-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 01 Oct 2023 21:50:06 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: mips64el Version: 15.4-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: mips64el Build Daemon (mipsel-osuosl-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.4-0+deb12u1) bookworm; urgency=medium . * New upstream version. . + Disallow substituting a schema or owner name into an extension script if the name contains a quote, backslash, or dollar sign (Noah Misch) This restriction guards against SQL-injection hazards for trusted extensions. The PostgreSQL Project thanks Micah Gate, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem. (CVE-2023-39417) . + Fix MERGE to enforce row security policies properly (Dean Rasheed) When MERGE performs an UPDATE action, it should enforce any UPDATE or SELECT RLS policies defined on the target table, to be consistent with the way that a plain UPDATE with a WHERE clause works. Instead it was enforcing INSERT RLS policies for both INSERT and UPDATE actions. In addition, when MERGE performs a DO NOTHING action, it applied the target table's DELETE RLS policies to existing rows, even though those rows are not being deleted. While it's not a security problem, this could result in unwanted errors. The PostgreSQL Project thanks Dean Rasheed for reporting this problem. (CVE-2023-39418) Checksums-Sha1: d457bb365f0e82bea654a234f2ff04b932cb39d8 39776 libecpg-compat3-dbgsym_15.4-0+deb12u1_mips64el.deb 2ddca1b24310c483ffb3d70b4a457fad3dcfcc09 19140 libecpg-compat3_15.4-0+deb12u1_mips64el.deb 4d961827c98b1de8a3c6787f8cd951a99d86c4ac 249736 libecpg-dev-dbgsym_15.4-0+deb12u1_mips64el.deb bedc34044b51fbdabb2caa59927d66f3b774d4a6 283408 libecpg-dev_15.4-0+deb12u1_mips64el.deb 13a374bac9586741a77fcd8211c8e5e49985c9b5 116532 libecpg6-dbgsym_15.4-0+deb12u1_mips64el.deb c61c29eb805c5405df2d7aad1ddfa58c69cff15a 54880 libecpg6_15.4-0+deb12u1_mips64el.deb bdf24d85d0aa39b2a35597db4f2a8c55ccdfceaf 92532 libpgtypes3-dbgsym_15.4-0+deb12u1_mips64el.deb ae8e925391d15d98ab7431ada3991695e8dfded0 40124 libpgtypes3_15.4-0+deb12u1_mips64el.deb 49f00ff27328a29f88117c2764efe659948d9a68 146756 libpq-dev_15.4-0+deb12u1_mips64el.deb 1b56cc1a130c44b7a5e8f47c2f02a535cfc1c234 286168 libpq5-dbgsym_15.4-0+deb12u1_mips64el.deb 7fe4fecbd7d48279b900ce9301184bfd73275e18 173900 libpq5_15.4-0+deb12u1_mips64el.deb 45ccd7c295c48cbaa682ed94d6ed2ec7844cba4d 16863740 postgresql-15-dbgsym_15.4-0+deb12u1_mips64el.deb ac53eeb9e890405eded830a2fa1926d2c5b4f45a 16878 postgresql-15_15.4-0+deb12u1_mips64el-buildd.buildinfo d4e638e35b9b36b441425bda0d0e98e2cb517a33 16196296 postgresql-15_15.4-0+deb12u1_mips64el.deb 86e8175470d3d4cf00e832df699a39cce6b8d931 2403708 postgresql-client-15-dbgsym_15.4-0+deb12u1_mips64el.deb e4fccbe9192d54049fa65a5f5fd9abf1e81123de 1637512 postgresql-client-15_15.4-0+deb12u1_mips64el.deb 03e875c071ed03201d84e1fd487bb2fb12c5206f 190180 postgresql-plperl-15-dbgsym_15.4-0+deb12u1_mips64el.deb 9510cbcf3cc85273234c115072c719570755db4d 82152 postgresql-plperl-15_15.4-0+deb12u1_mips64el.deb d9be2e2a442fdbeb85a80ab4ab198ce3feff6048 182240 postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_mips64el.deb 9c4465fdea0d158e5bb36f764a6d5174fba35721 101300 postgresql-plpython3-15_15.4-0+deb12u1_mips64el.deb 88d51439ec74fcac72a24a04ff16bf79bf0a35ad 81312 postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_mips64el.deb 7339dbe6e850fcef00bace8f57578a9ac7f9524d 36252 postgresql-pltcl-15_15.4-0+deb12u1_mips64el.deb ba41e407400a80c0d2cee27fb07994e67fd16c94 1143764 postgresql-server-dev-15_15.4-0+deb12u1_mips64el.deb Checksums-Sha256: 412f7fdcc07c382eed098f5c6ff9a28e7cb473d35d937b9488a625023a453741 39776 libecpg-compat3-dbgsym_15.4-0+deb12u1_mips64el.deb ce2740934f465edf9b045786cca405d3345b7fbaa288dcdfad4702bc0e6804cf 19140 libecpg-compat3_15.4-0+deb12u1_mips64el.deb 355c3ef145f4a3cb3f7fc77b00668ab3e13132463487409301823c4e2538f2b5 249736 libecpg-dev-dbgsym_15.4-0+deb12u1_mips64el.deb 964a28a86ee90d3131078bd7cef32ec65ccdd39c914dfe623ca3f9a06baf6390 283408 libecpg-dev_15.4-0+deb12u1_mips64el.deb 130a6e8d12fe3c8413d2a94618d6f76b58def013da51661e9eb0fa087debf5ee 116532 libecpg6-dbgsym_15.4-0+deb12u1_mips64el.deb 6164b22a479da05a13f670a933d3f563cf0e076de786837a889745ec010e7bf1 54880 libecpg6_15.4-0+deb12u1_mips64el.deb 9ee801d56758d20c1949005a124e01791f18a27ed1586dfb12ce0b217006af9e 92532 libpgtypes3-dbgsym_15.4-0+deb12u1_mips64el.deb 68500f787b0748af49fa2184546f6579c56ee49e93a7aa8f16440ccbfb0d2e87 40124 libpgtypes3_15.4-0+deb12u1_mips64el.deb e7471779b1188c4b824681e4bfc86d8f951aac9ed78d48365d07eef4b1d38e75 146756 libpq-dev_15.4-0+deb12u1_mips64el.deb 9b4f6d6bdca2253bdb9cca63b2e3154d994ed129d65bde8f1f4f4f2b81c70257 286168 libpq5-dbgsym_15.4-0+deb12u1_mips64el.deb ff3cef423a38e77c94b0b5e0a3740eec99663fbadc601ec09d6897697dacb78f 173900 libpq5_15.4-0+deb12u1_mips64el.deb 78f33d19eac37c749b335db987af614e2bdd0b09ee4a671624d44785a9b8f581 16863740 postgresql-15-dbgsym_15.4-0+deb12u1_mips64el.deb 2b5b0260eaebbafe48b1ae192a1ff5af8bc6a3b4cec72566919c3058809528b1 16878 postgresql-15_15.4-0+deb12u1_mips64el-buildd.buildinfo 978254a82c6dc196f9ea73e8cf37a6ccd5ac557eb8e9dbde6ffc937fac480b63 16196296 postgresql-15_15.4-0+deb12u1_mips64el.deb b40e201f529208aca453bcd63082b210ef2dbfb7d78e86326f4b7fcfa9b3aed5 2403708 postgresql-client-15-dbgsym_15.4-0+deb12u1_mips64el.deb d0ccbfd4d5f162238f12bd9095a4b0b7368d19e483e4f1699dbe414254c75da7 1637512 postgresql-client-15_15.4-0+deb12u1_mips64el.deb 1ff9ad508e9afdf1ee9a4f6d1959d030119e71b77c611de2a88ad0e4a9249792 190180 postgresql-plperl-15-dbgsym_15.4-0+deb12u1_mips64el.deb e06daf875451df5dfcf2d93e97829a646936bf0e93baf6c3b4388549eb061481 82152 postgresql-plperl-15_15.4-0+deb12u1_mips64el.deb 722aeb554af50a51ee5017b5bb2ce2ec42150d8f3996ede43d3a93f9d9c1ba93 182240 postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_mips64el.deb e8075d421221dc696fffc237388639e668531ffb2f59e9a8bb8be2a27d5317d2 101300 postgresql-plpython3-15_15.4-0+deb12u1_mips64el.deb ddec16e9345a5619974d795b84538c97b4d03595eb43e138ba238f5f463534b8 81312 postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_mips64el.deb b20a237e25e8db7aca6c18631ea2aec936320e25399a4a0c4b564edb4bf00137 36252 postgresql-pltcl-15_15.4-0+deb12u1_mips64el.deb 2858ccbe35542c811ec21ba8dc60bd120aac1c4eb2e8d9ccdb00988477b4663b 1143764 postgresql-server-dev-15_15.4-0+deb12u1_mips64el.deb Files: c66dd425aadc13b29cebefd5af13fa5d 39776 debug optional libecpg-compat3-dbgsym_15.4-0+deb12u1_mips64el.deb a8def256d5469ef6b44f795be7a13559 19140 libs optional libecpg-compat3_15.4-0+deb12u1_mips64el.deb b84f17e565845c056d6f6a3f901ecd69 249736 debug optional libecpg-dev-dbgsym_15.4-0+deb12u1_mips64el.deb 28df99370e0edbd23a1f74a4df89ee8f 283408 libdevel optional libecpg-dev_15.4-0+deb12u1_mips64el.deb b092b4f1094df9cb69183aa2f0343a01 116532 debug optional libecpg6-dbgsym_15.4-0+deb12u1_mips64el.deb 631e36d10ba01d3658f60d56b0a1a577 54880 libs optional libecpg6_15.4-0+deb12u1_mips64el.deb 8b9ab400eb009a7e5e68c77a5532c63b 92532 debug optional libpgtypes3-dbgsym_15.4-0+deb12u1_mips64el.deb dc0cae616f09982e369cb57e40de60f5 40124 libs optional libpgtypes3_15.4-0+deb12u1_mips64el.deb e2958112f338ee5cc900e18b13c46991 146756 libdevel optional libpq-dev_15.4-0+deb12u1_mips64el.deb 8852747e81670efd69651df75f78514f 286168 debug optional libpq5-dbgsym_15.4-0+deb12u1_mips64el.deb 4bd4ab92fa9578d71ae02d0efa9f93b1 173900 libs optional libpq5_15.4-0+deb12u1_mips64el.deb 026708e977486ffc52fbceefe2007dfc 16863740 debug optional postgresql-15-dbgsym_15.4-0+deb12u1_mips64el.deb 3192dcad59c949b6e12c6355cf7aaa05 16878 database optional postgresql-15_15.4-0+deb12u1_mips64el-buildd.buildinfo 6e676174757d1d76d0eaca9ca8b48d0e 16196296 database optional postgresql-15_15.4-0+deb12u1_mips64el.deb 951de0388931fb5984cf845875bb7830 2403708 debug optional postgresql-client-15-dbgsym_15.4-0+deb12u1_mips64el.deb 2a76bcb5aea9b9f579fd4742a80b415d 1637512 database optional postgresql-client-15_15.4-0+deb12u1_mips64el.deb 9a7c8ba04d590cca493e97e1cd522dc0 190180 debug optional postgresql-plperl-15-dbgsym_15.4-0+deb12u1_mips64el.deb 7fcabf7c2ed47fbdd62fec3580c90817 82152 database optional postgresql-plperl-15_15.4-0+deb12u1_mips64el.deb 3a2e5ba1bd9860f89628c576fd17af86 182240 debug optional postgresql-plpython3-15-dbgsym_15.4-0+deb12u1_mips64el.deb 75f35118ecbb9a07b940099a78c4438d 101300 database optional postgresql-plpython3-15_15.4-0+deb12u1_mips64el.deb 654c6d83895e176c3b9fc71ff60bd0ce 81312 debug optional postgresql-pltcl-15-dbgsym_15.4-0+deb12u1_mips64el.deb ba9fdf3bf106f503acb8fba14052bbf8 36252 database optional postgresql-pltcl-15_15.4-0+deb12u1_mips64el.deb 0204062c2c720bc9e855018c6b366275 1143764 libdevel optional postgresql-server-dev-15_15.4-0+deb12u1_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERCYbPUzzGtvq4mlq066AbFDPUlEFAmUoD2kACgkQ066AbFDP UlH4QRAAmk9RER9wE9Ua85MqYoXZxP64xZBXrr0y9UGX1G+ym61leEGhYRydsVfX MXXNxM/tcL7NuGrnKXVqY2mkZ+K8yVRh3SudYXWjsYkrI+j7lqhW0AdyhlBdFWqp 83f3JiCnNKGsW2hSgy7Mban5F7zBCLZndjIgvPC9L6rSgkZotcTDFAZdFuUErjf0 FkjaCtB5gIWJ9Xcc5j5FV8eNwVvJrg4Yi8Y2tEhxwbxfP2rILhhBVKv4q1vgt2Id r7dts2KoAltlprorqRyMtt64zG62qLul3fEaIPIqiqnvdI+xNdV9/jPlABdodW6w jN4Y4irDgDnKcSdIP8SoUOBuHvRRnUuwCvLHsAA5fRI1iysqoz8YQI6fUSciZKq2 dHuj7K37LcygYBh26AnqUrbY/zL09j+bVoIhuOS2n97acOqmQu1pvjs3E4AHntYK XNDyNSlRaxriwyQ2h9NEr7otbD6KYv6zxQckjLB8WGtOIZm9Jdg3ZwTTG6Umez6g Ub5uEhqtdUWxXxJbgiF72S7Pmp5+OVXWwKCp4YI/eXhekvmo8Ye5x7ElV07xEQnE kxew1ChLsB5wJBokdUA3g3yqbIouETX2cX1SvKd3A1/FE5uU/HKaZTzFZML/sZqT +pqdPs+THJWcOBGeXixePzaDE0ReR9WH1HtrmSuou4y8TbGTa3Q= =Dbf7 -----END PGP SIGNATURE-----