-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 01 Oct 2023 21:50:06 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: s390x Version: 15.4-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: s390x Build Daemon (zandonai) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.4-0+deb12u1) bookworm; urgency=medium . * New upstream version. . + Disallow substituting a schema or owner name into an extension script if the name contains a quote, backslash, or dollar sign (Noah Misch) This restriction guards against SQL-injection hazards for trusted extensions. The PostgreSQL Project thanks Micah Gate, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem. (CVE-2023-39417) . + Fix MERGE to enforce row security policies properly (Dean Rasheed) When MERGE performs an UPDATE action, it should enforce any UPDATE or SELECT RLS policies defined on the target table, to be consistent with the way that a plain UPDATE with a WHERE clause works. Instead it was enforcing INSERT RLS policies for both INSERT and UPDATE actions. In addition, when MERGE performs a DO NOTHING action, it applied the target table's DELETE RLS policies to existing rows, even though those rows are not being deleted. While it's not a security problem, this could result in unwanted errors. The PostgreSQL Project thanks Dean Rasheed for reporting this problem. (CVE-2023-39418) Checksums-Sha1: 1e6952532af29506488a438cbf3495629e4cfabe 37884 libecpg-compat3-dbgsym_15.4-0+deb12u1_s390x.deb e8caff54f597435a40de4d9f67db14204648b3fa 19320 libecpg-compat3_15.4-0+deb12u1_s390x.deb 0aecc8b6d6b0dfa3fb000d597fb3942dc98e142e 214476 libecpg-dev-dbgsym_15.4-0+deb12u1_s390x.deb 8bd286ac4b11d374ade0f628f98180d12ab179ba 276664 libecpg-dev_15.4-0+deb12u1_s390x.deb eb979d809169ab00ad12c0fa8f032cc6d9de44cb 111944 libecpg6-dbgsym_15.4-0+deb12u1_s390x.deb 547e09011b9052ea1a60c8769b6409ea7b3767cd 55468 libecpg6_15.4-0+deb12u1_s390x.deb b144af5639fc619406b24b9c0829c68d647bf661 88368 libpgtypes3-dbgsym_15.4-0+deb12u1_s390x.deb 5a94422333b3be079ff73cad02e829ba8130d1b7 40524 libpgtypes3_15.4-0+deb12u1_s390x.deb 0128c321e6d35b6ae9f12eccc078007e55628d69 134136 libpq-dev_15.4-0+deb12u1_s390x.deb 34c01a461a5a788e392247ad7cefa2abd031e220 272144 libpq5-dbgsym_15.4-0+deb12u1_s390x.deb 732d84c3d2fa9853f1a61eed54536453dff2c544 174840 libpq5_15.4-0+deb12u1_s390x.deb 95c4a47cded4d9b49e91e00c48112cd1aa62ef77 15331952 postgresql-15-dbgsym_15.4-0+deb12u1_s390x.deb a26870018aa6c713c5c2ddf4917e5a2cd9f6339f 15800 postgresql-15_15.4-0+deb12u1_s390x-buildd.buildinfo bc85e7cdf9a91d429ef9efe552ba35a79e6dcc0c 5494008 postgresql-15_15.4-0+deb12u1_s390x.deb 95ef0251edd963f806813ae16ec199b2013c6b57 2234560 postgresql-client-15-dbgsym_15.4-0+deb12u1_s390x.deb 014fad69f82739c2c21cc815b98b96667b2f09b1 1633356 postgresql-client-15_15.4-0+deb12u1_s390x.deb 4a08eca76ae00706b099319b7ea15932feb8c95a 180460 postgresql-plperl-15-dbgsym_15.4-0+deb12u1_s390x.deb ce4bd5bbbf53b94c7e5aca639888e9160b57e525 61844 postgresql-plperl-15_15.4-0+deb12u1_s390x.deb bcfe2e3342315ddb30e1b2c2b9883eb1e0bb41f9 169952 postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_s390x.deb 210c36226616ef558e06180ee82ec79b4df5cc28 84796 postgresql-plpython3-15_15.4-0+deb12u1_s390x.deb 7df7350a894386efefeb6e306ceb43bbe100a500 77580 postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_s390x.deb daebc1d1afee836b341cfe1f4cae913b55a59b78 37360 postgresql-pltcl-15_15.4-0+deb12u1_s390x.deb 41156e419ac5afa424a7a8570102c75856f75101 1128752 postgresql-server-dev-15_15.4-0+deb12u1_s390x.deb Checksums-Sha256: cc5bd0edf1561beb808ce7e6a6bb9c5c28bad5cb36cae5fa888b80ff5b43323f 37884 libecpg-compat3-dbgsym_15.4-0+deb12u1_s390x.deb b74b1bf83023d7a4f3b1376bfd43e0531335a2adf8055240aed60899c5e3ae44 19320 libecpg-compat3_15.4-0+deb12u1_s390x.deb cedc2920c67f9ff2ece35e43711ff6392846f10ebbcb8a37e13a346e63fe4c9a 214476 libecpg-dev-dbgsym_15.4-0+deb12u1_s390x.deb 09242c63021b390ed5b7805d251f987282a90f646bd3fe6b8ef5b860f6e0b695 276664 libecpg-dev_15.4-0+deb12u1_s390x.deb 5e3cf57ef8aab33ec9be6e18f552883322fd8fde59d6f999c2cd6bf723047fcf 111944 libecpg6-dbgsym_15.4-0+deb12u1_s390x.deb 710d0eb2399da4467d6f2c7b01fc48cca88afa19ffd3f5aa27642d9f5590e969 55468 libecpg6_15.4-0+deb12u1_s390x.deb f477d1ca08fe620784d6374368097774d00912008467c62163bfd9b19a2522db 88368 libpgtypes3-dbgsym_15.4-0+deb12u1_s390x.deb 55990549ef2f9946f4e681065a4c0027437b3ce4a01bda02315b9e71ebbdf8c7 40524 libpgtypes3_15.4-0+deb12u1_s390x.deb d7c233cdb233287a7b71628267dbfcb25c536a383e3185e7f8be36577e052280 134136 libpq-dev_15.4-0+deb12u1_s390x.deb efda86ccc1221225efc75a62731b9b86e877faf41ee64f258a9a4b35e68c209e 272144 libpq5-dbgsym_15.4-0+deb12u1_s390x.deb 79b6285bb83a874ddd1901f32c76b03515dc7fb03868083d33c3d8720ed258f7 174840 libpq5_15.4-0+deb12u1_s390x.deb d0eab7ecd1447e81da684bbf517f0717f14744c42b1a26f59f22ee2fccba8869 15331952 postgresql-15-dbgsym_15.4-0+deb12u1_s390x.deb a93369c9a538334fda17e9efdba05274cac84dc563bac4cb20e12237d745c25b 15800 postgresql-15_15.4-0+deb12u1_s390x-buildd.buildinfo cb58a931ce771e72d39f556e0d07920f0ff8e9f7dd977c67d452a3d0b4222cc1 5494008 postgresql-15_15.4-0+deb12u1_s390x.deb ae41aeb7b9e61a3a1f4f8e1fae5708b814894d7e2e8e863656d19ecc9f0a7bf5 2234560 postgresql-client-15-dbgsym_15.4-0+deb12u1_s390x.deb 5bb8764274928ddf488c1ba84b7bfe287b41c8f88452eabfe7f732464147bec9 1633356 postgresql-client-15_15.4-0+deb12u1_s390x.deb 81b86b18f3b7a52e4a40509c95c0be40abcf7af4aef879cc4e5fe9329a5df0bb 180460 postgresql-plperl-15-dbgsym_15.4-0+deb12u1_s390x.deb 20d1fb89882a01cc711ec1c201a7ea5cf1e632827843f6c5ac3084030a5d3d8a 61844 postgresql-plperl-15_15.4-0+deb12u1_s390x.deb 563030df1ad19e10375e00f05769423eed9a9870c7c9bfa33c9e385fc39c8ac6 169952 postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_s390x.deb 72c208f568806c7e13048e4c72c5480f20ff32b96346c5a3ca2771be3aa07e41 84796 postgresql-plpython3-15_15.4-0+deb12u1_s390x.deb c3d55d66cfcdd2fb92e19d7f026d3851aed226f2dbdf217656c742ae48157156 77580 postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_s390x.deb d6d27d609663baaacfb70392eb54f1fd9621546029a183769ad582e1ba6e31b0 37360 postgresql-pltcl-15_15.4-0+deb12u1_s390x.deb 0584f49891ef981377f9b0ec813f802023e1c16ba51906e5cf3763384a1cc7a4 1128752 postgresql-server-dev-15_15.4-0+deb12u1_s390x.deb Files: 31ccf9768f9cf85e50defaf4ee2357a8 37884 debug optional libecpg-compat3-dbgsym_15.4-0+deb12u1_s390x.deb 918364459801d1b2c96427a93828d7cd 19320 libs optional libecpg-compat3_15.4-0+deb12u1_s390x.deb 4ec6acaf006b5d6e182de06c7c1161d3 214476 debug optional libecpg-dev-dbgsym_15.4-0+deb12u1_s390x.deb 92f63d7a772a70b2ca5aaacc8621189e 276664 libdevel optional libecpg-dev_15.4-0+deb12u1_s390x.deb 39fba640d660a77d818a0819141dead0 111944 debug optional libecpg6-dbgsym_15.4-0+deb12u1_s390x.deb ea3ce9a430bf0b3c6167871302301d58 55468 libs optional libecpg6_15.4-0+deb12u1_s390x.deb d48faaf60410249fefbff043e1f908d1 88368 debug optional libpgtypes3-dbgsym_15.4-0+deb12u1_s390x.deb a653457fba826ac8639990363506d1df 40524 libs optional libpgtypes3_15.4-0+deb12u1_s390x.deb 2a831b31dbecfac8e395edd8402e17dc 134136 libdevel optional libpq-dev_15.4-0+deb12u1_s390x.deb 45620ddd803af537ad9cac50d10f94b4 272144 debug optional libpq5-dbgsym_15.4-0+deb12u1_s390x.deb e4fe00bb18da1fbd045e731d9b3ca24b 174840 libs optional libpq5_15.4-0+deb12u1_s390x.deb 825588378d31ac32ec7370a10bfeebd8 15331952 debug optional postgresql-15-dbgsym_15.4-0+deb12u1_s390x.deb 9b2d30095d7bd6104cecf2e362531c8c 15800 database optional postgresql-15_15.4-0+deb12u1_s390x-buildd.buildinfo 930914dc10e69ecdbb3c45b2b0a1f7aa 5494008 database optional postgresql-15_15.4-0+deb12u1_s390x.deb eac271d8445af83842596bdc3264590f 2234560 debug optional postgresql-client-15-dbgsym_15.4-0+deb12u1_s390x.deb 54d9223b0abc3b95cd7ce948392f84a4 1633356 database optional postgresql-client-15_15.4-0+deb12u1_s390x.deb 511e2410100caf49f97affa73b642845 180460 debug optional postgresql-plperl-15-dbgsym_15.4-0+deb12u1_s390x.deb aeef8b520b4e7e89e856f0621e751f6c 61844 database optional postgresql-plperl-15_15.4-0+deb12u1_s390x.deb d005cff8b8c3265f067d8c8cbe467943 169952 debug optional postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_s390x.deb 9393c3932bf5f1f53900665721099985 84796 database optional postgresql-plpython3-15_15.4-0+deb12u1_s390x.deb 215b4c9e3da1870fdc5d08b8bc3409c2 77580 debug optional postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_s390x.deb 7ab3e8591eb6c8c7d90920796100b9f7 37360 database optional postgresql-pltcl-15_15.4-0+deb12u1_s390x.deb 2df7b0ee798ccca5eed0f908ea72d4f1 1128752 libdevel optional postgresql-server-dev-15_15.4-0+deb12u1_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEhBjA3afmaHyzk51IFQ1EGN3xM6QFAmUntI4ACgkQFQ1EGN3x M6SPzQ//dsI5QpqO/PHnZ+DmA7HSIycSUyEDlCW4w7Jw3yWXQC7mxT/ngtDIjzBk Kq0jJxZhnZ80e4HKggQ2kPYWpNwQexRYWu8rxsFwxBP0s4fFWhlN3wqRvlgGC7+g 9A4JpLRUAlwSniAsGeWmILssgx4FYHY+azT7X7JIcZpKOVSLxUHp3TRvpAfu++vJ 1ximTlJmuo/KKu/pHpsBnVqN94KIYeqwuaZl7pb5dq5PKPNTLDLjKeCbml4nCB1K IMKnZVxAad0DCDQ0FboXL4yxq7uhF2mpNwKqIiKK9MHOsmzdZrrF2aRuVQiZJCEw OSj1UdYdGJxeUEMDbbtp1H9pAR2awu7KupCk8hjp6uR+e1P+a4hfjinXkEYUFly9 cTSEgGmDRbL/TELW6YK6mHwWs28EksZvEKP9sCNuB2BU2wcK84cv6KIibZzS23Iq cayi+Piouud3Wkuya3TuC5qgSsj5uA+WhQCtKf5Qxpn7mZz9ebpstl4mirALkuTY Wj82E/RZyYslEnl/etXsa96cDHTYJ6KyKr058b2tQk4xfXrKzE3YSz2evR4MQwzt uNFhn5TOzLB+/G3PDTcaM7MpIQFKI+rC/pi3VLYaXwrSsNSMfjIOBq/+kqwbSjzA WKHplJ3dKqCw5h1qmh6neZa0f+642SbC6ianqL/zXEqSC93LkVQ= =qoaH -----END PGP SIGNATURE-----