-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 01 Oct 2023 21:50:06 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: i386 Version: 15.4-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-02) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.4-0+deb12u1) bookworm; urgency=medium . * New upstream version. . + Disallow substituting a schema or owner name into an extension script if the name contains a quote, backslash, or dollar sign (Noah Misch) This restriction guards against SQL-injection hazards for trusted extensions. The PostgreSQL Project thanks Micah Gate, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem. (CVE-2023-39417) . + Fix MERGE to enforce row security policies properly (Dean Rasheed) When MERGE performs an UPDATE action, it should enforce any UPDATE or SELECT RLS policies defined on the target table, to be consistent with the way that a plain UPDATE with a WHERE clause works. Instead it was enforcing INSERT RLS policies for both INSERT and UPDATE actions. In addition, when MERGE performs a DO NOTHING action, it applied the target table's DELETE RLS policies to existing rows, even though those rows are not being deleted. While it's not a security problem, this could result in unwanted errors. The PostgreSQL Project thanks Dean Rasheed for reporting this problem. (CVE-2023-39418) Checksums-Sha1: 290c99b2c84899991ffa9e768b18f7ffb6109360 34612 libecpg-compat3-dbgsym_15.4-0+deb12u1_i386.deb 5a99087ae8cf0c0ed90a45776b37f49865d30110 20760 libecpg-compat3_15.4-0+deb12u1_i386.deb 6b239b85faf11e82bcbc8a9efcc60997622c24d8 271756 libecpg-dev-dbgsym_15.4-0+deb12u1_i386.deb c7b2cb9db6e0c27ca7644924ad4a796fc212da85 302676 libecpg-dev_15.4-0+deb12u1_i386.deb 0b83b39ba8aac387f786e6b86f8d70903fb836db 101804 libecpg6-dbgsym_15.4-0+deb12u1_i386.deb 02f2ae0f2c8b57005e0be3ac0e63010ed59fe295 61960 libecpg6_15.4-0+deb12u1_i386.deb e9e130f11b4a9d4df72e3d390ef54a7a206850d2 80800 libpgtypes3-dbgsym_15.4-0+deb12u1_i386.deb 6fced10869cbe41ac1a24d95ad660591da4a8538 43804 libpgtypes3_15.4-0+deb12u1_i386.deb 48ce6ed35682d95a9f46a707d02c765d825ff7a9 150036 libpq-dev_15.4-0+deb12u1_i386.deb 112f2f1de7b27171a0421db06f8a8223529293e8 241148 libpq5-dbgsym_15.4-0+deb12u1_i386.deb 2a967a6e0fd316304ed6953590dda4bfe2cf2b73 192804 libpq5_15.4-0+deb12u1_i386.deb 9a3a6a4cb26a69fae362e9d8ff2693ca20a3d360 15131520 postgresql-15-dbgsym_15.4-0+deb12u1_i386.deb cc7a40054721505998b346d603ca1f7deec05368 16748 postgresql-15_15.4-0+deb12u1_i386-buildd.buildinfo 20b5a4431df672183d3e914fce54ebf3833a2448 16882136 postgresql-15_15.4-0+deb12u1_i386.deb f128f34408834df750f5d696d2de00ca060db255 2058456 postgresql-client-15-dbgsym_15.4-0+deb12u1_i386.deb 3d335d8da100a0a2144b6f30e94cf1202c0cde31 1715892 postgresql-client-15_15.4-0+deb12u1_i386.deb 051d15e7cc6ab4104375b3cf3c48bf272edabb6d 173868 postgresql-plperl-15-dbgsym_15.4-0+deb12u1_i386.deb 188838c93c4cf58b6e4ca101d8632139f7d18b9b 90276 postgresql-plperl-15_15.4-0+deb12u1_i386.deb 3ce83cbae283c74096cf839a5126a121c2edc801 163392 postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_i386.deb c40199c0ad89389a56d21dd8d17647eac895ba38 111020 postgresql-plpython3-15_15.4-0+deb12u1_i386.deb ce2bb060636e7eec0617b6ce31589a74befccffa 74056 postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_i386.deb c15a9013c203a1c5fc8326fa2c927041cc3f17c4 40252 postgresql-pltcl-15_15.4-0+deb12u1_i386.deb 593652e27d9f4fc9683d06d656f8ad7da241f69f 1152540 postgresql-server-dev-15_15.4-0+deb12u1_i386.deb Checksums-Sha256: 317a0d0cab86aa632b3ddb5fe355e466a9d069819b46ff32cb6ff7a802047b52 34612 libecpg-compat3-dbgsym_15.4-0+deb12u1_i386.deb fa6c7f075b1061cb61266c8eecb48e2e7e0f682960f082c1a6bbbcfe3b1c16c2 20760 libecpg-compat3_15.4-0+deb12u1_i386.deb dc99eecea295ba4dfa48a9d5abde13d86c6d583118c853b4850254c5ebed0466 271756 libecpg-dev-dbgsym_15.4-0+deb12u1_i386.deb 99ed167e8526f65fb0f2b2f52afa1af99919fa0203e5ab147b43694af447a068 302676 libecpg-dev_15.4-0+deb12u1_i386.deb db0d13f1d7207727e700ea4bf14195cff27dde9bbd49316fe6c193db472580fa 101804 libecpg6-dbgsym_15.4-0+deb12u1_i386.deb b61c30f65a0f3d1b5af02cfb59d980cf75db4c12fe1edfeb74740cd4ffbaf2d8 61960 libecpg6_15.4-0+deb12u1_i386.deb ad9ab7b7b8d941f688904df24cb91ac24894a9802c2d5e695f513d59f21d1fb4 80800 libpgtypes3-dbgsym_15.4-0+deb12u1_i386.deb 9575a7cb60705d13386629efcb9131a4bb0f9d4102064e520e2264c5f37699bd 43804 libpgtypes3_15.4-0+deb12u1_i386.deb 580d5f24a21e121e39b9f98327ed9ede4e243c84d4f32501395e52748f87fc57 150036 libpq-dev_15.4-0+deb12u1_i386.deb 5c6e4259f1f677438d5ec8926adbbb8bec5e37d45cfcf5e35b9bd42abf872456 241148 libpq5-dbgsym_15.4-0+deb12u1_i386.deb 5706d4b5b45420e76841fe430647d953bf21012e2afa167e7438ddd7b0a4828e 192804 libpq5_15.4-0+deb12u1_i386.deb ec3ca6f50bd6f7e1b6274074bee50b6e37bb7ed9bf3db5606878ec1446c705a6 15131520 postgresql-15-dbgsym_15.4-0+deb12u1_i386.deb b0220e03607c6261aaa977e9e7069b615aefe52ef3897aeed8d6a72a5c09a93e 16748 postgresql-15_15.4-0+deb12u1_i386-buildd.buildinfo 29035e1d6c3a9ecdc082d027b640c62ec64168482f6bde27e6055b9a9f5d4ddb 16882136 postgresql-15_15.4-0+deb12u1_i386.deb 744c81d07b38ce87cd8c6c0a4630b8c8e43c2746b8153ff022749fb2359dd2ff 2058456 postgresql-client-15-dbgsym_15.4-0+deb12u1_i386.deb 1a2c07bc2c9ab345e7d0d359cd48163d37ae717794f3b11bc0982e77ba34bda8 1715892 postgresql-client-15_15.4-0+deb12u1_i386.deb 998a0d2eb448742426488914e186e9449420b9922bdc924a752a7a0fe1ca46fe 173868 postgresql-plperl-15-dbgsym_15.4-0+deb12u1_i386.deb aec329a7b1c1f80348747362a913a2ae0dac7a62a6a8be5693c491d764f498e1 90276 postgresql-plperl-15_15.4-0+deb12u1_i386.deb 4a15d3e26c078da95886c090db51d3d094311940df99711b92242f2125b97664 163392 postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_i386.deb f009c9bd4d33ce48055acceba55a3de3bc547732570f77125731170159abfb31 111020 postgresql-plpython3-15_15.4-0+deb12u1_i386.deb b25b30fbd9b8a22d2d00a22521e58346924ca332b3b377f75cc878ba459be467 74056 postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_i386.deb ade0edff6ad43514f7bc493d48fcfecfff446087833d0d47146193d2af4d5d65 40252 postgresql-pltcl-15_15.4-0+deb12u1_i386.deb c12d8aa19838da5a36e9edb3f4943bc8174a6b3f85aab7cde44fe9c43fba7625 1152540 postgresql-server-dev-15_15.4-0+deb12u1_i386.deb Files: 60cc54916d2d37ef1bbb900e6a6556f0 34612 debug optional libecpg-compat3-dbgsym_15.4-0+deb12u1_i386.deb 94884a048f503f58e3dd81a3d3ad6744 20760 libs optional libecpg-compat3_15.4-0+deb12u1_i386.deb 7605286e6398f3265cf332662909cae2 271756 debug optional libecpg-dev-dbgsym_15.4-0+deb12u1_i386.deb f5635272477b3e059ae917cbc34d5cd9 302676 libdevel optional libecpg-dev_15.4-0+deb12u1_i386.deb 9e4eceae3672bf6fe3a44db25345f0e3 101804 debug optional libecpg6-dbgsym_15.4-0+deb12u1_i386.deb dda62db4cd4628db96566eaa95f1ba88 61960 libs optional libecpg6_15.4-0+deb12u1_i386.deb 69faec5452e50f3022a5fa6a3b010c80 80800 debug optional libpgtypes3-dbgsym_15.4-0+deb12u1_i386.deb 8d829a6b79c71e9fa5b067a91125337f 43804 libs optional libpgtypes3_15.4-0+deb12u1_i386.deb 6f4a7e89fde86d5228461eecb5264519 150036 libdevel optional libpq-dev_15.4-0+deb12u1_i386.deb c456f2886d6fd9afe65d066ccce6ac45 241148 debug optional libpq5-dbgsym_15.4-0+deb12u1_i386.deb 66d3ce359b46b9103c6eef49081382da 192804 libs optional libpq5_15.4-0+deb12u1_i386.deb 2e74fcf6b3a227c0a262351df4c562bb 15131520 debug optional postgresql-15-dbgsym_15.4-0+deb12u1_i386.deb b247cc22361a9eaeb8c5aefaead614db 16748 database optional postgresql-15_15.4-0+deb12u1_i386-buildd.buildinfo 0a613a986e96cd745f6e0f0c2d286ca3 16882136 database optional postgresql-15_15.4-0+deb12u1_i386.deb 24c8bf6b1459d4a49a87bb1f1fb6d9d0 2058456 debug optional postgresql-client-15-dbgsym_15.4-0+deb12u1_i386.deb 991c9e6e70ca197415296cb86b5a5b69 1715892 database optional postgresql-client-15_15.4-0+deb12u1_i386.deb ea46a76122f3cdd185da1d0bef5ece02 173868 debug optional postgresql-plperl-15-dbgsym_15.4-0+deb12u1_i386.deb e4cb16c89cd17aecfe96b1096ed230c4 90276 database optional postgresql-plperl-15_15.4-0+deb12u1_i386.deb f0ec8a51d9b90b302e00d4d386953a89 163392 debug optional postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_i386.deb 12b18e2a3bc6d6e31a2ef30f3aeb481d 111020 database optional postgresql-plpython3-15_15.4-0+deb12u1_i386.deb 0be398093d61241f6dbde1a9154765e7 74056 debug optional postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_i386.deb c0e0d6e610af7df83947aee06bc0016e 40252 database optional postgresql-pltcl-15_15.4-0+deb12u1_i386.deb c822a6735327f1a8401e2a28058b5a9f 1152540 libdevel optional postgresql-server-dev-15_15.4-0+deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEOtJZa9Q/HRv7PgxxkF7E12VCox0FAmUnvVcACgkQkF7E12VC ox3C+g/8DLpmSh/B+fAC6IC6keSAdpmX490bwI/6n1xyQ652noL6CH2OuXN2RB4j olnqtl8xs+JcVM2jOj6I2hIjK11MpHvLjurcxoi4kPiKp0rsJzvo3ERkspT5JyZS uySWa1EvEverEn0mWsiyt11CQf96YwjwgVp+AxTVT9v/CXyjrZkjnx1dSwlbOmcB 2Pr6pg+blWzIDnd3O5nZyF0wT3qZH/4JwhoSQbODGDmw5WWq/13YgocifU3QGdT9 gq9ROSJV9oAZGTmx3ZaSyZ/Q49OmiJKxCSpVm7XGa+PTGM9p090u6dwZQDt1P21B cfXNIs5+3HowrF1N0wGqbZ7gQrPaT5SPrhrNnGXL4Znd3BZ3q0zy5Zyiqc80TNbd x/tNGzy4LwqfkRgY/pUeUqgaMu7vSrGuirA2GD+0BIZSa1ha8w3y/Ep4QoSIEAYW sUR/yWbbsaku+V6qVeyQ6DmxMlVIcbFkZWE+OGq3Hv8orf289KTfvuuwniBtmRKa vqp0JijGnf4XYgvDlUqgb33HP8jYsNG2DhIprSu3fG87H/TqjsFCC2X9CfKboKjP Ld+aDv/LAHcyWFFIvFBYM9j3nSFFP5ugTcrvUClynkPVKqqC7NP7jK0FRxcoAYtI vfESJ+zlG8o+4/CDdYBpgFfvgMQez7Fr6j3W0/Doh/8agxZ73Ac= =TqRr -----END PGP SIGNATURE-----