-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 01 Oct 2023 21:50:06 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: mipsel Version: 15.4-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-04) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.4-0+deb12u1) bookworm; urgency=medium . * New upstream version. . + Disallow substituting a schema or owner name into an extension script if the name contains a quote, backslash, or dollar sign (Noah Misch) This restriction guards against SQL-injection hazards for trusted extensions. The PostgreSQL Project thanks Micah Gate, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem. (CVE-2023-39417) . + Fix MERGE to enforce row security policies properly (Dean Rasheed) When MERGE performs an UPDATE action, it should enforce any UPDATE or SELECT RLS policies defined on the target table, to be consistent with the way that a plain UPDATE with a WHERE clause works. Instead it was enforcing INSERT RLS policies for both INSERT and UPDATE actions. In addition, when MERGE performs a DO NOTHING action, it applied the target table's DELETE RLS policies to existing rows, even though those rows are not being deleted. While it's not a security problem, this could result in unwanted errors. The PostgreSQL Project thanks Dean Rasheed for reporting this problem. (CVE-2023-39418) Checksums-Sha1: 2b63eeefa55ea120c4d460f1f6f27a446f819b4a 39524 libecpg-compat3-dbgsym_15.4-0+deb12u1_mipsel.deb c8dc62d268c394c31b76b2af1c29e19f96aec9ba 18908 libecpg-compat3_15.4-0+deb12u1_mipsel.deb bb460766417ffbb2d9fc64824d39991b02c233b9 261876 libecpg-dev-dbgsym_15.4-0+deb12u1_mipsel.deb 9c83334f138ac630cac47fc84d581b90ab4eedcb 279184 libecpg-dev_15.4-0+deb12u1_mipsel.deb 1deb56fd159d8f089f103373e886b2611aa24f6e 114920 libecpg6-dbgsym_15.4-0+deb12u1_mipsel.deb 93aa673eff0544502df27439874a29dca6b80305 55292 libecpg6_15.4-0+deb12u1_mipsel.deb a2539f222d3c7a7bee2ea76f09d9372aaad0f7a2 91608 libpgtypes3-dbgsym_15.4-0+deb12u1_mipsel.deb ff4bb3b6b80f53311c61f7e60d075deb57654d3f 40652 libpgtypes3_15.4-0+deb12u1_mipsel.deb b3fdf63bcf6e13d541fc022b2c5e9bfb269c97e7 146064 libpq-dev_15.4-0+deb12u1_mipsel.deb 7ab7fd029cb393278a1c879424bd3bc5cf42479e 282548 libpq5-dbgsym_15.4-0+deb12u1_mipsel.deb ce3c571f92718ee9eaba76c45e3283b40c0a99dd 173056 libpq5_15.4-0+deb12u1_mipsel.deb c5e58c499a6e8addfa9a43b37b0401209179bddb 16475988 postgresql-15-dbgsym_15.4-0+deb12u1_mipsel.deb 7fedd093fcf7c81db0e0e9c797bc94fabf27e86c 16735 postgresql-15_15.4-0+deb12u1_mipsel-buildd.buildinfo b59fd6fb7e0d077c11649e710014b7cd72248d78 16120032 postgresql-15_15.4-0+deb12u1_mipsel.deb dacf7c1f8e2d0a35b2f2bfc4c3744eeea725cf45 2333208 postgresql-client-15-dbgsym_15.4-0+deb12u1_mipsel.deb 9160f3093b70a3288b06c13f038bd7fa36452892 1637588 postgresql-client-15_15.4-0+deb12u1_mipsel.deb 7db77c53fb44bde7b9f84d330b1954fe8ea43d00 184612 postgresql-plperl-15-dbgsym_15.4-0+deb12u1_mipsel.deb 7a21a997ffeac5152f777ae5d7dbce50bd0dc6d8 82040 postgresql-plperl-15_15.4-0+deb12u1_mipsel.deb 8553e60bfd4a207dfa5fae224e0abfc3e4d3e874 175408 postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_mipsel.deb 779b584ad27f5d165e4f6715675e945d7dfcb1d9 100960 postgresql-plpython3-15_15.4-0+deb12u1_mipsel.deb aae3b281e47ffb35a1294f00ae8daecfa38e5098 79952 postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_mipsel.deb e59ca97cc094c7bf115e69d225992eadd5227be9 36256 postgresql-pltcl-15_15.4-0+deb12u1_mipsel.deb 4d36484aae5f9f5ee21d750c0d6ac80e01e73acd 1144456 postgresql-server-dev-15_15.4-0+deb12u1_mipsel.deb Checksums-Sha256: bcf2ba3b9ba1701587768b5c1e33541e8568910dd562145297292b232673cb4e 39524 libecpg-compat3-dbgsym_15.4-0+deb12u1_mipsel.deb 47757ecaf2a77f6bf8832786a75c1fe90f508404947ff400d05941eb45433a9f 18908 libecpg-compat3_15.4-0+deb12u1_mipsel.deb dfb6371617e6087796b64a67097f310061cce8031b74f3063fae63a997bcce03 261876 libecpg-dev-dbgsym_15.4-0+deb12u1_mipsel.deb b932dfb488333dabf69914303d6d529720e16f5474c690503a444d961cc74103 279184 libecpg-dev_15.4-0+deb12u1_mipsel.deb d9bd134276d7646b0ca2bd3eac722db029dec11796d64332c2ff144b2efecd23 114920 libecpg6-dbgsym_15.4-0+deb12u1_mipsel.deb 50c8c4d8b2289612a47123c53143fb5814d8b6e2378d5d48c1c3bc2a83d20b6d 55292 libecpg6_15.4-0+deb12u1_mipsel.deb b905b238bdf92438c78a1492e381daa1490c0b794006771ff7ab21e6a578d7a5 91608 libpgtypes3-dbgsym_15.4-0+deb12u1_mipsel.deb bb4d07f983b07e03805861102a899ab6bb869a4f8ed82bac1ab342a7567a2a10 40652 libpgtypes3_15.4-0+deb12u1_mipsel.deb 3c000a28529bc727adb85121a4870dbfe70b442aa8992edea41cca70344da441 146064 libpq-dev_15.4-0+deb12u1_mipsel.deb 0ba6fc6077be972aacd0877995799182ba2791dd8659d957ff343eefa4d00a6e 282548 libpq5-dbgsym_15.4-0+deb12u1_mipsel.deb 79cc4035dfbde66baa745103a408755f7ccca0a65d9e0eb387005c2a51576c95 173056 libpq5_15.4-0+deb12u1_mipsel.deb 38ee7322e22eadd760ad9c214a9387abccb2469a6ff83fdbcc7eec9b2df906e4 16475988 postgresql-15-dbgsym_15.4-0+deb12u1_mipsel.deb 081f1948de94d4d7aaffaa7562b08b7e4df13755107fca4ce02754f8762ea49e 16735 postgresql-15_15.4-0+deb12u1_mipsel-buildd.buildinfo 7f018f71a14042ef1fad747eb8bcf9c421e721fb63f6cc1bd270976e19532c5f 16120032 postgresql-15_15.4-0+deb12u1_mipsel.deb a140cda118f7edbf4f6d3f31bd9e8fd6ea1decef77be274e60411ef1de27fc75 2333208 postgresql-client-15-dbgsym_15.4-0+deb12u1_mipsel.deb 3c1135a106aee545d8dcae4f3274a399e1c391041cfc0a4e2290d35fa0916ac5 1637588 postgresql-client-15_15.4-0+deb12u1_mipsel.deb 0dba558a0b58c8bc1a345b404101735b121f6d911af93c5ebc973769ae57e7d4 184612 postgresql-plperl-15-dbgsym_15.4-0+deb12u1_mipsel.deb 5d8f6958efbbcb2b612a0dcb1fdfe24f319518e867c64d2ff00b795f7e61ce66 82040 postgresql-plperl-15_15.4-0+deb12u1_mipsel.deb 4035e45a56e5339680c2b4446eaee9a971cad51578365cb1734b209212a721b4 175408 postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_mipsel.deb f3d66c0753a06d20c549318b5752bdae160ac7436d48b86f80de8d338d154148 100960 postgresql-plpython3-15_15.4-0+deb12u1_mipsel.deb 53e60616e2ac07a34fb6a9d7ff0fd71964e49b8336a048e5e3b9b2c3ecfc7fa9 79952 postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_mipsel.deb ef17b1d03fae662caebcae49f434005c50f1e180d5153a85d86a9e9cf8ce6212 36256 postgresql-pltcl-15_15.4-0+deb12u1_mipsel.deb edcb9fc8a051286664b071feca61a57b0ec49ed95656e59fe99375dc59a54d2f 1144456 postgresql-server-dev-15_15.4-0+deb12u1_mipsel.deb Files: aa59029ca8ff948e382ca50d00318645 39524 debug optional libecpg-compat3-dbgsym_15.4-0+deb12u1_mipsel.deb 13e5a188a759cc2739493eff1eb4da06 18908 libs optional libecpg-compat3_15.4-0+deb12u1_mipsel.deb 36c0d91175c1ea56c50bb63753ff2f8d 261876 debug optional libecpg-dev-dbgsym_15.4-0+deb12u1_mipsel.deb 93a259276466cc190a264f7569ae9288 279184 libdevel optional libecpg-dev_15.4-0+deb12u1_mipsel.deb 81ba96491067d674349a57ee0450bc59 114920 debug optional libecpg6-dbgsym_15.4-0+deb12u1_mipsel.deb 4dca1b20e4c75307ba1d93b8d82a077a 55292 libs optional libecpg6_15.4-0+deb12u1_mipsel.deb 08011ff84b6a365e67ee7d136de007a0 91608 debug optional libpgtypes3-dbgsym_15.4-0+deb12u1_mipsel.deb 490340866bb7d15473ef361d36da51aa 40652 libs optional libpgtypes3_15.4-0+deb12u1_mipsel.deb 29ad26c79fc3e7d378bf5910af59730a 146064 libdevel optional libpq-dev_15.4-0+deb12u1_mipsel.deb 344e9e0cd1d5ab5f422145605af58faa 282548 debug optional libpq5-dbgsym_15.4-0+deb12u1_mipsel.deb d12d4ce996aeb2d88cffb86284d524e3 173056 libs optional libpq5_15.4-0+deb12u1_mipsel.deb ecf775d90385b9845db7b278e334bdd9 16475988 debug optional postgresql-15-dbgsym_15.4-0+deb12u1_mipsel.deb 96d19457366ab203f803129ca2840596 16735 database optional postgresql-15_15.4-0+deb12u1_mipsel-buildd.buildinfo bc775d7ba2d7a9b4899ecf3ad4721ce1 16120032 database optional postgresql-15_15.4-0+deb12u1_mipsel.deb 5b396026de1179ea604621a3141e4ed3 2333208 debug optional postgresql-client-15-dbgsym_15.4-0+deb12u1_mipsel.deb 04706167f4d1818476b054eca66e21ce 1637588 database optional postgresql-client-15_15.4-0+deb12u1_mipsel.deb 114213aa43fb788fbeb4226e724b0d20 184612 debug optional postgresql-plperl-15-dbgsym_15.4-0+deb12u1_mipsel.deb beded5a02f9bf413acad11cbaa6150f7 82040 database optional postgresql-plperl-15_15.4-0+deb12u1_mipsel.deb 7d038c8be25f41d0f8f35136b9da6892 175408 debug optional postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_mipsel.deb 5ff0364a01d4d1fe369eea7ba18df4ad 100960 database optional postgresql-plpython3-15_15.4-0+deb12u1_mipsel.deb 032733f0852d6b1a1f425a5c701f4e0b 79952 debug optional postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_mipsel.deb 003ff0e217125bab173ab60c996a641b 36256 database optional postgresql-pltcl-15_15.4-0+deb12u1_mipsel.deb 928485d3ceb5ed42916ca9d20143e808 1144456 libdevel optional postgresql-server-dev-15_15.4-0+deb12u1_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEEmZlxOBLdXDBxnwAL00bee7O74EFAmUn3SkACgkQL00bee7O 74GMURAAj235lDomkIeX1s1c7wssSbGEFafJG4LKma3LHVWohmW94lXdRN0IbnPF 6uJkRJzX9qXgUXkyiYHpRgVxddMJcTBZc66gYtVci9Qae6023L/YCpdOP+oSbGGK z3AJnPLo65bjPhmcv5OzSwCgU8EqDoPTM56rK6O1uf8ZQyvS5IXu9QkOPVt+jvoe 1Zseo2kez4UQjHLrtTWaLMc32/syKzgMJBjFsl/6U5UsElrWwqYu2B70D/W4/KcM vmrWAThALkHgrg9EYBVo8VHH4/VCVqeVf22q+J6I13ZjQWt/9QfQPNZP+afCRO3F VDQIu5RYk+qiqMymg2fzwPrNfEXZ3/eq9JEMKYb4hqXMWLRPx4rlHyuJVKIn3TLY iag1CSi2W9UBQCOKCiUj4LVH3x/Qg5erVeu0GAisJz0Z03pVlTbrjFDntv7WpKqL zLD2Dk5X0q0INZ3AgM4BY4eoB93VO6is1lBgIzVWM9IKnuqkoq46NzUELh+H9hIu R3DvjR9VMki2XucWPSmUVdESEhGCXtBIXZCxl4oiMbQRWW3kcFfWrYEiEvNrBKkT gkZ2qWIZGHvmaRM4G3D/DnrJZsuYAdPGpS7HqfQ9zZS7UuwfDEjSsqN1x8gcXxOp VwLxcOEva6ExifaEG8Itd0TTke2FC+MCSGzieB2XOhsSy8SMIK0= =ODvC -----END PGP SIGNATURE-----