-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 16:09:15 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: s390x Version: 13.16-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: s390x Build Daemon (zandonai) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.16-0+deb11u1) bullseye-security; urgency=medium . * New upstream version. . + Prevent unauthorized code execution during pg_dump (Masahiko Sawada) . An attacker able to create and drop non-temporary objects could inject SQL code that would be executed by a concurrent pg_dump session with the privileges of the role running pg_dump (which is often a superuser). The attack involves replacing a sequence or similar object with a view or foreign table that will execute malicious code. To prevent this, introduce a new server parameter restrict_nonsystem_relation_kind that can disable expansion of non-builtin views as well as access to foreign tables, and teach pg_dump to set it when available. Note that the attack is prevented only if both pg_dump and the server it is dumping from are new enough to have this fix. . The PostgreSQL Project thanks Noah Misch for reporting this problem. (CVE-2024-7348) Checksums-Sha1: 66825f6f2da85f9a457f64aebafb6001aa6c1171 37464 libecpg-compat3-dbgsym_13.16-0+deb11u1_s390x.deb 1b5438452758eca99cc3d2a75e62ff00ae5d6222 26344 libecpg-compat3_13.16-0+deb11u1_s390x.deb eb17f1d9ddcc1fa4d39710fea7776888db4910ce 207216 libecpg-dev-dbgsym_13.16-0+deb11u1_s390x.deb 5d35b30bc397ddf4e0fb5549428402b5da7fbae9 271268 libecpg-dev_13.16-0+deb11u1_s390x.deb c321122a29714a227a4077ab4c40f821e6dccab7 111228 libecpg6-dbgsym_13.16-0+deb11u1_s390x.deb b6d23c0a7a8676c61a34f5927c71a6a24415c1ed 60292 libecpg6_13.16-0+deb11u1_s390x.deb 1505e922aa140c00aa3a13a57dbb08ef0807774a 89276 libpgtypes3-dbgsym_13.16-0+deb11u1_s390x.deb 268dfbdcafd89cdcbbe2190baa7a5ecd27feb073 48084 libpgtypes3_13.16-0+deb11u1_s390x.deb 45c521789d107ebcfe1b494ea3955250b34e40d5 137588 libpq-dev_13.16-0+deb11u1_s390x.deb 12dd7d148250c92780c6839800de6122f8552c16 256880 libpq5-dbgsym_13.16-0+deb11u1_s390x.deb 8842ba004ee84a9d0151c9b724b7a6fd026243e9 173804 libpq5_13.16-0+deb11u1_s390x.deb 1f1f4c5b9655d53da20d7133fcf9f3be297c2cca 14975964 postgresql-13-dbgsym_13.16-0+deb11u1_s390x.deb 19f74d3553204c83e2ca26b3f6630a38346e1709 16216 postgresql-13_13.16-0+deb11u1_s390x-buildd.buildinfo 4adb1c08d2d94732c148af927f4aab5c3bf2c025 15830348 postgresql-13_13.16-0+deb11u1_s390x.deb 86477dc2d302c2b3cfe76ecb10190f3bd4b069c8 1874544 postgresql-client-13-dbgsym_13.16-0+deb11u1_s390x.deb 8ed77fba6a9fc4a85181787cbf51de741338ba17 1467128 postgresql-client-13_13.16-0+deb11u1_s390x.deb de69644be6fd52093bbc2fc31a672062ffd6abcc 156104 postgresql-plperl-13-dbgsym_13.16-0+deb11u1_s390x.deb 37cede5a45aba7dbef5767b8c7c0f555816a5312 87164 postgresql-plperl-13_13.16-0+deb11u1_s390x.deb b33aa06f847ca064ceb87b7da3d4d316662baa76 156356 postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_s390x.deb d641349bc2041225fedf0c39d3eae7330e8f9467 107192 postgresql-plpython3-13_13.16-0+deb11u1_s390x.deb 5ba70bd5effd138dee3f579b166ef7521d5fbd7d 73720 postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_s390x.deb ab34ecfe08be7ff20b2caa12058b6f74328caa10 42652 postgresql-pltcl-13_13.16-0+deb11u1_s390x.deb ae5438112b7e8127a4e394325d8ef8eb3d6719d6 1036552 postgresql-server-dev-13_13.16-0+deb11u1_s390x.deb Checksums-Sha256: c8a488134bc0ff967c00b3366e82c3726bfe1f77eb81052bceb6621e44f5cd60 37464 libecpg-compat3-dbgsym_13.16-0+deb11u1_s390x.deb 2643820ca20c492d440f01bd5a29649c33551412b866db922853fff472204c64 26344 libecpg-compat3_13.16-0+deb11u1_s390x.deb cb7a13d26e5d11abe14dc1a1d825d3e313988a187838549c83d8ec193dc56c5b 207216 libecpg-dev-dbgsym_13.16-0+deb11u1_s390x.deb 9a8d237c7b8cf0f5615c0cdae21645a957078f6827160e636bef3ffc1e377f06 271268 libecpg-dev_13.16-0+deb11u1_s390x.deb 12766a79be880ef35a844f90687105c86f98b1195c8c8b6db8ac53269966dccb 111228 libecpg6-dbgsym_13.16-0+deb11u1_s390x.deb 9804d755a7d5ae230116952934fa7e6d9e01b0d806051bce8fb03b9813cd29f0 60292 libecpg6_13.16-0+deb11u1_s390x.deb b120ea15e12b6ad27e42ef215d67073ee3de8ae36a1d733e9e7da068e8c81179 89276 libpgtypes3-dbgsym_13.16-0+deb11u1_s390x.deb 2810280ce4d308ff1f929e0b2d9ee610a4f73338a7003d908416ad9cd4b4e92c 48084 libpgtypes3_13.16-0+deb11u1_s390x.deb 72277f90b36199362fce4f00a5b622d2476e9b4d1013944df939884fa2150fba 137588 libpq-dev_13.16-0+deb11u1_s390x.deb 1eb3629b58e010200cd63c3ddf9e24ee85c2c397eb6269f485152230a77351e6 256880 libpq5-dbgsym_13.16-0+deb11u1_s390x.deb ba08f6514fb0ed88444b811267b368be85c93039d8a2bef14c2883ee843f39ad 173804 libpq5_13.16-0+deb11u1_s390x.deb 3459211ac2a07f7dcc39f76e83f7632d0150eb4a365fdcbfc981cac91d027149 14975964 postgresql-13-dbgsym_13.16-0+deb11u1_s390x.deb 4d05a6c9638bb65f5d47d8c91685c6d3e169f76d4fdf0d00cbb42d508e916acd 16216 postgresql-13_13.16-0+deb11u1_s390x-buildd.buildinfo 242cc417734be2cc0d34f0de4ef2a03067a4ce42e8f87fe22af8dd535dba83ed 15830348 postgresql-13_13.16-0+deb11u1_s390x.deb 95290771890417eb102bbbf3513ce2e1cd36a46942dda3b5e5e6d74079238fb9 1874544 postgresql-client-13-dbgsym_13.16-0+deb11u1_s390x.deb 7602fcad1750a19c55feb47490ffcea3c50f1dac1a51dd98667e00f8d7618d6e 1467128 postgresql-client-13_13.16-0+deb11u1_s390x.deb 0fe2d9ddf0852872cb475db1375b60e4c130b2d96ff0a0c018ffca1910bf3e85 156104 postgresql-plperl-13-dbgsym_13.16-0+deb11u1_s390x.deb aa8ed0616b32a6da8c0908fcb5ef57e642064fef2cba5057f0e7407cc2a820a8 87164 postgresql-plperl-13_13.16-0+deb11u1_s390x.deb 35f8b749e4248045105d670bae373b7dd988738e5ba48aa044d7eae640e92bca 156356 postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_s390x.deb 2e75c20668ba14c3abcc35d3991557112114b523ab9ab85c6463abdca0972e4d 107192 postgresql-plpython3-13_13.16-0+deb11u1_s390x.deb e4d4f72acfe0b8fd8203210daefc54a1af26589794b97fe49011424d89a50268 73720 postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_s390x.deb 05e048adcf7cc3d82974abfcd56715b513032dd62be914e89a8b2f06c9e49608 42652 postgresql-pltcl-13_13.16-0+deb11u1_s390x.deb 2ba58805d21630765624f5936affccea57197f8a805036ffc81bd0b5d7117dbe 1036552 postgresql-server-dev-13_13.16-0+deb11u1_s390x.deb Files: f83491f5951978f728004d7d6744b755 37464 debug optional libecpg-compat3-dbgsym_13.16-0+deb11u1_s390x.deb e2670d65147dbe6ef8e30d472b049dd9 26344 libs optional libecpg-compat3_13.16-0+deb11u1_s390x.deb d301a56c72172c2a633f297e22635ea7 207216 debug optional libecpg-dev-dbgsym_13.16-0+deb11u1_s390x.deb 0c4c702ad49101de4f0724b0cc6d2300 271268 libdevel optional libecpg-dev_13.16-0+deb11u1_s390x.deb c3a3cbb4dd1fed2d8d18e08df7e5b0a2 111228 debug optional libecpg6-dbgsym_13.16-0+deb11u1_s390x.deb 188e86c60574202c494d14bf0b2d5aec 60292 libs optional libecpg6_13.16-0+deb11u1_s390x.deb b936f5e74a6227e905ff83e2a97251ba 89276 debug optional libpgtypes3-dbgsym_13.16-0+deb11u1_s390x.deb 0637ba079247ad1597dbcbdac9ba16cd 48084 libs optional libpgtypes3_13.16-0+deb11u1_s390x.deb a0395e5bcbdc577f0908d54b790eb8e6 137588 libdevel optional libpq-dev_13.16-0+deb11u1_s390x.deb 7c634ddca36ffdd9b020bc9bdeb1723e 256880 debug optional libpq5-dbgsym_13.16-0+deb11u1_s390x.deb 05f9647d190c12f9b16b860427955b25 173804 libs optional libpq5_13.16-0+deb11u1_s390x.deb 77516567768c62a234acbe08b4c675de 14975964 debug optional postgresql-13-dbgsym_13.16-0+deb11u1_s390x.deb ee04bf02c31bd4259acaa5c2ceb99a19 16216 database optional postgresql-13_13.16-0+deb11u1_s390x-buildd.buildinfo 5712a15a4a1ce4b915052da37d424a19 15830348 database optional postgresql-13_13.16-0+deb11u1_s390x.deb 421d975a2c48ab5e483d4ee2abc2c1b3 1874544 debug optional postgresql-client-13-dbgsym_13.16-0+deb11u1_s390x.deb 8c934a829cd145fece27634738b9cf08 1467128 database optional postgresql-client-13_13.16-0+deb11u1_s390x.deb 215d426311f798a0992841eba0e170eb 156104 debug optional postgresql-plperl-13-dbgsym_13.16-0+deb11u1_s390x.deb 87420cfcd9bd8f84afe261ad30cb5eed 87164 database optional postgresql-plperl-13_13.16-0+deb11u1_s390x.deb ff3b66efe7261b688f75be7cf1be7f8d 156356 debug optional postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_s390x.deb 86be0f82eacb65c817fcc648093eb007 107192 database optional postgresql-plpython3-13_13.16-0+deb11u1_s390x.deb 93790f18541c188a28a1144ad330706d 73720 debug optional postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_s390x.deb fdb4594d08b0e0de6e97c24fe7dd1c49 42652 database optional postgresql-pltcl-13_13.16-0+deb11u1_s390x.deb 3b0f8d74ba409111e0afc9226ba0c463 1036552 libdevel optional postgresql-server-dev-13_13.16-0+deb11u1_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEctqRAwcjFMIrbct74euoNlQ3ywQFAma08tkACgkQ4euoNlQ3 ywS9fw/9HycTOOh5Ob6xVj7907B623LXB0kUJs6KTaqjQRhmjis+0w0672SbJoat nBFuJgJmy0aIEuZKsEoHLGtCxBvWbnNqaT9/lmEGsBrpvVp0xlx4tSZxl35f/1rp MxkVXZUxaAZWIm82KibLzz/sNIJ8SLnFuaoSgGjRAHO5oZzjJixEPSr7W9ZRbMdx qiGCF4L+hD1axm5IIwcSXto77TQhDNOySmS1O2xrUVJsdhOkW+PleoVTUsHr3NzJ 4fr3Y90KnSq6IS/eagNZ/Zs6fQUqYNiSE52duQyH4iMe5OHUSK+y4ZUA4Zv4QO8b KJXyqG/1xumzs/lyb6uBgnVPyb3CFSSLCtP2hT5tow6sxaCLyhmgNYBFICJC0ch+ m21v8kcZ1CSLAMJwofo29DiMVxy1nsvI7ydDqHowws13cBIfbeErtGSc2OhcETsZ 1U39E+X60CxJOwbdkQUs7bpUtIXlBjMcG+EP7+ZLxqDM662dMAbW4BESNBHpTw1K ES+L+vkCZQ9jOKpuXVoroTB4uKXqopEaXyw5MOxyHM8nOrzQxas8HCJE3UAElVL4 GbVEluD84y2x3ysXd1RND6QvW1TFElQ4ihZbi++juK9JXebFCtbpOjEADKBlxK+3 UfUQ5IUY8jKZnut2epBPj2yQyipI6M9G+AUkTYNbcIzhT9JBwzg= =MHQF -----END PGP SIGNATURE-----