-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 01 Oct 2023 21:50:06 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: armhf Version: 15.4-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.4-0+deb12u1) bookworm; urgency=medium . * New upstream version. . + Disallow substituting a schema or owner name into an extension script if the name contains a quote, backslash, or dollar sign (Noah Misch) This restriction guards against SQL-injection hazards for trusted extensions. The PostgreSQL Project thanks Micah Gate, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem. (CVE-2023-39417) . + Fix MERGE to enforce row security policies properly (Dean Rasheed) When MERGE performs an UPDATE action, it should enforce any UPDATE or SELECT RLS policies defined on the target table, to be consistent with the way that a plain UPDATE with a WHERE clause works. Instead it was enforcing INSERT RLS policies for both INSERT and UPDATE actions. In addition, when MERGE performs a DO NOTHING action, it applied the target table's DELETE RLS policies to existing rows, even though those rows are not being deleted. While it's not a security problem, this could result in unwanted errors. The PostgreSQL Project thanks Dean Rasheed for reporting this problem. (CVE-2023-39418) Checksums-Sha1: b8d8f4caf91834d21abe3e106ab947497d9a7317 37648 libecpg-compat3-dbgsym_15.4-0+deb12u1_armhf.deb c37b73dcff08f338bdc1280aba5a9dd6c0e991a8 17416 libecpg-compat3_15.4-0+deb12u1_armhf.deb 0d82b0eedc4079e4b4700710bc9ddd3a8973b404 235580 libecpg-dev-dbgsym_15.4-0+deb12u1_armhf.deb fd39c86db428121ff659ce830c4848527bdbce59 273712 libecpg-dev_15.4-0+deb12u1_armhf.deb 61aa5cfacf818e5a7ea050cd56c8c37f19b10a43 111508 libecpg6-dbgsym_15.4-0+deb12u1_armhf.deb 7d9a481d7b94254e26ff4ba451cbf492dae1e0c0 50316 libecpg6_15.4-0+deb12u1_armhf.deb 8d955c5f1ebea360f6bb1a4b8e455d19e9d48fcf 88564 libpgtypes3-dbgsym_15.4-0+deb12u1_armhf.deb 0c62af7cfca47e19c75871ea680bd7d2d4130dd1 37224 libpgtypes3_15.4-0+deb12u1_armhf.deb 0ef4bcc447d7e223c573f9345dbf6dc22009a624 129484 libpq-dev_15.4-0+deb12u1_armhf.deb 2de612c8fc39badc638b6f164bcb1a0732620f17 273208 libpq5-dbgsym_15.4-0+deb12u1_armhf.deb 9ae72d8646185547012da4dd7d4358863e70889c 167108 libpq5_15.4-0+deb12u1_armhf.deb 0a5407f6dc37023e93df9a38f7e1edc17b6740ce 16035632 postgresql-15-dbgsym_15.4-0+deb12u1_armhf.deb d5bf6ccf611118bd0e045e137afc70d556a06dcd 16721 postgresql-15_15.4-0+deb12u1_armhf-buildd.buildinfo 55353def7d681043bd153db2d95845025cfd707b 15900488 postgresql-15_15.4-0+deb12u1_armhf.deb 1653d8881c3d2f6cb3e84821496867d330266b44 2239708 postgresql-client-15-dbgsym_15.4-0+deb12u1_armhf.deb 633e43014838a78968c09b19e6081e442be3e5bf 1608456 postgresql-client-15_15.4-0+deb12u1_armhf.deb fdd84de6eee675027950e8d2146c912bf0c339e3 182864 postgresql-plperl-15-dbgsym_15.4-0+deb12u1_armhf.deb e43fdd208d7c274abba17701079899cc175cb946 83660 postgresql-plperl-15_15.4-0+deb12u1_armhf.deb b795e0c19eaef0a65fd1a5e4c31699a8bea35b24 172060 postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_armhf.deb 23d5495df6fdb757dbc9d8fae7735769bd79407c 102016 postgresql-plpython3-15_15.4-0+deb12u1_armhf.deb 308044efe0c881ee6fa26ba0e2901718fd3f9101 78180 postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_armhf.deb 2b2fa4af5b3b394db7eb03cdb2f360522ba4d592 36272 postgresql-pltcl-15_15.4-0+deb12u1_armhf.deb 8ff873e09163d811c51094237d399d56f6f037e8 1120156 postgresql-server-dev-15_15.4-0+deb12u1_armhf.deb Checksums-Sha256: 04cabf667db877c7e8107d8096338a3e87648fe3d144b0da0ede8fb18b355948 37648 libecpg-compat3-dbgsym_15.4-0+deb12u1_armhf.deb 056418586aee7a8b3f87477a8252fe5421aca7dd000b29e53d196b71de6d10be 17416 libecpg-compat3_15.4-0+deb12u1_armhf.deb 84cce16dcaafe39f7ca2e3c2a2c383c52ea467b86a8b74f1c0f8ce69f41eeb7e 235580 libecpg-dev-dbgsym_15.4-0+deb12u1_armhf.deb 79b591a6a0e1d3f4fb50269cead19e45ab4879fb90f5c6c47d54813992a72d73 273712 libecpg-dev_15.4-0+deb12u1_armhf.deb 4b06cb8365def6820f1b823128c98dd2e7331feb1c8339d075ab71ddd7102485 111508 libecpg6-dbgsym_15.4-0+deb12u1_armhf.deb 4d8fce6d8e7c2075720de391ab90aa4b5adb6c3b2263673ccf435755ac344b39 50316 libecpg6_15.4-0+deb12u1_armhf.deb a50c3508d21b08545180fbd0cb81a99c9b92151192a0c9a10649bdfe271d4f4d 88564 libpgtypes3-dbgsym_15.4-0+deb12u1_armhf.deb 955a46b728956808fc93af4082a3d43aa9f2f532ea328691e9892e5c9423780e 37224 libpgtypes3_15.4-0+deb12u1_armhf.deb f995231b573bfc1f1d51f81dad03b68ba46fc31f880bd20a5f74c0e58fdd2690 129484 libpq-dev_15.4-0+deb12u1_armhf.deb 130321d0911b8a8fcf62c9fd12a3ed3d8fb78983742f89cba37724f8657be0c3 273208 libpq5-dbgsym_15.4-0+deb12u1_armhf.deb 1e6a1e3bb02c593eb2603490b5967230f207923d294cee1ebb54a9aa441038a4 167108 libpq5_15.4-0+deb12u1_armhf.deb 27947fa6aad19da4a6399a3fe368293c5b7990f154fa7e7f81beda04ea0ffdd4 16035632 postgresql-15-dbgsym_15.4-0+deb12u1_armhf.deb 0518d58faa6d7ef036a8d5e612dc6fb69598f7c264909495febe96a32a58c8e5 16721 postgresql-15_15.4-0+deb12u1_armhf-buildd.buildinfo 05d1c932774240c97ecb91b40c2424af0177fc85bb855d894de4b223791f826a 15900488 postgresql-15_15.4-0+deb12u1_armhf.deb 63a8056935e2837b01f8a84da73d143d9baa91f4f56e3cedbe1c2972a5f72e3c 2239708 postgresql-client-15-dbgsym_15.4-0+deb12u1_armhf.deb caccb196716fb272a19d2e13392b797bb05c26acd98b4b64679fd3ff0b4fd0bd 1608456 postgresql-client-15_15.4-0+deb12u1_armhf.deb 8586e5e8b8373496ffee9c25959cf5aa242ece17ac805d99b0e02398f17f201f 182864 postgresql-plperl-15-dbgsym_15.4-0+deb12u1_armhf.deb 50cce7b99cfadd0adb117120a5e973ca155bd96daacbff6e4716bdb339f55a7e 83660 postgresql-plperl-15_15.4-0+deb12u1_armhf.deb 2a30918b9ef647cbf154eb2253693d18b61e9dca00226c6870c7c3d7791e7f0e 172060 postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_armhf.deb d46a9a7c101a48582e8640547d8dc6624127d3545e0521ecd53dc780e39b14ee 102016 postgresql-plpython3-15_15.4-0+deb12u1_armhf.deb cc83f2c2f011f86e2b1183e5c02fc40d155441a0fd9131cb257c429beada8077 78180 postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_armhf.deb 1d3e5765d717c3a6d71b6fe1d01b665a5aa27966aa01b27bf8fd7f54417f74fb 36272 postgresql-pltcl-15_15.4-0+deb12u1_armhf.deb dcdeb0eab6081583d43cb77f2ef4c2a1af9d9fa29d2183696ef5ce4bd725cb08 1120156 postgresql-server-dev-15_15.4-0+deb12u1_armhf.deb Files: 13eae887fab260356e756734bb6a50a4 37648 debug optional libecpg-compat3-dbgsym_15.4-0+deb12u1_armhf.deb 09c3c6ff41ce0c9f6f8f48daf24a0698 17416 libs optional libecpg-compat3_15.4-0+deb12u1_armhf.deb a7fdcba133f3b3ae40738c7f7c336cd2 235580 debug optional libecpg-dev-dbgsym_15.4-0+deb12u1_armhf.deb bcc491240e48db3593d72251d8b001cf 273712 libdevel optional libecpg-dev_15.4-0+deb12u1_armhf.deb ee481834f0493552032a18c29ce051bb 111508 debug optional libecpg6-dbgsym_15.4-0+deb12u1_armhf.deb af1c1fb4d5ebeaa104790cac753755ee 50316 libs optional libecpg6_15.4-0+deb12u1_armhf.deb 49270ed976f67d53ee1595510f8b1de7 88564 debug optional libpgtypes3-dbgsym_15.4-0+deb12u1_armhf.deb 4ab3ed4e6e629db9038ec4e5b35da97f 37224 libs optional libpgtypes3_15.4-0+deb12u1_armhf.deb b3ac51a11d4b04d8d97aa9f014b8b782 129484 libdevel optional libpq-dev_15.4-0+deb12u1_armhf.deb bb1b0ef0467f043c192e5ede8611f754 273208 debug optional libpq5-dbgsym_15.4-0+deb12u1_armhf.deb 8ce5c36746346a1aed2825e1d8352a66 167108 libs optional libpq5_15.4-0+deb12u1_armhf.deb cea021e8e98174591f768e2cd84d9327 16035632 debug optional postgresql-15-dbgsym_15.4-0+deb12u1_armhf.deb 5cd33897eff242bd4129a438abd06404 16721 database optional postgresql-15_15.4-0+deb12u1_armhf-buildd.buildinfo 1ff13951afe83842b34840fac9b034f7 15900488 database optional postgresql-15_15.4-0+deb12u1_armhf.deb 69fb5a9b64c8c672eeb9cdf0f973011e 2239708 debug optional postgresql-client-15-dbgsym_15.4-0+deb12u1_armhf.deb 2ac1de5debaddeee42a12077daa29c72 1608456 database optional postgresql-client-15_15.4-0+deb12u1_armhf.deb 4b130c9d07543e9e11d880ff18424cab 182864 debug optional postgresql-plperl-15-dbgsym_15.4-0+deb12u1_armhf.deb ccbcdcc933533d941cefed2db3ae05c7 83660 database optional postgresql-plperl-15_15.4-0+deb12u1_armhf.deb ceb574e215d02bfca35322ccab1f1c55 172060 debug optional postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_armhf.deb 7a13eb797c0b7652f4bb2bd08daceeec 102016 database optional postgresql-plpython3-15_15.4-0+deb12u1_armhf.deb b8b0873167d10a2395ea3be296ea5549 78180 debug optional postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_armhf.deb bb87ca8ae9fa4cee70a65adc40ccc1a8 36272 database optional postgresql-pltcl-15_15.4-0+deb12u1_armhf.deb 7108a595b49704098c0eab4328f961ca 1120156 libdevel optional postgresql-server-dev-15_15.4-0+deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE85cWtWDyjeTR1DyXYfnSkVoQrNkFAmUnzBkACgkQYfnSkVoQ rNmxRxAAnl6EGFWyLoRq8Etchvi0gyBxIxI/f7OfMflJAV1hgKrQpImgBYl1rzea HZezDxErG0OOrnqzSEIJ8yLh78OmuALeGdZdv6wS23BRlt9KBq5HPCizwJHgRgp9 hXq5aQfuBba/LE/Khlly09BvUE0L1F7VTHaeEARrUx/W8gwX7PTNyU8vrYXbFQvj Dqv5FeaQTyZN8x2UAftORmC3HpIWrMzosefkmDxMdOWDtGEIhLg7IOfqCoo8b+kT sO0EOjuBACD5kji6j3yDvn7IjuO7XTAZcV4ZtZK7dxU3fqUnZa5UdhM5AEgLrwEd XcesasyGjh63tytJmjPB7THmwembFU2xuW9kCt+YJZyGlncI99/goW4mvquKw2YE LTD0VmMV+EfGI1c/gau6pE3UlXnn29DP8rRV1hIcjynneaYNhFquE19G6bLdhbYb GzRUe/xBpW0bpvWFNL08M6cfsbE73V8Toe5YVUW1Kl1nmwFNoYlpnBXS4oC/JKkU uyqIhZCoQ4bm1a+0haTjckl1Wnr0QArdEnXkOztnArzxeMh5gF52ciXDSa05vxzg 2fsBhMy9ZqO+tjE2Yk8o0EYM81fG65V9jWJaS8Zq4LKNmAj4sC5u7RAmYpcNHTIf 6cJlM1PNUBp1bzdtdNRQa86SRClgQvWf1IeQ3qj+HWtApCbTDQQ= =cVF7 -----END PGP SIGNATURE-----