-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 16:09:15 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: armel Version: 13.16-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.16-0+deb11u1) bullseye-security; urgency=medium . * New upstream version. . + Prevent unauthorized code execution during pg_dump (Masahiko Sawada) . An attacker able to create and drop non-temporary objects could inject SQL code that would be executed by a concurrent pg_dump session with the privileges of the role running pg_dump (which is often a superuser). The attack involves replacing a sequence or similar object with a view or foreign table that will execute malicious code. To prevent this, introduce a new server parameter restrict_nonsystem_relation_kind that can disable expansion of non-builtin views as well as access to foreign tables, and teach pg_dump to set it when available. Note that the attack is prevented only if both pg_dump and the server it is dumping from are new enough to have this fix. . The PostgreSQL Project thanks Noah Misch for reporting this problem. (CVE-2024-7348) Checksums-Sha1: 83d3aaf67f6ce24703e2954c05f7b6ca6b7bf0ba 36308 libecpg-compat3-dbgsym_13.16-0+deb11u1_armel.deb 054e52a27b3b2e0e901fc63846753b54ac959d95 25408 libecpg-compat3_13.16-0+deb11u1_armel.deb 37995717194da6c70e1042cd792cf99b58726f3d 216928 libecpg-dev-dbgsym_13.16-0+deb11u1_armel.deb 9ca533496b0e0343c36bfb77c054d6baa7370a1a 262608 libecpg-dev_13.16-0+deb11u1_armel.deb 92fc62d8e6228e24c2712dbc4384c80b9c6b8944 107088 libecpg6-dbgsym_13.16-0+deb11u1_armel.deb 8d43cf19099608aa1b52bcf1ff5d7e639bbeb3be 56652 libecpg6_13.16-0+deb11u1_armel.deb 4dfb28b5f1d1ca94495930ed74976ac75f8bcd00 84220 libpgtypes3-dbgsym_13.16-0+deb11u1_armel.deb 675b47e25b17bf38c6c7d0bc81c962fc9acafb79 45480 libpgtypes3_13.16-0+deb11u1_armel.deb 6d396021ac6faed39266132571cac0657563ecdd 131096 libpq-dev_13.16-0+deb11u1_armel.deb 65df55f540c0a3a4a8794b0aa3a366513a5199ce 242572 libpq5-dbgsym_13.16-0+deb11u1_armel.deb 814d0156e289ba69c9ae7454820586f9f03c3696 165796 libpq5_13.16-0+deb11u1_armel.deb d89265503a00a07e5d76a8ea573f761b757300fd 14191872 postgresql-13-dbgsym_13.16-0+deb11u1_armel.deb 0fd451d57b115aa3e2065f6d32acf63b20dc569b 16195 postgresql-13_13.16-0+deb11u1_armel-buildd.buildinfo 5e2f55dc3fa45b3f996b9a014ce12892fbf35652 14553132 postgresql-13_13.16-0+deb11u1_armel.deb 0cca48b96750c8683b7c9459a0a6157ab0d171c2 1800984 postgresql-client-13-dbgsym_13.16-0+deb11u1_armel.deb 2df1adc07455685d93ea17df8cf7b43fde03cc9e 1435304 postgresql-client-13_13.16-0+deb11u1_armel.deb 2f978ef05c4a3afe8d6c0b638ed769027558c0a5 152124 postgresql-plperl-13-dbgsym_13.16-0+deb11u1_armel.deb 63a6a51e5e71a5beae11bc0c7d6db4d81a944d11 86304 postgresql-plperl-13_13.16-0+deb11u1_armel.deb d54cd69bfc0ee5ecec2afcba1d70c3bfd5b71afe 154544 postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_armel.deb 0028a7c7f975322472360b307f13c00ca578facb 104392 postgresql-plpython3-13_13.16-0+deb11u1_armel.deb f45d0adc3ef345a32b12d95ee9d3fc92fdaeddd4 72324 postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_armel.deb 7ed8db0139577b0c28de5aad68d72ecbdda91f90 41280 postgresql-pltcl-13_13.16-0+deb11u1_armel.deb 798cebc0a19278b15b74a3e4cd2ea8469afe7585 1031172 postgresql-server-dev-13_13.16-0+deb11u1_armel.deb Checksums-Sha256: 1b2cf20b22762213abb5bdfec52cac1d49208c422bf7dfdd3999fe0c5c774efe 36308 libecpg-compat3-dbgsym_13.16-0+deb11u1_armel.deb 3af176059ec8f66745922058592aa1fd0d5cae4ed2796003218f5742e2f53b8a 25408 libecpg-compat3_13.16-0+deb11u1_armel.deb ed62f5fddb339eb05e1c0d93c30515b4d7bf2174675810a184cab98123619f43 216928 libecpg-dev-dbgsym_13.16-0+deb11u1_armel.deb 18b6e654dc43023e011145c1d4d56445b9ff26260dcfd228c6a40e1f9e6665a5 262608 libecpg-dev_13.16-0+deb11u1_armel.deb c2ad3c6ca41ef3e8db27c9dfe9c858acb6c9da3d369881f14fb2af4818bc97ad 107088 libecpg6-dbgsym_13.16-0+deb11u1_armel.deb 496ec4142568173ab71d78a14f6a9d1aa0740e03e92c07b35b29cfa713fb79c3 56652 libecpg6_13.16-0+deb11u1_armel.deb 84eb5d82f865e1710ba554f05204a754782d66d409cdef9c49db2aa64698b9ce 84220 libpgtypes3-dbgsym_13.16-0+deb11u1_armel.deb e4855f3b16ee3af6fdd46baa1b34044d64caa9b1e1e2f06a81e3d9661174eeb9 45480 libpgtypes3_13.16-0+deb11u1_armel.deb 0e48009cc6c7b80151fc9592d9a252cd14fc472aa75a2b29e6b674ef7adff0d1 131096 libpq-dev_13.16-0+deb11u1_armel.deb 87a86e55c0a0947fdd57231b4819f5e1f974f32f28227fcd58fbc10ef372b06e 242572 libpq5-dbgsym_13.16-0+deb11u1_armel.deb 31acafd437a0984046b1f0f6df26b96e678142a625c8f9a7bd667e07fea2540f 165796 libpq5_13.16-0+deb11u1_armel.deb ff4aa7ef59a0fcced9d65e6464532acca97e8260559c9ce9143693cffc26a6cb 14191872 postgresql-13-dbgsym_13.16-0+deb11u1_armel.deb 6ed365229e14a3f5213f6ab5d9149a3fe7dbf255450a81c45a77a5a419251daf 16195 postgresql-13_13.16-0+deb11u1_armel-buildd.buildinfo 4eb1aaf3013f8377a93d1fd43dad8ab3722184e598c0f23bf4fa111fc6d2b23e 14553132 postgresql-13_13.16-0+deb11u1_armel.deb 9335fee2640d4402c4f34964e7e28ee161ea7505a5cae5be6d47cf693d38bb5b 1800984 postgresql-client-13-dbgsym_13.16-0+deb11u1_armel.deb 10c7a67e98ebf4ce65707fa29fbe6ea725687f784e7a0b31e94a30273e70e746 1435304 postgresql-client-13_13.16-0+deb11u1_armel.deb df1386d12cc1bc7e9a206412f6319de35be9341e882cf9ca38dc0c4aef9d0028 152124 postgresql-plperl-13-dbgsym_13.16-0+deb11u1_armel.deb c1f916d1c70081484a3eb216be74c8a476b9ea35c225e1e1acc2625f15b7ebb8 86304 postgresql-plperl-13_13.16-0+deb11u1_armel.deb d4f5db76c56e4f44d0f6dbebfdf1969d659c18f869da819475ec710ca354cd56 154544 postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_armel.deb ffd9745f0346d021f27a13bee05ef9114831ce72714e1e5147a73b23e6796788 104392 postgresql-plpython3-13_13.16-0+deb11u1_armel.deb 21df726a8290252a2df7f31aa1c1b5adfecc72ca3c0da0376843a2e212189ac7 72324 postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_armel.deb b8f935f00edc53d56cf83a211e176e3797af14c81a2f5b4550d42cb4cf1a8782 41280 postgresql-pltcl-13_13.16-0+deb11u1_armel.deb e6f5117b1c0c190413c2777e504221c14191a5e0cc62663ef77d51939e1ca356 1031172 postgresql-server-dev-13_13.16-0+deb11u1_armel.deb Files: cbd783477ceb8369dcb9058ebcebfba2 36308 debug optional libecpg-compat3-dbgsym_13.16-0+deb11u1_armel.deb 319609d59c3174d8219a9e21cce76cb0 25408 libs optional libecpg-compat3_13.16-0+deb11u1_armel.deb 0299f387b58123dc8e9567f60e78804e 216928 debug optional libecpg-dev-dbgsym_13.16-0+deb11u1_armel.deb d37969ec35d613bc9c7807b0cddbf8d7 262608 libdevel optional libecpg-dev_13.16-0+deb11u1_armel.deb 40d13a6c9ddbce997b42dd56dbf0925a 107088 debug optional libecpg6-dbgsym_13.16-0+deb11u1_armel.deb be71bd8049a3664573b520b4c9bfdb9a 56652 libs optional libecpg6_13.16-0+deb11u1_armel.deb 85bdb290733590f566231918932f34c0 84220 debug optional libpgtypes3-dbgsym_13.16-0+deb11u1_armel.deb 29043d3d014ea34289692a581b1c2295 45480 libs optional libpgtypes3_13.16-0+deb11u1_armel.deb 154a1ee49c2f6aa9e664c191490fb12e 131096 libdevel optional libpq-dev_13.16-0+deb11u1_armel.deb 307083f8026c1d72b3be9f0419324b89 242572 debug optional libpq5-dbgsym_13.16-0+deb11u1_armel.deb 9bcb9644cea00f84fd88ddd00233cf56 165796 libs optional libpq5_13.16-0+deb11u1_armel.deb 116964629ce2aceb8f4eb7386b56e1b0 14191872 debug optional postgresql-13-dbgsym_13.16-0+deb11u1_armel.deb 77d5211a60341cb326665f3d39c10176 16195 database optional postgresql-13_13.16-0+deb11u1_armel-buildd.buildinfo a5c8a3e91dfd3ad7369376abb763d634 14553132 database optional postgresql-13_13.16-0+deb11u1_armel.deb fd30a80243cd8d4f447eb775db724c00 1800984 debug optional postgresql-client-13-dbgsym_13.16-0+deb11u1_armel.deb 98b0c16634a4fe9102aed2c30d7fa1e3 1435304 database optional postgresql-client-13_13.16-0+deb11u1_armel.deb 48eaefe5adca3ba02ecedbfbc55ae9c9 152124 debug optional postgresql-plperl-13-dbgsym_13.16-0+deb11u1_armel.deb 561b8cc46cc21c8c068e49e15ddeede2 86304 database optional postgresql-plperl-13_13.16-0+deb11u1_armel.deb 1cfe628134fe79308769261a4dd07744 154544 debug optional postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_armel.deb 7aa8a1f734e6b100285e3a4caa871498 104392 database optional postgresql-plpython3-13_13.16-0+deb11u1_armel.deb 2633f747958ee1227452e021cc27ca5c 72324 debug optional postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_armel.deb 985d0bf91446963e654b5ed068926783 41280 database optional postgresql-pltcl-13_13.16-0+deb11u1_armel.deb 31bcd51a62ffba31e8f123b5daaa3309 1031172 libdevel optional postgresql-server-dev-13_13.16-0+deb11u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEw2TRpv7HYIvK+TsIbEMdCP/rlD8FAma05NQACgkQbEMdCP/r lD+LbRAAkwzxO1SFzWW5hRzP2IXu9MXBRRnIKaqALC2SKU+HxqfEFAPcYzHiASjh FmM8zpsLjVJCX+w1HIiOiSmObRv1pT3dp/jCFZfE9OkaHAGQUA6hqyQYQgHut35E s0eKBnrU7RZxLQQmpAuTDM8tnDLCJWWwqCfONfPpnwqZddj4kekl1mPbUbZUcF0E g8MABNBcdqBSd/OJBZ6tR0rK7P4ua0RuNwuanB1WIrjAmMSApeDbzU6XTQyJh7Mw W55T6FiVIc4VOF+cTvkaz7zSxE/lg1a8K1OJck1et1TllP2BouWNRn2f9XxtmxHe GuKeaisRf1oK36A/mHXBMW5d8Q7w2Fg3+yTm2emjIyQN6LXAqZru6xsF3lNqqgEp Zsq+6jI2eDhXuz7YdrdW7rzfVuAGjnoegQ2Qc2LeGlLjACGp6blC1DKGf+27JrvA g0DnhARegka70/5bxEIANfF0GXzy+ueHy/UEMii74BiqlZ+fbkn6hyAzhAI4/Og4 rozHLIO20hpo/UsolI09EAbjpHi/9r8raQF0kK0xwRoDXV9+oBez1z24rVEkd5uy hinDp+ArNNjcuw3wgerOIP9sVXFAzoN9QUSEwOypWeMT4gi4aYfay3/+fAAmiBOk oL81MOVS2k9EhaHhMTZDQEuC3UgOjeha39YQP0EVWeCKo3/oLBw= =vc3L -----END PGP SIGNATURE-----