-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 16:09:15 +0200 Source: postgresql-13 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-13 postgresql-13-dbgsym postgresql-client-13 postgresql-client-13-dbgsym postgresql-plperl-13 postgresql-plperl-13-dbgsym postgresql-plpython3-13 postgresql-plpython3-13-dbgsym postgresql-pltcl-13 postgresql-pltcl-13-dbgsym postgresql-server-dev-13 Architecture: mipsel Version: 13.16-0+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-03) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 13 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-13 - The World's Most Advanced Open Source Relational Database postgresql-client-13 - front-end programs for PostgreSQL 13 postgresql-plperl-13 - PL/Perl procedural language for PostgreSQL 13 postgresql-plpython3-13 - PL/Python 3 procedural language for PostgreSQL 13 postgresql-pltcl-13 - PL/Tcl procedural language for PostgreSQL 13 postgresql-server-dev-13 - development files for PostgreSQL 13 server-side programming Changes: postgresql-13 (13.16-0+deb11u1) bullseye-security; urgency=medium . * New upstream version. . + Prevent unauthorized code execution during pg_dump (Masahiko Sawada) . An attacker able to create and drop non-temporary objects could inject SQL code that would be executed by a concurrent pg_dump session with the privileges of the role running pg_dump (which is often a superuser). The attack involves replacing a sequence or similar object with a view or foreign table that will execute malicious code. To prevent this, introduce a new server parameter restrict_nonsystem_relation_kind that can disable expansion of non-builtin views as well as access to foreign tables, and teach pg_dump to set it when available. Note that the attack is prevented only if both pg_dump and the server it is dumping from are new enough to have this fix. . The PostgreSQL Project thanks Noah Misch for reporting this problem. (CVE-2024-7348) Checksums-Sha1: e5fd96bc513bb5f613ce5a5fa009706aaf7551c1 37632 libecpg-compat3-dbgsym_13.16-0+deb11u1_mipsel.deb aeb4e14a5ff1692d81f68411d996c1cc0025b105 27144 libecpg-compat3_13.16-0+deb11u1_mipsel.deb cc39f9186f834f4443abdae03aa05556cde866a1 237180 libecpg-dev-dbgsym_13.16-0+deb11u1_mipsel.deb 45e77e639df85208ecffa8f205a0fdb7f9198d3f 276824 libecpg-dev_13.16-0+deb11u1_mipsel.deb 6562c3572c13c0a34715cc98030d0423b7af50f6 109480 libecpg6-dbgsym_13.16-0+deb11u1_mipsel.deb 2845ca5f8795f667be68047393074ab9e7cac2e1 61000 libecpg6_13.16-0+deb11u1_mipsel.deb bf749da2b82a948de472db469ab50f505928cd2c 89360 libpgtypes3-dbgsym_13.16-0+deb11u1_mipsel.deb 8402029c2227fdad78e7a0f6c684d9847adcb1fc 49512 libpgtypes3_13.16-0+deb11u1_mipsel.deb e37d7ec01293745564679b130c587f9ba61c1a53 371728 libpq-dev_13.16-0+deb11u1_mipsel.deb e796e8400dd063b2b43b5888702a7157ce89217f 250596 libpq5-dbgsym_13.16-0+deb11u1_mipsel.deb 17ddb1be9485173a6d45df1d27f7da431fcbd22d 173368 libpq5_13.16-0+deb11u1_mipsel.deb b59b491e52d55ea12b0532410a8a09d97441c1d7 14528432 postgresql-13-dbgsym_13.16-0+deb11u1_mipsel.deb b53eb1b6157bbf517990a38b624f5c1b5646b83a 16332 postgresql-13_13.16-0+deb11u1_mipsel-buildd.buildinfo a8f51ab1e22ccd6c82324ec01b97abcc254016ce 14715860 postgresql-13_13.16-0+deb11u1_mipsel.deb 714fd653672acc46117a397e5718c554c8cd6e15 1866164 postgresql-client-13-dbgsym_13.16-0+deb11u1_mipsel.deb 2e1d633b3cfa5349b937c1e94e07f35791ed28d9 1470072 postgresql-client-13_13.16-0+deb11u1_mipsel.deb 4866e0eef524dd63be82bbf06b9c8f06cdcb2419 152108 postgresql-plperl-13-dbgsym_13.16-0+deb11u1_mipsel.deb e171878e8c156fff43d48b50893a9b2598823390 85536 postgresql-plperl-13_13.16-0+deb11u1_mipsel.deb 963a6739edfb91b8d789fb51bfd9abd451b250ec 154132 postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_mipsel.deb 6b457eed9b0739efeb31bfa3ce0bebfe5afba029 102716 postgresql-plpython3-13_13.16-0+deb11u1_mipsel.deb 7b1588696f42324cfa70a347a8c6702f2c4d6f2e 72328 postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_mipsel.deb ca6023bf199df8f5e4e44be8e9e061bfb4ac3a49 41280 postgresql-pltcl-13_13.16-0+deb11u1_mipsel.deb 0f7bff44d4a9128ea55dbad1c9cbb739279f33d5 1050468 postgresql-server-dev-13_13.16-0+deb11u1_mipsel.deb Checksums-Sha256: 8ea3dc641e18d174a585315ec896cf8813a1aec274ce163d7b33e5509e947991 37632 libecpg-compat3-dbgsym_13.16-0+deb11u1_mipsel.deb 4b2a2445b8dbe900b270ca56b793c00a5ae3e5f4dee9bb160be069ce14c6839e 27144 libecpg-compat3_13.16-0+deb11u1_mipsel.deb d2e3dcbba99faffe86355e7c5e464a71c53d9dca54ec5af5391cd33235364d4c 237180 libecpg-dev-dbgsym_13.16-0+deb11u1_mipsel.deb 06c7f686db5ed163985bd9125dbf93c1e132091bb1d1fc4c91031dc30fb17adb 276824 libecpg-dev_13.16-0+deb11u1_mipsel.deb 3c53855045aba1cb819c9c35ad06f6cadc550bf5baae0f0c697954cc0121b2a3 109480 libecpg6-dbgsym_13.16-0+deb11u1_mipsel.deb 0df0984d10267b269b319d94b33a90081f6fb0642e2b8f36e41d41bb7e23979c 61000 libecpg6_13.16-0+deb11u1_mipsel.deb 03bb14b16d2130f314936d402d933aecd25a170a85301f817204247d13841839 89360 libpgtypes3-dbgsym_13.16-0+deb11u1_mipsel.deb 0d092c9382147223acc9bab75c1856e86fe46b796296d9ad650791195b65c3f9 49512 libpgtypes3_13.16-0+deb11u1_mipsel.deb 7741713a38f844bea5e9789a45e21d7ce215861b3f4a6c3035e18bdf215248bb 371728 libpq-dev_13.16-0+deb11u1_mipsel.deb 5902ad0c4875a9989823840ca3c28b7688b417a58fe8236aa9322affa7385248 250596 libpq5-dbgsym_13.16-0+deb11u1_mipsel.deb 290937dbebd91b7fdfa1ec81bc88fd3a03ffd5e6089b4409f2243d4a70772f96 173368 libpq5_13.16-0+deb11u1_mipsel.deb 3a32a71b2a647650a113b9899abdda1d967b39f879f97dfb8f931dd93f5c9a71 14528432 postgresql-13-dbgsym_13.16-0+deb11u1_mipsel.deb 60dc2964b33c5ef212f336a2d7801fb5cb17da273d33de49b6b3a85571ee7a8b 16332 postgresql-13_13.16-0+deb11u1_mipsel-buildd.buildinfo 61e05a7b486e317ce95720e065eef9541aa61ff96b820269300d14da8800efa6 14715860 postgresql-13_13.16-0+deb11u1_mipsel.deb 175da18d4498d7d126375ef97f33684034a6feafa56d6f11abcd15b937d848b2 1866164 postgresql-client-13-dbgsym_13.16-0+deb11u1_mipsel.deb 40beace01b0da78b771c2ccc459ba5fcad6de81e4d8216e74594b5dea83a46e9 1470072 postgresql-client-13_13.16-0+deb11u1_mipsel.deb 8120082b913ea2f36fb7b3555bae42a964b8eaa3089db3c0437b00ac7d05ff0e 152108 postgresql-plperl-13-dbgsym_13.16-0+deb11u1_mipsel.deb 996aeebbcd579ce90dbb4f64ad7ec1b9aae8f4f4566b74b14c3fb350166f7c9d 85536 postgresql-plperl-13_13.16-0+deb11u1_mipsel.deb c4d70dc49cec5e08b7dd2c97ca487dfe68679e74a85b5d33e01a20b1e692f731 154132 postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_mipsel.deb 9c76a1a2537c891fedddee171e518e5a799b6e6b0721cf72ce7b7ce7584ff04c 102716 postgresql-plpython3-13_13.16-0+deb11u1_mipsel.deb 278b073c4c696d57233b3fd07797effb75fec45e43f5c59b2f1326e67ca7f550 72328 postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_mipsel.deb 797d7d512636b9172b347d952ee64a080c187fe8de2bdc02755ca984b0527770 41280 postgresql-pltcl-13_13.16-0+deb11u1_mipsel.deb b7c68a1491faccaa06e862025454743c914f28c7a8cf8bf55263612b210202b8 1050468 postgresql-server-dev-13_13.16-0+deb11u1_mipsel.deb Files: 3128206a29a42358ed0b33f7b9bc58de 37632 debug optional libecpg-compat3-dbgsym_13.16-0+deb11u1_mipsel.deb c30b36e947dc03c6d5fa52e6d2d0c53a 27144 libs optional libecpg-compat3_13.16-0+deb11u1_mipsel.deb 6f5f60a72d9973d9705d0d74282ae761 237180 debug optional libecpg-dev-dbgsym_13.16-0+deb11u1_mipsel.deb 149918b50ce11c86d58cc8e5f6f0e585 276824 libdevel optional libecpg-dev_13.16-0+deb11u1_mipsel.deb 130d3730c230fe98dc5532c266c08462 109480 debug optional libecpg6-dbgsym_13.16-0+deb11u1_mipsel.deb f4217241056b0b47cfacfb78d67c9096 61000 libs optional libecpg6_13.16-0+deb11u1_mipsel.deb a508e76f5de1a0daeceef45139a408e0 89360 debug optional libpgtypes3-dbgsym_13.16-0+deb11u1_mipsel.deb b95113d4ab224d141162b0d69d54186a 49512 libs optional libpgtypes3_13.16-0+deb11u1_mipsel.deb f2ec67c3c920296b549299e907c89f0c 371728 libdevel optional libpq-dev_13.16-0+deb11u1_mipsel.deb 697f015d6a4396a42a6d8a03dfe8bb3e 250596 debug optional libpq5-dbgsym_13.16-0+deb11u1_mipsel.deb 57453f896523a94ebc3bf400b67aba91 173368 libs optional libpq5_13.16-0+deb11u1_mipsel.deb 1fda48f209b52bd85dc7179f98a4d945 14528432 debug optional postgresql-13-dbgsym_13.16-0+deb11u1_mipsel.deb 65c0cee3b5e230b3093709f1a1b29d0b 16332 database optional postgresql-13_13.16-0+deb11u1_mipsel-buildd.buildinfo c0c9ac8c07aeef119816d9e44103a535 14715860 database optional postgresql-13_13.16-0+deb11u1_mipsel.deb 287255864489581dcabbc0f07c49e107 1866164 debug optional postgresql-client-13-dbgsym_13.16-0+deb11u1_mipsel.deb 54d0c565851f62e0c9384b31c95fb2ef 1470072 database optional postgresql-client-13_13.16-0+deb11u1_mipsel.deb 0acfaee3cc325d85a37d51282955a251 152108 debug optional postgresql-plperl-13-dbgsym_13.16-0+deb11u1_mipsel.deb 8ba46e0dc1cccfb53c26e2cc3e5c1b83 85536 database optional postgresql-plperl-13_13.16-0+deb11u1_mipsel.deb a746be0f8ef06537e66e91d94fd22444 154132 debug optional postgresql-plpython3-13-dbgsym_13.16-0+deb11u1_mipsel.deb 55ad53d067bf9259b12e7613a75cfadd 102716 database optional postgresql-plpython3-13_13.16-0+deb11u1_mipsel.deb 5952369d0031d9a28e3900ce40bf410d 72328 debug optional postgresql-pltcl-13-dbgsym_13.16-0+deb11u1_mipsel.deb 843c6d8188091a4b47df7d20c48f9128 41280 database optional postgresql-pltcl-13_13.16-0+deb11u1_mipsel.deb 2446a7cd480f8e3ab2ca2134abba0929 1050468 libdevel optional postgresql-server-dev-13_13.16-0+deb11u1_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEunmvxaaGKuI+hxxClmZGXOM83t8FAma1AWAACgkQlmZGXOM8 3t8y0g/+P5/w0CC0M/r0XW6PVLR1CA/6iz9rEge9okaBWUkpI1nvoAgn11GpUKZa PV5q87Opl908EiowgHyy9Nw/7+8C0oxgjHswml2J4FTd1e1FazeRN1vw5vJNmK0J 7Y5dyzs1SPntpiumGcUw0j+cJpYJfxDMCUc8kt70HH/VEgJmK87H4Yb/18yVwttY CiRzAZv1e73EtsOnZpgnhGAyRvqVALdeHmpBoR+onyHhbzqA+R9BiBs1P1kAtmjo /fSPlw1Fih/p104GuKkQitIsTtmKlZkAOHYyqeAQrFzgkBM6YsgJ7AN/lgPXGWBW E4IfFgx0Zn4yOEkBcY39M9FYuTqL/La4GeLOovZlROdqlbSm57cPiojLxrq7qNEv RhyS/Q6pzc/2JGdHCr4XucxTguSPzH4YP9WuoCVNG2/aikXKdsbd9D7rczahhbxY RN/HII6mY+EjlnWJmol5aN11/C9OX9tO2/3mPWFqa/Zb5QKeFJOT02LE9KT1KF1V EaYG6xEHbKdQ+ep94EvxzPylrxuLkhmUPz096lfcmyO6zSuVouedBJn2DzKIC50C WJHU9OY8YLMvYWJEzX2vQztp5tVwedFvy4XmEDnCwVXiTLfKhcLksZFnCgeDwWU/ lOBxLOZxKnMEDBv20XQnQV64y89gvcen8v/v+GzhiBjZSUMdKpI= =M+K3 -----END PGP SIGNATURE-----