-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 01 Oct 2023 21:50:06 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: ppc64el Version: 15.4-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-osuosl-02) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.4-0+deb12u1) bookworm; urgency=medium . * New upstream version. . + Disallow substituting a schema or owner name into an extension script if the name contains a quote, backslash, or dollar sign (Noah Misch) This restriction guards against SQL-injection hazards for trusted extensions. The PostgreSQL Project thanks Micah Gate, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem. (CVE-2023-39417) . + Fix MERGE to enforce row security policies properly (Dean Rasheed) When MERGE performs an UPDATE action, it should enforce any UPDATE or SELECT RLS policies defined on the target table, to be consistent with the way that a plain UPDATE with a WHERE clause works. Instead it was enforcing INSERT RLS policies for both INSERT and UPDATE actions. In addition, when MERGE performs a DO NOTHING action, it applied the target table's DELETE RLS policies to existing rows, even though those rows are not being deleted. While it's not a security problem, this could result in unwanted errors. The PostgreSQL Project thanks Dean Rasheed for reporting this problem. (CVE-2023-39418) Checksums-Sha1: 79a427997885b647c2ac251f455df4e269546838 38840 libecpg-compat3-dbgsym_15.4-0+deb12u1_ppc64el.deb 6c9c2f87430aad7382bc6dd0f2b42849c15f31b0 21372 libecpg-compat3_15.4-0+deb12u1_ppc64el.deb 5abc5269ae304f2ddc5271c6ac9f25f190ac7688 223344 libecpg-dev-dbgsym_15.4-0+deb12u1_ppc64el.deb def79201e23867d684ac32edde2fcad7bff10109 295852 libecpg-dev_15.4-0+deb12u1_ppc64el.deb 7adb6fe1b142781ecbd5deb0160a486b39fe576b 113188 libecpg6-dbgsym_15.4-0+deb12u1_ppc64el.deb 4836fb00d8b4a60562ed88d935950bc3c43301bc 61780 libecpg6_15.4-0+deb12u1_ppc64el.deb 8c9f582612cc19eca392ec897746aff24d29b52d 90884 libpgtypes3-dbgsym_15.4-0+deb12u1_ppc64el.deb e4f518cbc3c9c8d4aa8124f33bc4e57bf783b6aa 45576 libpgtypes3_15.4-0+deb12u1_ppc64el.deb 02faf39b56e01bdcc8bc53543089334a5080b868 153552 libpq-dev_15.4-0+deb12u1_ppc64el.deb a93367d93ac5834c07055d38d6ce611aa8158825 285192 libpq5-dbgsym_15.4-0+deb12u1_ppc64el.deb d22ab117c01ae117fcd80d4305d15a5772b1ab66 196372 libpq5_15.4-0+deb12u1_ppc64el.deb 5ae0524996167dd4dd0d387393c4b6626f9c7c28 16536332 postgresql-15-dbgsym_15.4-0+deb12u1_ppc64el.deb acfa812855dfd8be20ffc242abd0f75d1b908c60 16962 postgresql-15_15.4-0+deb12u1_ppc64el-buildd.buildinfo 0d9f0449cc5d36e1d0b0f97e2daadf01673e1f0d 17007820 postgresql-15_15.4-0+deb12u1_ppc64el.deb 3a6ca161eed119dc259a0dfebdd78888a4fc4a1c 2314216 postgresql-client-15-dbgsym_15.4-0+deb12u1_ppc64el.deb cef3fdd3ec976962ee2590aeeb261f6d88fb3184 1719296 postgresql-client-15_15.4-0+deb12u1_ppc64el.deb b3e2ac414da9381eebb4058dd4dc0b9634a9af86 186416 postgresql-plperl-15-dbgsym_15.4-0+deb12u1_ppc64el.deb ff6d5db653375dc6742172021ef929059a0bc2a4 87696 postgresql-plperl-15_15.4-0+deb12u1_ppc64el.deb e46dd713e4aafefda0208d550a31d783c4622629 176108 postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_ppc64el.deb 5f40251c1f2de39e1e8deb0a1c62940efafc59fd 108452 postgresql-plpython3-15_15.4-0+deb12u1_ppc64el.deb a213b176dc5a6f5c36724aabc225b65f98266d3c 79932 postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_ppc64el.deb daa69bc624673bf739dbd82475e586e9a15f36ae 38924 postgresql-pltcl-15_15.4-0+deb12u1_ppc64el.deb 1903d4b59caf78069a046e813a344c1297388022 1150748 postgresql-server-dev-15_15.4-0+deb12u1_ppc64el.deb Checksums-Sha256: 9ad2601631fe042dfe932a205294c84275ec642c813cd66e0a2886e4e3f3308f 38840 libecpg-compat3-dbgsym_15.4-0+deb12u1_ppc64el.deb 2435681f71b26f9f92cf6602a5c65c7f9efab00b54a0a495489d8fad4e929e46 21372 libecpg-compat3_15.4-0+deb12u1_ppc64el.deb 6d097575db7aadda9340989c4bd05becb9d15fe539bd97b21b6446bb8a66f623 223344 libecpg-dev-dbgsym_15.4-0+deb12u1_ppc64el.deb e5d044cdd795860f677dabb4b51b25df229f564d2a64a627e8d61a201cbdd129 295852 libecpg-dev_15.4-0+deb12u1_ppc64el.deb 4460b9a09b0b14663d09540543d782eb2304ae86881ea6addaf53f114a81045e 113188 libecpg6-dbgsym_15.4-0+deb12u1_ppc64el.deb cc05a3533b3ea518d6a8f6a4000ef4eee6f850021085c614d2aaba5029933440 61780 libecpg6_15.4-0+deb12u1_ppc64el.deb fdfcff557f667dd47ac73a771a82bb17f355ddefe32744d91647b90a5180384b 90884 libpgtypes3-dbgsym_15.4-0+deb12u1_ppc64el.deb 4aff22879945b4c5ad5345a06fc0d3a41c21bce1600b41808ed1ed79ab992248 45576 libpgtypes3_15.4-0+deb12u1_ppc64el.deb 99524e3a10fce7be0ac98c9f1c8d162366ef021dd00af6333c6fd201dff54006 153552 libpq-dev_15.4-0+deb12u1_ppc64el.deb 0cf7a3892eea140b10bb1edf23605d1926b84d33b930376af3f45ed01b3a072d 285192 libpq5-dbgsym_15.4-0+deb12u1_ppc64el.deb d830dcbb63967d990c5e9dd8d669fedb393e6763363a40ff1925a41a1c9a4ecc 196372 libpq5_15.4-0+deb12u1_ppc64el.deb 8c49ff2ab19d2827696175d37ca578259b3fe42b9a3a7500a9cbbe33b86556be 16536332 postgresql-15-dbgsym_15.4-0+deb12u1_ppc64el.deb 39a26fe91c7f00eb8a43076eeb44e5e07c8bf39d58dbe48f4447788f2b9f85e6 16962 postgresql-15_15.4-0+deb12u1_ppc64el-buildd.buildinfo 719575e9cffdb1e3e8bda54ef58e01bbdff60328372ccbea277e7d4d80be6901 17007820 postgresql-15_15.4-0+deb12u1_ppc64el.deb c39b43fcd05cbd4a246af25a0276193e5a86075c02558d3d9b99653ae86cdaad 2314216 postgresql-client-15-dbgsym_15.4-0+deb12u1_ppc64el.deb fe6190773ff0fa000c569cababa52bbf18e9ab9bf1abfc2cf5aec3b38dce1d48 1719296 postgresql-client-15_15.4-0+deb12u1_ppc64el.deb a41f40e830904a0abb4a9d952c7b794fb93d3ae8f67fa1c78e4fa0fa766f1935 186416 postgresql-plperl-15-dbgsym_15.4-0+deb12u1_ppc64el.deb ee99355799eca98a665d1e6f0bcbc5ef4483003da5d8ef0c53e9fe5a73b28744 87696 postgresql-plperl-15_15.4-0+deb12u1_ppc64el.deb 6c37ef59c535abc0c95ccd8eb5700eb537eaaf82bdbbd926958444a12f45103d 176108 postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_ppc64el.deb bb31f89424fc2d822cac22cb99e4dcffc089a2d46c6d83afcd141fba4d7f8b46 108452 postgresql-plpython3-15_15.4-0+deb12u1_ppc64el.deb 696d11946a57f3dc82907e2d5b7596df47ebe95b0ed094f5dd0275a914bdc2c5 79932 postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_ppc64el.deb 9684bd8bd5709c08637a11da32765f3f6b6beba9660d961e8a11e02217520da4 38924 postgresql-pltcl-15_15.4-0+deb12u1_ppc64el.deb e64025b1f3c0a124500c3805754d0d385e317836303e4fda150406c9d5f64353 1150748 postgresql-server-dev-15_15.4-0+deb12u1_ppc64el.deb Files: df77df54aacab262a1c82a6502f03d04 38840 debug optional libecpg-compat3-dbgsym_15.4-0+deb12u1_ppc64el.deb e85665686156cb29904dc45963e85b8a 21372 libs optional libecpg-compat3_15.4-0+deb12u1_ppc64el.deb 6bb8aae7df4e2f5e072f2a6c384ad0a3 223344 debug optional libecpg-dev-dbgsym_15.4-0+deb12u1_ppc64el.deb 0894d85452db7cd04d66ad876a8be3eb 295852 libdevel optional libecpg-dev_15.4-0+deb12u1_ppc64el.deb 3b8a2adb1447c147fca49469f069383e 113188 debug optional libecpg6-dbgsym_15.4-0+deb12u1_ppc64el.deb 0ce7ee9c8fc7ee93229c58e749c3b948 61780 libs optional libecpg6_15.4-0+deb12u1_ppc64el.deb 3dbeffa940a6886fe782b9d4bfd1b2d5 90884 debug optional libpgtypes3-dbgsym_15.4-0+deb12u1_ppc64el.deb 0e052236eb8c65e66ce988b0a0533b97 45576 libs optional libpgtypes3_15.4-0+deb12u1_ppc64el.deb e41b932e3c74a61cfd3ecd7a4d2bb577 153552 libdevel optional libpq-dev_15.4-0+deb12u1_ppc64el.deb c60697ccb2b7d1a737ec1da95f952579 285192 debug optional libpq5-dbgsym_15.4-0+deb12u1_ppc64el.deb 6087516d1eb677deb124fccfdff76a6c 196372 libs optional libpq5_15.4-0+deb12u1_ppc64el.deb 71d99b953355527e6ed7d89f7e1f9bb3 16536332 debug optional postgresql-15-dbgsym_15.4-0+deb12u1_ppc64el.deb f4be8d6347de4c50b8d3ebf2373f22ca 16962 database optional postgresql-15_15.4-0+deb12u1_ppc64el-buildd.buildinfo 1591cdce1159dd515c52057bd0b5d3cd 17007820 database optional postgresql-15_15.4-0+deb12u1_ppc64el.deb 00fc31c38b592d9c0d9cf22747af66e5 2314216 debug optional postgresql-client-15-dbgsym_15.4-0+deb12u1_ppc64el.deb df2569da81e9d1a419086c496af27b28 1719296 database optional postgresql-client-15_15.4-0+deb12u1_ppc64el.deb 2bca1fbb414a55a283d1c72d36898fe5 186416 debug optional postgresql-plperl-15-dbgsym_15.4-0+deb12u1_ppc64el.deb 413a1c6c133862bef8a4ff20eda810b2 87696 database optional postgresql-plperl-15_15.4-0+deb12u1_ppc64el.deb c439c0a7941454aef0e94903ba01f955 176108 debug optional postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_ppc64el.deb a8c643e66ba9811f9599ee3bc4d9ebfd 108452 database optional postgresql-plpython3-15_15.4-0+deb12u1_ppc64el.deb f626674493b5f755fe8619f855cf19fa 79932 debug optional postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_ppc64el.deb 8d1a61ecd649a832b35283b338ca8c5c 38924 database optional postgresql-pltcl-15_15.4-0+deb12u1_ppc64el.deb 0be2d081588ef56303fdf286baf2502c 1150748 libdevel optional postgresql-server-dev-15_15.4-0+deb12u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEHDNCkvGgp2XShfnByW8ECaj2byoFAmUnusoACgkQyW8ECaj2 byqarhAAnyh3MafiF4CsljPgzXTchyXky0v++XQPCN/e63gmd0tnxkVDjBkfl/44 0N7FrnMVMpTOtCDtlmnOyy7C3MV5yo6WWfTwxbRN6qRBwx/p4uvyRthTkeGFOppH p7B/h7/zPIwOtliCM1+TVuul1LkLsNmJdfS/dssh9y/PJd475ZkVa0+RU5td56a6 bP6593+Y9Tb+YYiwFOSlTw4zqr6PG4uqMmQBmT71bDozWSRAHw5YcmyVIwjaj4un wHt+Veuo22lbbYx3sT4eAYZAoS4gKoEfz0mlycDGVsNM9sc8VUi0LAInQZcE6QkU UBu4HM//ZxXNLAMjhq8vwVBjZjy71zKC5SDCtcRAb+KR/Vdd2Bnm0wAQgTnUekxF HMZsRkeKscVICj5jMEp53Ipv2teOstossmiqxffCFGQNWH6eSx5KGv3Dfw4vZ7Rn 4qfMfMIp5UiduiaPQD+5m+kV8psY68GCfRWzPwQfPU/COOGzLPeWbbJjpahggfEf kYah0u3mRupHe/dYugtMEOnC/4aWx8u5SJt21FrfQVu+gC4YmMAgyhx/UOGPco1Z d8jCz57/CDparczmjXNRnfOZt0wSaj4gZaAGZP66vPI+1AXAO+zJgFfSxKQ9q4Qi jj4d7QHS3Wo33qQcaGspHk9PNwb2DOqSckl5dM0jSD72IuzfNOc= =2X5p -----END PGP SIGNATURE-----