-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 01 Oct 2023 21:50:06 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: arm64 Version: 15.4-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-arm-04) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.4-0+deb12u1) bookworm; urgency=medium . * New upstream version. . + Disallow substituting a schema or owner name into an extension script if the name contains a quote, backslash, or dollar sign (Noah Misch) This restriction guards against SQL-injection hazards for trusted extensions. The PostgreSQL Project thanks Micah Gate, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem. (CVE-2023-39417) . + Fix MERGE to enforce row security policies properly (Dean Rasheed) When MERGE performs an UPDATE action, it should enforce any UPDATE or SELECT RLS policies defined on the target table, to be consistent with the way that a plain UPDATE with a WHERE clause works. Instead it was enforcing INSERT RLS policies for both INSERT and UPDATE actions. In addition, when MERGE performs a DO NOTHING action, it applied the target table's DELETE RLS policies to existing rows, even though those rows are not being deleted. While it's not a security problem, this could result in unwanted errors. The PostgreSQL Project thanks Dean Rasheed for reporting this problem. (CVE-2023-39418) Checksums-Sha1: 47a88a09ddd731a1548cdb854e0c33bc92436e77 38664 libecpg-compat3-dbgsym_15.4-0+deb12u1_arm64.deb 7a67b2df024ee9aaae14866885b30e10ec9fb792 19380 libecpg-compat3_15.4-0+deb12u1_arm64.deb 452a2393ec190e9ad90942f8a495643d3a21503a 273844 libecpg-dev-dbgsym_15.4-0+deb12u1_arm64.deb f4e08d8d1303c44762206de95e452c4ea752d434 276528 libecpg-dev_15.4-0+deb12u1_arm64.deb 4dd20d700fde029beb0cad399ce3d280ea712cb1 113156 libecpg6-dbgsym_15.4-0+deb12u1_arm64.deb 8ab6b2759a59fe767b3068d2f6d40bf2e67b9614 55296 libecpg6_15.4-0+deb12u1_arm64.deb fcaff8771507635873f9bee31c5b05c21401b5ef 87292 libpgtypes3-dbgsym_15.4-0+deb12u1_arm64.deb 16eebcdc76102cd10f304836b4e952f211615993 39384 libpgtypes3_15.4-0+deb12u1_arm64.deb 0c87330e866069244d12b17c269e55801c76f4b1 137236 libpq-dev_15.4-0+deb12u1_arm64.deb cc4213e62e5935c99c6f5c51fdf4454d3c03a7ac 274144 libpq5-dbgsym_15.4-0+deb12u1_arm64.deb e6099bc7c3fcf6fae087aab0a63ee96bf9a281a6 177008 libpq5_15.4-0+deb12u1_arm64.deb ac51be7ded09c6e4da9f3ea1932b8e14c45d7776 16318368 postgresql-15-dbgsym_15.4-0+deb12u1_arm64.deb 67503e6c342fea9748f3e5d7a9564cef1cb50613 16845 postgresql-15_15.4-0+deb12u1_arm64-buildd.buildinfo 67ea5e7c278a2fa4027108ecc4814eb646ed16a6 16200016 postgresql-15_15.4-0+deb12u1_arm64.deb 0c66fa837a9e4adaa18e6ae815fa21063338db56 2421520 postgresql-client-15-dbgsym_15.4-0+deb12u1_arm64.deb 429551ef89443869a88e8de88477b1004ba70304 1642104 postgresql-client-15_15.4-0+deb12u1_arm64.deb f5dd603a010a762726bb6f7dc2add2b756453ccf 183360 postgresql-plperl-15-dbgsym_15.4-0+deb12u1_arm64.deb 32069d2c370b1fcfa5a868c63a64f295feffc327 83512 postgresql-plperl-15_15.4-0+deb12u1_arm64.deb ea1d72aeec62d60a9e552344c67a1c5acd7a0641 175400 postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_arm64.deb 40a341bccb32fd361bc67138b692e2306245cc9d 104112 postgresql-plpython3-15_15.4-0+deb12u1_arm64.deb abcefe45962eac3c36747b97524998327c8fc155 79192 postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_arm64.deb 8dc008d26c5a22c2f85b1ac744cf78510c5eedd7 37256 postgresql-pltcl-15_15.4-0+deb12u1_arm64.deb 63447dcdd74335df23ecb44d12bf093a7cf02e5f 1131536 postgresql-server-dev-15_15.4-0+deb12u1_arm64.deb Checksums-Sha256: 4e64877f28723ad491aea49539b3e643394b448ccf0c43ccb5eba69856975448 38664 libecpg-compat3-dbgsym_15.4-0+deb12u1_arm64.deb d81c4eadcad0df4ac6839add24b2595edacbc95fce493893a711498357d201e4 19380 libecpg-compat3_15.4-0+deb12u1_arm64.deb b58675d4d1469fc7f9caaa2e18c6231c9e502fa46d912a6cb241392c99a3d1ba 273844 libecpg-dev-dbgsym_15.4-0+deb12u1_arm64.deb 0f666585386fdb8ab1c8e3372f86d20552431deb97c3937225e8676b2ebb2817 276528 libecpg-dev_15.4-0+deb12u1_arm64.deb 46401e53eff0d9230110dce38471ca8651163c552aa9f673876015436fa2ad10 113156 libecpg6-dbgsym_15.4-0+deb12u1_arm64.deb e14fb7ea5e301484f7803473ef4cc9e2350262c064d3eeb0245154e4fbe62c82 55296 libecpg6_15.4-0+deb12u1_arm64.deb dd74b81161e54b65d77b1d4fdb31c622d78bb1f9a8ac9e1c99bfd1f69ed3b890 87292 libpgtypes3-dbgsym_15.4-0+deb12u1_arm64.deb 5755a50bcf3490fe0aeb834034ccfdca183217aa2508a619cbaec2705630ed66 39384 libpgtypes3_15.4-0+deb12u1_arm64.deb 88553cdad0a6f1b0ac689ae121de140b78a14da09c8ac703fc0520c7348b559f 137236 libpq-dev_15.4-0+deb12u1_arm64.deb a7f2da87cc00584146792f76418d21d023030fabdc8321ab021052fd78bf68ef 274144 libpq5-dbgsym_15.4-0+deb12u1_arm64.deb f1accdae2d12dd4d8b7cfaecea5d7e232ffa52a3330ef11bf0c8e4d90d799d92 177008 libpq5_15.4-0+deb12u1_arm64.deb fa7e05b33da6d91eae0344f9f7ffa8d62d0e95f4070022221d980e18d849cf42 16318368 postgresql-15-dbgsym_15.4-0+deb12u1_arm64.deb 5e9af20de69ad6f65613200232e020e2fb6816c998b91ad7bbbf8e44406c85c2 16845 postgresql-15_15.4-0+deb12u1_arm64-buildd.buildinfo c2787ac45bfea143f54933d77404413b8da9137ed53cf33c1ae055fea1fc326b 16200016 postgresql-15_15.4-0+deb12u1_arm64.deb 5d8729395d6749d8104c2b0b3bee1306981242d859262d2ba90f7a83727a2772 2421520 postgresql-client-15-dbgsym_15.4-0+deb12u1_arm64.deb f7013dca99bf4e4437d58f5a84ddfe8dedff5ae116627b44d0ccf2bf26333ebe 1642104 postgresql-client-15_15.4-0+deb12u1_arm64.deb 7e5167866ff592c43f4f99d648956d31a052447e12cbfce276064889e9fe0c89 183360 postgresql-plperl-15-dbgsym_15.4-0+deb12u1_arm64.deb 6ac1c4c9adb0d061432d3169a4e497038e8d1b84252fec67d76aab826e9567f6 83512 postgresql-plperl-15_15.4-0+deb12u1_arm64.deb f725f246163b2453b4de4cee7c9d46d5a7fce6f876f10ebd53dffe5b821350b7 175400 postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_arm64.deb 36759ca29d29b1fff9c73bf5ad441cbb3ec7d061d3bf48b2a208fc85a6ad661b 104112 postgresql-plpython3-15_15.4-0+deb12u1_arm64.deb a69d1045486bb7f3d559dec66941fa42f99a41f9ee939c902119488bd826e586 79192 postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_arm64.deb 41da193b9314cb9dde35fb336e2d64b3d5e45df29f27df8376f8f5452da6c7d1 37256 postgresql-pltcl-15_15.4-0+deb12u1_arm64.deb 5d0ba6de8075ae978025283afb33f2ecb1d4dbfa1fac022b84f5e79ed9b60e34 1131536 postgresql-server-dev-15_15.4-0+deb12u1_arm64.deb Files: 8ebeb124d19e9bca66c5d1184729fd20 38664 debug optional libecpg-compat3-dbgsym_15.4-0+deb12u1_arm64.deb 28634e78464c1482adcfe1515b6c0d5e 19380 libs optional libecpg-compat3_15.4-0+deb12u1_arm64.deb b3aff1267d6bd645e2426b31ccbeb730 273844 debug optional libecpg-dev-dbgsym_15.4-0+deb12u1_arm64.deb b12779283d6ea557e5a9fcac1fcea341 276528 libdevel optional libecpg-dev_15.4-0+deb12u1_arm64.deb 3fa1a122075ffc51f43062544c754fe8 113156 debug optional libecpg6-dbgsym_15.4-0+deb12u1_arm64.deb 5ec2e401e5ed8ed58493be7fc4a6bcd7 55296 libs optional libecpg6_15.4-0+deb12u1_arm64.deb cb14f9f444f8af280459ce831c41e6b6 87292 debug optional libpgtypes3-dbgsym_15.4-0+deb12u1_arm64.deb 213f9561d323b7c0b6d454a09ae3e97e 39384 libs optional libpgtypes3_15.4-0+deb12u1_arm64.deb bd31f112deeed0ec975733d2275bb80c 137236 libdevel optional libpq-dev_15.4-0+deb12u1_arm64.deb 2724ed1b73f21bb54eb881f41eff4b19 274144 debug optional libpq5-dbgsym_15.4-0+deb12u1_arm64.deb ef15353408b19cdfd060f4a8a6a99b22 177008 libs optional libpq5_15.4-0+deb12u1_arm64.deb 82aec3edcf916e7965a2674cb75db35c 16318368 debug optional postgresql-15-dbgsym_15.4-0+deb12u1_arm64.deb 0a78e45f64d3c322b20afa269c490166 16845 database optional postgresql-15_15.4-0+deb12u1_arm64-buildd.buildinfo 8a88525cd15e9c763939975e0510eab4 16200016 database optional postgresql-15_15.4-0+deb12u1_arm64.deb 373fe56aa3afc721b13b27446ed6307a 2421520 debug optional postgresql-client-15-dbgsym_15.4-0+deb12u1_arm64.deb 85402c8b578d6a6281553fcab8c2cb28 1642104 database optional postgresql-client-15_15.4-0+deb12u1_arm64.deb a74faf33ae7a4c0cb2b6ddda89e80c82 183360 debug optional postgresql-plperl-15-dbgsym_15.4-0+deb12u1_arm64.deb 6a7859e69294a5b7fcef6a53a75e07a0 83512 database optional postgresql-plperl-15_15.4-0+deb12u1_arm64.deb 0eb31876cb279f1715d87753ec690ee0 175400 debug optional postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_arm64.deb 4ef8d62f72a04e00270ec14605b3b306 104112 database optional postgresql-plpython3-15_15.4-0+deb12u1_arm64.deb 73f407fc0652ca41efb80506f04062dc 79192 debug optional postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_arm64.deb bd96e63bbd7247204418f8cccaacb25d 37256 database optional postgresql-pltcl-15_15.4-0+deb12u1_arm64.deb 6d945d5e4c550f8071132a4622ec89be 1131536 libdevel optional postgresql-server-dev-15_15.4-0+deb12u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmUDOxnfDwdc47jJKqoc2e3yvTA0FAmUnwbwACgkQqoc2e3yv TA1zVA/+ICRGJkOTPZrM8Fox9DC/xD3EIV7lxpk0HgTSnAaUdCWkIgBVphZ64kTs xYc1RF11VRO0tOFOsXIGpFURsgThTcZtlJBc3q5uIYl5xxAPCufbQfbJVCeJD6SD 2TM4HNDCQPn26F3IkH+ZY5MrKalRXy+I+zRQmQJduPqkBYNIQ1/Fm3if8OuXzMO+ AYhwwBVCruyIC2Ibc8RYQLJcJbJNMLpyiYVVhlle2lFtHVva563IGhTgyXzO9usB oIK8Cs1l0SwFZB0TmTa3u1L3SIIGf/hkaFBzxFYd2sa/gPS7p5TDNr0Dq/YjK6Mi oOLgBtz5YRnh1kxVkZfk2ozFtUkU1yzi6NdAegFcyr0ACDV53xPw0UBvEy1JOcCh YNNlcJkjhnNT6GUaHyekTOIU0nqwXgFe7WWO8qDJo9yIKG+P5XaKW9n17Chd6eWA jTEGafpBMlPuGtHQu3ubnsGX9I0/WbcH6/4o1kEtjpohM/TQDCddjBFV5pUz0ZtA tRItIKwlZ3JcCoKGHhnXpLHgA0bQ//1QHH6XA703qsszGkzUFD7w/cTj0GpBtP0s 4Ss5iy3UWEJ+zx+OqbkrcZTBdUPTW86SAJCQ+8LeiisG4xAMDdNKQIozRdEHwHDn PXSyChyiH+K6W7DjGaXt4GpWwVA8lCTHvRpIuu789Y+dxwz9L68= =3qmb -----END PGP SIGNATURE-----