postgresql-client-15-dbgsym_15.7-0+deb12u1_mipsel.deb 78ac72bad001b2b24b3aabfa423902abaf4f1d0b3f61edf67351dc32c57c7836 1643156 postgresql-client-15_15.7-0+deb12u1_mipsel.deb 4dcfd05e928833463d1c2280c5a191eae49ba0b435a1499600604b98ec8bd061 184560 postgresql-plperl-15-dbgsym_15.7-0+deb12u1_mipsel.deb cf4710565402422c9753741979b61aab6b4dc0ad3c7878c907f57bbeaada515f 84216 postgresql-plperl-15_15.7-0+deb12u1_mipsel.deb e23c025bdaf2e20ed37ed792b3ea86464ac6cfd702d5c902aabc9d4a487435da 174916 postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_mipsel.deb 4b9e15605562eda76363abd0e8eeb5b6cb8386e0531a77a2894ae0fcb9978be5 102824 postgresql-plpython3-15_15.7-0+deb12u1_mipsel.deb 07d0dcd95086a88dfd708d08144369e40091a1ac0fd107cb40b1619128a3289f 79984 postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_mipsel.deb 82e518dc59b198fffdc5a5f2911f5b09f25ba43c955698cf8783fc038ddda042 38428 postgresql-pltcl-15_15.7-0+deb12u1_mipsel.deb 544c372e764c00cc0d71a4b452517f2d228093aed8ed57040025445ec10a187a 1148876 postgresql-server-dev-15_15.7-0+deb12u1_mipsel.deb Files: 9a68e85b84eaa8c4dc5ce5dca83321af 39460 debug optional libecpg-compat3-dbgsym_15.7-0+deb12u1_mipsel.deb a96f961c4ef7271b462e1cf96af082ae 21036 libs optional libecpg-compat3_15.7-0+deb12u1_mipsel.deb d33d3efb382a832ed217f4a9fd8bb720 260860 debug optional libecpg-dev-dbgsym_15.7-0+deb12u1_mipsel.deb 3c19c86d98b400d7b5db3071343ef250 281592 libdevel optional libecpg-dev_15.7-0+deb12u1_mipsel.deb f84580987ef652147551bde0a540cc88 114968 debug optional libecpg6-dbgsym_15.7-0+deb12u1_mipsel.deb e3cd1804092456e9c98bb1891334e992 57500 libs optional libecpg6_15.7-0+deb12u1_mipsel.deb b67860ddf3cb34a00b05972cda1bad50 91628 debug optional libpgtypes3-dbgsym_15.7-0+deb12u1_mipsel.deb af3601549466ac5cef8477397e60254c 42800 libs optional libpgtypes3_15.7-0+deb12u1_mipsel.deb 703b750a9c178edcc78b3c29504235bf 148372 libdevel optional libpq-dev_15.7-0+deb12u1_mipsel.deb 05233ddc546f115628a189d99cd216ae 282968 debug optional libpq5-dbgsym_15.7-0+deb12u1_mipsel.deb b09be69bf0ec2ce87fdc54b79d6a2e54 175404 libs optional libpq5_15.7-0+deb12u1_mipsel.deb 77afff1254faf10dcc363730aca77a1b 16608924 debug optional postgresql-15-dbgsym_15.7-0+deb12u1_mipsel.deb c427de763536f524bb6c0284fd908d94 16813 database optional postgresql-15_15.7-0+deb12u1_mipsel-buildd.buildinfo 80f168d4d58a42a70fbfa5860511dee6 16270920 database optional postgresql-15_15.7-0+deb12u1_mipsel.deb 411f5137a766ac898e4b3e4d527b6679 2332136 debug optional postgresql-client-15-dbgsym_15.7-0+deb12u1_mipsel.deb a01bac396c95ed322b25854384fa4fd0 1643156 database optional postgresql-client-15_15.7-0+deb12u1_mipsel.deb 9f0ce2db455b191f58ed33d5251f6a2e 184560 debug optional postgresql-plperl-15-dbgsym_15.7-0+deb12u1_mipsel.deb d9fcfaf4a33b6d1c44d10efa9e615671 84216 database optional postgresql-plperl-15_15.7-0+deb12u1_mipsel.deb d883668423529b47ccd1e2111caad491 174916 debug optional postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_mipsel.deb 61f94def08216ca30887a429eb02a976 102824 database optional postgresql-plpython3-15_15.7-0+deb12u1_mipsel.deb 562a7a02072d521f0c040630726bd0fa 79984 debug optional postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_mipsel.deb ade4cd5a8f86e45333c743ae4421e2b9 38428 database optional postgresql-pltcl-15_15.7-0+deb12u1_mipsel.deb 524a5c0542c7acb83fd93691dd7e4db6 1148876 libdevel optional postgresql-server-dev-15_15.7-0+deb12u1_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEuQAPGkYIXAAfq7z1C2Vm2FYVKKAFAmZMDhEACgkQC2Vm2FYV KKB20A/+Krs9nn3OpwEdcDpzSB/DUvDARxsCSBMftRtnvWDJiLgs2iXAEoDyhrp3 fHDOdKFakVA45o7OnAvkr/fFEGQ2CSiGael7lQKmYc2yFIpiAm+UVnBzay/8UhSB jU3O7Rebgrg2wp/Rebif9ZIhpb3mkwBs1Ft7DVdv5NC2NfaCa4Yo2/Cx+OEAF7gL wtKpHAdyPqrkNWBerk5W7HFiPyC8v9QM1wFrra/1IZcuQa+yGB6wg/KbeFECjiDe nG+A1nVqIo8XQv2WyAHBTeY//grX+Me7l6Nmm4UcCFBXYRDlm2E24PpOz1efMdb+ 04gFAVLbIPC6U7JuphKMoBKxP4DwQwPDJibPf9mDF2Paf/2hmcppUYcF3mXJYRMD xoLloniAQqK/8UpSu//vQRn7FQf6VMxxxc6s847au4PE06wkdP28YJY/OzuOKUs5 APtMcE4mZD527sFstNa/dUk9KhqujokSLpRPeJClzGecTZKDU5dvYlPNVQZbtN15 hFoPrsHCW/YMS6p7/VIui8oqOUJcSn2vUdBUiaGwNKDw3YFmo87XnVfFtvfahWks lp7PsSX3Por1Lqvsc+YZUa8u6zuWGBa+qgJtAzm81QYQRLQ/PGK2cCpfQ7/qlKQU FVxuACqHiUrCk13Qv6dsT4iHUaKlCq3XkegkvWtaOsDnBgHuWGo= =CPHU -----END PGP SIGNATURE-----