-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 01 Oct 2023 21:50:06 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: amd64 Version: 15.4-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.4-0+deb12u1) bookworm; urgency=medium . * New upstream version. . + Disallow substituting a schema or owner name into an extension script if the name contains a quote, backslash, or dollar sign (Noah Misch) This restriction guards against SQL-injection hazards for trusted extensions. The PostgreSQL Project thanks Micah Gate, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem. (CVE-2023-39417) . + Fix MERGE to enforce row security policies properly (Dean Rasheed) When MERGE performs an UPDATE action, it should enforce any UPDATE or SELECT RLS policies defined on the target table, to be consistent with the way that a plain UPDATE with a WHERE clause works. Instead it was enforcing INSERT RLS policies for both INSERT and UPDATE actions. In addition, when MERGE performs a DO NOTHING action, it applied the target table's DELETE RLS policies to existing rows, even though those rows are not being deleted. While it's not a security problem, this could result in unwanted errors. The PostgreSQL Project thanks Dean Rasheed for reporting this problem. (CVE-2023-39418) Checksums-Sha1: ad30f1e5523322414035f0e4c0e138c7712e06ce 38116 libecpg-compat3-dbgsym_15.4-0+deb12u1_amd64.deb 86936a968b140e32a6991842c7d8ed9186c114f0 20052 libecpg-compat3_15.4-0+deb12u1_amd64.deb c52da0e9355a77e520397321bb491fa16b053a43 281152 libecpg-dev-dbgsym_15.4-0+deb12u1_amd64.deb 1bc3ae8401a015c24b86ecf65e44e4b06e67745f 292748 libecpg-dev_15.4-0+deb12u1_amd64.deb fb254da7c19e5e909ba58eef97b35892b3274cbb 113004 libecpg6-dbgsym_15.4-0+deb12u1_amd64.deb f11471879de6284945ad056e7f1f4ec08e8a75d8 58060 libecpg6_15.4-0+deb12u1_amd64.deb 927e7ae95dcfc6d014bb557c63e4f4b2d79e3806 88328 libpgtypes3-dbgsym_15.4-0+deb12u1_amd64.deb f6f94c9ebb940d2cbc54f08e5876335ef8e0c563 41756 libpgtypes3_15.4-0+deb12u1_amd64.deb 2c136a3b7be184052c8c6bdba9358a2d7f23bddb 140912 libpq-dev_15.4-0+deb12u1_amd64.deb 96cf9bad76bc3b2320ce3ca3300548f35a0c5580 276460 libpq5-dbgsym_15.4-0+deb12u1_amd64.deb ca0e8d8a7340b32e4c7e794e3c5df0c89ff0b191 185760 libpq5_15.4-0+deb12u1_amd64.deb 78754041341483263bd52d27c1556e6a791c893c 16736160 postgresql-15-dbgsym_15.4-0+deb12u1_amd64.deb de97eed019d4613adbf243f933a07b9d872b7872 16868 postgresql-15_15.4-0+deb12u1_amd64-buildd.buildinfo fc758e9a62f9ab8af48853e2799282ca31c07e4e 16641192 postgresql-15_15.4-0+deb12u1_amd64.deb 2a494fec1d0c7542e1ab35bad19bcc5afe0d4beb 2416132 postgresql-client-15-dbgsym_15.4-0+deb12u1_amd64.deb 618ecfe7b0575d28a35c1a2cc232a8fe8092802d 1692876 postgresql-client-15_15.4-0+deb12u1_amd64.deb fb730afc22bf340c539e8251ad3cadb36ea76939 186872 postgresql-plperl-15-dbgsym_15.4-0+deb12u1_amd64.deb ff0ff213df9124d93d9be530c3218b9007cb670b 86896 postgresql-plperl-15_15.4-0+deb12u1_amd64.deb c03870d43256b9165588a2090ab6c8825fba26c2 178304 postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_amd64.deb 4a5a5ec6d149ccc9edebe979f4c5fa7554df2d1d 108172 postgresql-plpython3-15_15.4-0+deb12u1_amd64.deb 8b61ad87121922e51eae4437e4d281460d3bcdc6 79524 postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_amd64.deb 055efe385aa8991498a769aa2ff7b205a500b1d3 38800 postgresql-pltcl-15_15.4-0+deb12u1_amd64.deb a1198c6677b227f87d20f7948bd4b076b0a0fd72 1137940 postgresql-server-dev-15_15.4-0+deb12u1_amd64.deb Checksums-Sha256: b500fe40752a90eb0e9a74f76affcef2642012416c0788af08248e0ca2b4826e 38116 libecpg-compat3-dbgsym_15.4-0+deb12u1_amd64.deb 08340817542219ea980ed9d8745927eb56b3743b75ff44cb32026e5ae39a6d64 20052 libecpg-compat3_15.4-0+deb12u1_amd64.deb a05afcb00397668e9bd5ff583feef6d9cff9cad3abff9ec1da4cfeb668a6f6c6 281152 libecpg-dev-dbgsym_15.4-0+deb12u1_amd64.deb 4c10d3665f38e083e3cfe3281884f2f6d7f9afab370719db6de09093c5c664d1 292748 libecpg-dev_15.4-0+deb12u1_amd64.deb 0fadb40c4d850c6f22fbad5603ac61c14ecc76d09f9876b906b6cd218de0d695 113004 libecpg6-dbgsym_15.4-0+deb12u1_amd64.deb d8fa4946897eb840cadf0e48d29c2cf4afdd243aac433a8b93cd4a95f3a87c04 58060 libecpg6_15.4-0+deb12u1_amd64.deb e09348f51972fe49deb0bbc531969c49ca3a22bd2db4925f1991862e64782e2f 88328 libpgtypes3-dbgsym_15.4-0+deb12u1_amd64.deb 2d09dfc65496cd788925a4e054ce3979cf5be0b605e09bd9f59ca47ede5ffb8d 41756 libpgtypes3_15.4-0+deb12u1_amd64.deb 59f7fe866f6f7da7b51d2f3b4c9c2df70b5773e464e54b5b9cab042db19a024d 140912 libpq-dev_15.4-0+deb12u1_amd64.deb 46135859c1b74df50456c5cdfc385a90e7ad52d635f6b52703ce238e245d99af 276460 libpq5-dbgsym_15.4-0+deb12u1_amd64.deb 40982eec1e0492d4e73f8a44cf6b56dc2d2c488435feb8e3fa75023dad2439aa 185760 libpq5_15.4-0+deb12u1_amd64.deb 6010ed86b9410097b05d4c0be3f89638a67ad8b80bc4a94a83dfec6e17143bee 16736160 postgresql-15-dbgsym_15.4-0+deb12u1_amd64.deb 8ec8705a929b3dfd1f39731fb3d09aa3de3411774be398d45fac07b96bc9ea9d 16868 postgresql-15_15.4-0+deb12u1_amd64-buildd.buildinfo 16908f113adaa1b17d9bf0b60a139076da5b36e33bb29c99af12581dcb93858c 16641192 postgresql-15_15.4-0+deb12u1_amd64.deb 8274ab3578197029d534fd9e2120fe4714c74f39232b2a2e589b4dd0dbbc4d1e 2416132 postgresql-client-15-dbgsym_15.4-0+deb12u1_amd64.deb 915309efe4b405e2fb038a0ff0e3fc3c5aaeae43de04c3673184cb3526047bc2 1692876 postgresql-client-15_15.4-0+deb12u1_amd64.deb 716e5f585f585c2f30b154760b272f3df9ce8b52204cc2a4d7550f92cb5d9b39 186872 postgresql-plperl-15-dbgsym_15.4-0+deb12u1_amd64.deb 78674d83292efe5eb79af4a136861d28d209d802d3c537ca46e620f019976432 86896 postgresql-plperl-15_15.4-0+deb12u1_amd64.deb da723367be5d0ccee2fd7e902ad13d547f2b5b34fa0ee1c911b23dc58633801f 178304 postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_amd64.deb 93d80444745379ff2d0505823477c32e3f51b0a25d769751e4129f3815bc471b 108172 postgresql-plpython3-15_15.4-0+deb12u1_amd64.deb e06765ad65f4299cf0b2dbf1eee0a9c5ef318a54617267e702439f56838ee97c 79524 postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_amd64.deb b33c0b2faa43cbf369b6ffc2fa80e7657218e7b818de6a5858e2642f7845280d 38800 postgresql-pltcl-15_15.4-0+deb12u1_amd64.deb fb14b513b523c37a23b996e52e61a83162e3774553e46b559d7fdc7a35d3c880 1137940 postgresql-server-dev-15_15.4-0+deb12u1_amd64.deb Files: 2032ec2aaade256377eef99dffed9494 38116 debug optional libecpg-compat3-dbgsym_15.4-0+deb12u1_amd64.deb c2d4f70e5d7e3d0328102c889d805e5d 20052 libs optional libecpg-compat3_15.4-0+deb12u1_amd64.deb 0603603a86f241908ce53b35e67f9273 281152 debug optional libecpg-dev-dbgsym_15.4-0+deb12u1_amd64.deb e2a7823cb13004d731470c3d18261489 292748 libdevel optional libecpg-dev_15.4-0+deb12u1_amd64.deb c6b2ca110f244f5858b8113dd12c29d0 113004 debug optional libecpg6-dbgsym_15.4-0+deb12u1_amd64.deb c9a2227b6a4d0e1310e69b0d999ac034 58060 libs optional libecpg6_15.4-0+deb12u1_amd64.deb 228ea1b3dffcde3ede372eac165a370c 88328 debug optional libpgtypes3-dbgsym_15.4-0+deb12u1_amd64.deb 1cc3de6849a1eabdd94d939fd5665914 41756 libs optional libpgtypes3_15.4-0+deb12u1_amd64.deb 5ddd18dc55a907a3d657021a3b4386f5 140912 libdevel optional libpq-dev_15.4-0+deb12u1_amd64.deb e29662690c93c8dfd1453848bb91e92d 276460 debug optional libpq5-dbgsym_15.4-0+deb12u1_amd64.deb d43acdee55aa2bf1bf1e697f97c0d077 185760 libs optional libpq5_15.4-0+deb12u1_amd64.deb 246b0abb9000697c2f3e419597a3a686 16736160 debug optional postgresql-15-dbgsym_15.4-0+deb12u1_amd64.deb c479260284f9a7d7b5cc0a7d80ae5504 16868 database optional postgresql-15_15.4-0+deb12u1_amd64-buildd.buildinfo 3d9e7e2e3dbbcff4dd72229b7889dfb4 16641192 database optional postgresql-15_15.4-0+deb12u1_amd64.deb e53e87be305107ef6f8e7beb4a98c79e 2416132 debug optional postgresql-client-15-dbgsym_15.4-0+deb12u1_amd64.deb d9997316eb3771273b8e8ef527ad6afa 1692876 database optional postgresql-client-15_15.4-0+deb12u1_amd64.deb f3455c4831e9ba98f75cbef78a07b8d9 186872 debug optional postgresql-plperl-15-dbgsym_15.4-0+deb12u1_amd64.deb debd450138897fccf78e59531837cd10 86896 database optional postgresql-plperl-15_15.4-0+deb12u1_amd64.deb 18f568414db3c9290bc1527e360860d6 178304 debug optional postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_amd64.deb de9b09b211be101e88c9e7af61ba1c77 108172 database optional postgresql-plpython3-15_15.4-0+deb12u1_amd64.deb 4a6de9464da127ed757be96020102e8f 79524 debug optional postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_amd64.deb 32b4fb28dc1d6b4eb9fc72154a418967 38800 database optional postgresql-pltcl-15_15.4-0+deb12u1_amd64.deb 5535778080b5f771bc69c65d15d1f043 1137940 libdevel optional postgresql-server-dev-15_15.4-0+deb12u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEi/TVpVg0yb7dq8QfDZWW6X29YdoFAmUnvDwACgkQDZWW6X29 YdoMHg//XE67hgPcfe1NoYT/e0bkk6eWFacPJAKah1rtmDnI0sWiV2uDdTcpga0c FUra57NpsJHNPOjMAr7Q8eyt1WTjBQhi2oHu03+rYcwU4tzliWshopb2boSvXFwU qNyZgsRlAOBF2ZCVb9cG8gNPuGmCkq7mFbwO8eRPy0jVvPI0VFQlnR8CSST0tTf+ Wzlf6zAQeKpjUmmObKdNXppfOJZKl5aTb7Y0hzVNhu2jLFxVMB4+uqKqo7wYkYo1 9i3nMbmC78MK5e3Wqm4fdA/2LeKe9ZYZBasK6ClhlBRQ9kJ8UAkLTa4p588q3dRP Khhxb9bjG+f6oIdB36XKpas1Hs42Fu50uPKX92jmCrf9c25bltMX/PziCZOQbCjN x6yK465Sa5dfswS37of+ZpQqCd1G7ad+/PJSial272WjfHxQLdj0oWCpDDT62H5w uqcfGAOlmYMgDIKn6MAJQO/Uk3EYXrcooE7YxXfSnyucVS1l0I7exthM3CwBLew4 UrPv4gBHsA7VJ2f8axzKY9GzD8ZwixlgKuxMBwgY3OssIrLtZrrhoO9FhQbYsZvy AeOHsHD5QVSYMnfxrWEkAnNVHhwD7Zf+QTjJdmNCKspsdIoVfuGcvsIJSou60OVg Rlr/vT4THhtBfRaOfAqgtHJqpzAYJFZWcrvFewFb+E5uynP9KGo= =DJrw -----END PGP SIGNATURE-----