-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 01 Oct 2023 21:50:06 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: armel Version: 15.4-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-ubc-04) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.4-0+deb12u1) bookworm; urgency=medium . * New upstream version. . + Disallow substituting a schema or owner name into an extension script if the name contains a quote, backslash, or dollar sign (Noah Misch) This restriction guards against SQL-injection hazards for trusted extensions. The PostgreSQL Project thanks Micah Gate, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem. (CVE-2023-39417) . + Fix MERGE to enforce row security policies properly (Dean Rasheed) When MERGE performs an UPDATE action, it should enforce any UPDATE or SELECT RLS policies defined on the target table, to be consistent with the way that a plain UPDATE with a WHERE clause works. Instead it was enforcing INSERT RLS policies for both INSERT and UPDATE actions. In addition, when MERGE performs a DO NOTHING action, it applied the target table's DELETE RLS policies to existing rows, even though those rows are not being deleted. While it's not a security problem, this could result in unwanted errors. The PostgreSQL Project thanks Dean Rasheed for reporting this problem. (CVE-2023-39418) Checksums-Sha1: ef8ded6a66e6812d0e172283a3e9bd988d7f8581 37140 libecpg-compat3-dbgsym_15.4-0+deb12u1_armel.deb 0564070735aa3619aa1863b99d5e9d3ff733a424 17760 libecpg-compat3_15.4-0+deb12u1_armel.deb 55b18008655b6de19e7379eb182e5901ce5f51c9 231600 libecpg-dev-dbgsym_15.4-0+deb12u1_armel.deb b1992959b1118a3ec58f052d542883ea3ce8cf1f 268928 libecpg-dev_15.4-0+deb12u1_armel.deb d5ade4d54917a95a49a622899043fc4cb8a5ac9d 110568 libecpg6-dbgsym_15.4-0+deb12u1_armel.deb 6fa7e7a6b63019fd5cd6c96642e6df9439449cbf 51592 libecpg6_15.4-0+deb12u1_armel.deb c7b6997dee18d5ba99c83787b1db4b83b90ed80d 86544 libpgtypes3-dbgsym_15.4-0+deb12u1_armel.deb af778f74bf7ad114b97c08ee0fb3951d9f6fcdf6 38164 libpgtypes3_15.4-0+deb12u1_armel.deb 4214d1822511cc6e4b0af7f871d2e2ca300eba45 129236 libpq-dev_15.4-0+deb12u1_armel.deb 133e83836f7d6ebdca8a91f482d790d5d058015f 269412 libpq5-dbgsym_15.4-0+deb12u1_armel.deb 510cd177e91630b0bcef35bc68b6d0310098d929 166248 libpq5_15.4-0+deb12u1_armel.deb f1e88af6bb2598aeacb8394f22476df5f02b48f5 15962496 postgresql-15-dbgsym_15.4-0+deb12u1_armel.deb 22ed1be07c24652be9fcc91afe7faaf50e4a652a 16719 postgresql-15_15.4-0+deb12u1_armel-buildd.buildinfo 8e76b4d23be852f247ee00f8023c2a7cc40340b0 15946584 postgresql-15_15.4-0+deb12u1_armel.deb 509331093ab4398f2b688802b7d3edb6e1c3a93f 2222816 postgresql-client-15-dbgsym_15.4-0+deb12u1_armel.deb 2d592d504a79d115117d95267815bf5a3815f1b9 1594232 postgresql-client-15_15.4-0+deb12u1_armel.deb 863002fd2fc4c359ced6cfde10c9dfef74f2ccc4 181840 postgresql-plperl-15-dbgsym_15.4-0+deb12u1_armel.deb 9b0ea1bcd8175f8fb5a3a76ea4b950b08b5865de 83528 postgresql-plperl-15_15.4-0+deb12u1_armel.deb 9850ccc85c7008b23d9ac86232282eae5eb75f91 171832 postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_armel.deb c6c3ee31c85c9776446262da7c5da1cfee050c4e 102632 postgresql-plpython3-15_15.4-0+deb12u1_armel.deb af554e25c3f4baf28b0adcc76d9e61cedeaebd72 77876 postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_armel.deb 3d2c41252a9a1db28ee325521d30464e5c927d8e 36048 postgresql-pltcl-15_15.4-0+deb12u1_armel.deb b1bd86c1e97071955c26ec270ad94f9e767276da 1122484 postgresql-server-dev-15_15.4-0+deb12u1_armel.deb Checksums-Sha256: 2f7599dfbb4c7dfb3c6471818b84cb579799ae38f1b73d3cfd903495b93b5dda 37140 libecpg-compat3-dbgsym_15.4-0+deb12u1_armel.deb 26c32081f5eb98c17cca095cc50f67615b94f150089ea134eba108a64d631786 17760 libecpg-compat3_15.4-0+deb12u1_armel.deb 963e43d1668a22340183e1beff44aaecc57e3f224ef7ec7b94b3594a881ab44e 231600 libecpg-dev-dbgsym_15.4-0+deb12u1_armel.deb 6f9a1af5c67cd9ccf4aa27eeee89e2d363679cc08089bdc65792a0a4bf66fe9a 268928 libecpg-dev_15.4-0+deb12u1_armel.deb 695b7bffc5d0dd51a584cd5f66f878bbe724325d304b62b71bf0a93db568574f 110568 libecpg6-dbgsym_15.4-0+deb12u1_armel.deb 6b107ac087a45e81439e260b6b5be471ceafbb23e9355b4b0564801433ef51b7 51592 libecpg6_15.4-0+deb12u1_armel.deb 6898bea1fcc6bb986b0336b3636cc15feb54c2c78c48db47ebc12af5b908d369 86544 libpgtypes3-dbgsym_15.4-0+deb12u1_armel.deb 7013d0b06a25945cfc003498bc34cf270b248b0ccb12e3ec7d4fc43c5978b818 38164 libpgtypes3_15.4-0+deb12u1_armel.deb b297043a4f3e7c3dd05882e5d594c7f7ec1f821b7738772cc11a1f2388085834 129236 libpq-dev_15.4-0+deb12u1_armel.deb 69bc34b83a5bc56616cff02fca61bcad8cf39fcf4160c6759780b1d078b999c2 269412 libpq5-dbgsym_15.4-0+deb12u1_armel.deb 3054158238ab80460431608d196d70d3e85569084d17461ea7afab22ab896d8a 166248 libpq5_15.4-0+deb12u1_armel.deb 3bb8a5275fd7c6ed4611e19d313489489c58674ab89c79da4e0fa1a3efa50b76 15962496 postgresql-15-dbgsym_15.4-0+deb12u1_armel.deb c0bd6d7c8ad83558041724d0e66d98bfb6d27f7311eeae8b452aa20bd554ff3f 16719 postgresql-15_15.4-0+deb12u1_armel-buildd.buildinfo 17dac1e9a88956bb6b58a5d9afbaa51ac4969827e1a80d6593f55e8c0a865205 15946584 postgresql-15_15.4-0+deb12u1_armel.deb ebd004a4fdb86e5487dfe296eadcc09458cc0ab98903f360b914731ce55da36f 2222816 postgresql-client-15-dbgsym_15.4-0+deb12u1_armel.deb cca1860b1a8fc15ef6c216d6399f6cebd9dceca78ce2f8d164070ae25b40404c 1594232 postgresql-client-15_15.4-0+deb12u1_armel.deb ec31f7db18e5c8dba3e6fd971b471bd4bb096224d8b93794de9090e577c76d8b 181840 postgresql-plperl-15-dbgsym_15.4-0+deb12u1_armel.deb b3048f1ebbad6c8a9b4551eaa10dcfb89d942ee65f7d6f3aeb575627930e8344 83528 postgresql-plperl-15_15.4-0+deb12u1_armel.deb 71ed7b0aff015d1a68255936abe30a74793f1521d85d83399db700250760f840 171832 postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_armel.deb f7bf9320a79b3267f80f005a680b7e4e9c48de8c7055d1a71df3745c5c5cdbce 102632 postgresql-plpython3-15_15.4-0+deb12u1_armel.deb 78188b48b9deec62b74e25306ad2848cb836715f74f662665f042a46c9ea1225 77876 postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_armel.deb ad892ae69c9f00858c01f064db2066624d0f1bd913c84c1a03e2890fee816363 36048 postgresql-pltcl-15_15.4-0+deb12u1_armel.deb f0ce122445d3b2611f616b3df70153a5d2cc0126df831c361a1d828bbc666e03 1122484 postgresql-server-dev-15_15.4-0+deb12u1_armel.deb Files: b1809d69ac47c1547c248a525c1e6723 37140 debug optional libecpg-compat3-dbgsym_15.4-0+deb12u1_armel.deb cfdb3d002d360dff58df3b9c06eb976f 17760 libs optional libecpg-compat3_15.4-0+deb12u1_armel.deb 2993b9f3f2968f0dfa33fbbf3768e485 231600 debug optional libecpg-dev-dbgsym_15.4-0+deb12u1_armel.deb 2f0bdeb7cfa82efcf04d3e8186ad4180 268928 libdevel optional libecpg-dev_15.4-0+deb12u1_armel.deb 7197a384b4fa9c29b40fb9797d45fae3 110568 debug optional libecpg6-dbgsym_15.4-0+deb12u1_armel.deb 69e376fc9bdb77d7043a2d5fb8b3e264 51592 libs optional libecpg6_15.4-0+deb12u1_armel.deb a798c25e5386c8f1961b1e28744ea3aa 86544 debug optional libpgtypes3-dbgsym_15.4-0+deb12u1_armel.deb b172bd079d65b0c4283bfd8bacdae6cd 38164 libs optional libpgtypes3_15.4-0+deb12u1_armel.deb 49e6e5be744e813fae258b46c927723d 129236 libdevel optional libpq-dev_15.4-0+deb12u1_armel.deb f4e5aa70b25b62bffe54e676b2d1b1cd 269412 debug optional libpq5-dbgsym_15.4-0+deb12u1_armel.deb 5b4104b0f15d7ddd2a9eee10372f9c1d 166248 libs optional libpq5_15.4-0+deb12u1_armel.deb a67b9c3327a6162ed7ec1f86207849c2 15962496 debug optional postgresql-15-dbgsym_15.4-0+deb12u1_armel.deb 41ac223031e04157d1ebf75504e4dd04 16719 database optional postgresql-15_15.4-0+deb12u1_armel-buildd.buildinfo 0b2b1b5e51617dfc2e5718df84b75808 15946584 database optional postgresql-15_15.4-0+deb12u1_armel.deb 14d9b534a8c71cd5df0a31a60492f370 2222816 debug optional postgresql-client-15-dbgsym_15.4-0+deb12u1_armel.deb 8f945de755aa7d98b79cd94836cd36fc 1594232 database optional postgresql-client-15_15.4-0+deb12u1_armel.deb 49f02d9c89c0437403d2f3d81af5ef95 181840 debug optional postgresql-plperl-15-dbgsym_15.4-0+deb12u1_armel.deb a519680b822579fe6be701f4a27a1866 83528 database optional postgresql-plperl-15_15.4-0+deb12u1_armel.deb 41e9ee2d01f27a62cc6fd72a6d44cccb 171832 debug optional postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_armel.deb 1493f148b7349ad6fb2c8007f0208f47 102632 database optional postgresql-plpython3-15_15.4-0+deb12u1_armel.deb 9a053d0ffb73af0ba84a8ca1f7545ca9 77876 debug optional postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_armel.deb d10a4d8d23e8b9083cef64a5d0262d1a 36048 database optional postgresql-pltcl-15_15.4-0+deb12u1_armel.deb d48a420fe7ce6299999046fd3f90ceb6 1122484 libdevel optional postgresql-server-dev-15_15.4-0+deb12u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEU5Ohx66NeEdc9V4jWTHLDRjMKsQFAmUn0sQACgkQWTHLDRjM KsTFcA/+PHs5Gx6IyFT5i+dFFK80xRGOHYnp9bgTyBFJBmRCUJ9F6zXnHn8OzePI FwkWzeP1iRdyMX9ywrfK0SvxsE9IFj12lluHaLF1HJVrbrBgtm7LnXV24D6LxcPQ 4+DwOnmwOrnmP2Es6E9wNcU7UWK2XnBlxfIjAmNrmoMzAwUOC0MoNCr4p4HQcEvW Id5EGa+9AzbzuHCy5sfOCC5t1o+SlbcE2RT2pey0smhnjqrEOgbVAMDD8IFG2+RZ b/VDQ8opFWtvljt3+k33bSsSOPIOqj0gTRINP2Vd+YahKMxmk4u0GsOZ06hILIqT pOiSU252DksiTbO5mQKindJBfyvmM8Bf5yQ5Fso8G+I48Un05j6F81uYY+MxA6su YC6fDuZ/6+cvSKyHTQgmbYJUyDHjAKxaiH85Y6dqxta34mie7f9ndssvLQBnlEyq LW/NoAE0EZHR+MfdevFEd667z3X4Zz+TvqdAmO3Y+x+ff344BMCgi/MJq2sPhMkg oEEGbne3STTelH0h1q600uqYfeetxk+IS9iVlbc6J/sR+JCXVO06UbXt7BD78y9z d7lSe1kLyE+esp4O01/2SlqyfyJ6MDRl1T6MvXP7nvjkNy1QLHiJeHA8O30ymxhS WLa9KlZeQRdqeUVsxVnpb9EwP6SAslH6iI2Icpdo2HIUMksV4mI= =7HHL -----END PGP SIGNATURE-----