-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 07 May 2024 11:24:26 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: ppc64el Version: 15.7-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-osuosl-02) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.7-0+deb12u1) bookworm; urgency=medium . * New upstream version. . + Restrict visibility of pg_stats_ext and pg_stats_ext_exprs entries to the table owner (Nathan Bossart) . These views failed to hide statistics for expressions that involve columns the accessing user does not have permission to read. View columns such as most_common_vals might expose security-relevant data. The potential interactions here are not fully clear, so in the interest of erring on the side of safety, make rows in these views visible only to the owner of the associated table. . The PostgreSQL Project thanks Lukas Fittl for reporting this problem. (CVE-2024-4317) . By itself, this fix will only fix the behavior in newly initdb'd database clusters. If you wish to apply this change in an existing cluster, you will need to do the following: . In each database of the cluster, run the fix-CVE-2024-4317.sql script as superuser. In psql this would look like \i /usr/share/postgresql/15/fix-CVE-2024-4317.sql Any error probably indicates that you've used the wrong script version. It will not hurt to run the script more than once. . Do not forget to include the template0 and template1 databases, or the vulnerability will still exist in databases you create later. To fix template0, you'll need to temporarily make it accept connections. Do that with ALTER DATABASE template0 WITH ALLOW_CONNECTIONS true; and then after fixing template0, undo it with ALTER DATABASE template0 WITH ALLOW_CONNECTIONS false; Checksums-Sha1: 08b799a581ba5f045a2dc0e488141346e7cd8938 38728 libecpg-compat3-dbgsym_15.7-0+deb12u1_ppc64el.deb ebe7381a74f62a9656768f816a839449e6897dd0 23544 libecpg-compat3_15.7-0+deb12u1_ppc64el.deb 0e4e93a16acd3bc0749c983261a9a4ec21af9f2e 223376 libecpg-dev-dbgsym_15.7-0+deb12u1_ppc64el.deb d5bd1384bdfa644092ada6788a887c3900e6250f 298312 libecpg-dev_15.7-0+deb12u1_ppc64el.deb 21d4b3f175b41bd65a320e6bbb99a07adba4b9a1 113248 libecpg6-dbgsym_15.7-0+deb12u1_ppc64el.deb 84caa50afd7f7c54ad96b6f5578c400ab51d01e5 64048 libecpg6_15.7-0+deb12u1_ppc64el.deb 542f602aba69c398f10ad02f9da47f9fb16e1db8 90888 libpgtypes3-dbgsym_15.7-0+deb12u1_ppc64el.deb 135a5f1c52c0ee32f4752d258d958159493985c7 47740 libpgtypes3_15.7-0+deb12u1_ppc64el.deb 24d243f9da39951d4c9558bfed56d61b5bd0b1be 155636 libpq-dev_15.7-0+deb12u1_ppc64el.deb 6927e3c32a8ad3ee506c81e1f833b5c3710096a7 285188 libpq5-dbgsym_15.7-0+deb12u1_ppc64el.deb a5585a7237c34e757f54f29792c5945fe201ec39 198784 libpq5_15.7-0+deb12u1_ppc64el.deb 58d3943708e695e6daa9a3e65c6ac930a51eb859 16671264 postgresql-15-dbgsym_15.7-0+deb12u1_ppc64el.deb 1341af173ca06dd00eb017a53e456c890b9a36d0 17040 postgresql-15_15.7-0+deb12u1_ppc64el-buildd.buildinfo 432ededd435e46e877ae97d620c2a98c7ce91a2b 17141244 postgresql-15_15.7-0+deb12u1_ppc64el.deb 95c0c760dfaf0ae2ceb7f733bb31c76ddb07bf54 2314900 postgresql-client-15-dbgsym_15.7-0+deb12u1_ppc64el.deb 185454cec9a549549ccdde266f7f12f225f548dc 1725396 postgresql-client-15_15.7-0+deb12u1_ppc64el.deb e59ac4cf2c0262a36fc5a32b06acb03dd4eef0f5 186452 postgresql-plperl-15-dbgsym_15.7-0+deb12u1_ppc64el.deb dce7d1294543b3749cef94468e92736f340db2b9 89904 postgresql-plperl-15_15.7-0+deb12u1_ppc64el.deb eb99daf4f0c6c42316d3bfb4b408a8aafb640b8b 176132 postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_ppc64el.deb 5196540dc792faacd8e3603bb9f9dee9d6754203 110448 postgresql-plpython3-15_15.7-0+deb12u1_ppc64el.deb 3883b7b3783695c82a3a9ea0c27d541726c6cb00 79924 postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_ppc64el.deb a868616d8f9907ef6fe0fa716c198946b6596a3e 41060 postgresql-pltcl-15_15.7-0+deb12u1_ppc64el.deb dd62428a5811d73102a055fb8393e689c4d418dd 1155204 postgresql-server-dev-15_15.7-0+deb12u1_ppc64el.deb Checksums-Sha256: 87b4e5f6f9d442ea82d57a4052870d813c3c0eb2de502f2551912633ba15a435 38728 libecpg-compat3-dbgsym_15.7-0+deb12u1_ppc64el.deb e13966375324338ee13d224764ea7d995d38f39465675f4b054cf92805ede171 23544 libecpg-compat3_15.7-0+deb12u1_ppc64el.deb aeae02e2bbac5a3fd4327c97ef462e2ee916078aeded22ca30691ecf25b1fc8f 223376 libecpg-dev-dbgsym_15.7-0+deb12u1_ppc64el.deb 97d6c3ce2df1456b220ba394673524935abfac6e56e33ef501f19166859de190 298312 libecpg-dev_15.7-0+deb12u1_ppc64el.deb b7de71a3c829e93d3e16df0148c62bdf1a21fce107b8840766584d27b65d2ea7 113248 libecpg6-dbgsym_15.7-0+deb12u1_ppc64el.deb a4113fad526f8f849669464b989bf11322c8ef87968343427a5be5d4f869250a 64048 libecpg6_15.7-0+deb12u1_ppc64el.deb a178a00f8d0fb38a0e4f0d905c7b1c54a85725f083e87a3cbf837153c56c7b67 90888 libpgtypes3-dbgsym_15.7-0+deb12u1_ppc64el.deb 5e4b632ed173ba824e8dcdc2bcc73fde66f2b7110044d6a9f83a4f3a80497f70 47740 libpgtypes3_15.7-0+deb12u1_ppc64el.deb 0282b84d36402fcec3f41eaac2b7fd747485173a987abaf8f4f3dae2fda70a4f 155636 libpq-dev_15.7-0+deb12u1_ppc64el.deb 70d54e6e79b103ff9a1300aa9b8e71719c34a6f6f2d15cc8638f998343fa8864 285188 libpq5-dbgsym_15.7-0+deb12u1_ppc64el.deb b97fce9dff02b63e22523d8d8b2dc3651dc644a44ac82884d4a12b0b99bf9223 198784 libpq5_15.7-0+deb12u1_ppc64el.deb 933b222e01ff592081f4c7c293d0ea9ed064f0565e3d79dd0e0eddc99258a1af 16671264 postgresql-15-dbgsym_15.7-0+deb12u1_ppc64el.deb b3b5db89411fa6dff11b5e3fd7d6b665aaa11613d1b68fe52918beb46a608707 17040 postgresql-15_15.7-0+deb12u1_ppc64el-buildd.buildinfo 47f45b6e1798e887a96d215c9fc7c402d5702f04c1362c4031b4fa68956c5544 17141244 postgresql-15_15.7-0+deb12u1_ppc64el.deb f91975b05d3c2c8a5d7faba172311e50b9679c8e01de189f7fcfc623803341d4 2314900 postgresql-client-15-dbgsym_15.7-0+deb12u1_ppc64el.deb 10feedaf7f56def959ca7b413bb78383bf786da90e8e220697d743320d59c9ae 1725396 postgresql-client-15_15.7-0+deb12u1_ppc64el.deb 5cb32b229874b6467eb33a272ac19b434f3c16f4c2baa8b2ca3c81b7ca0a9db7 186452 postgresql-plperl-15-dbgsym_15.7-0+deb12u1_ppc64el.deb 49df46d03a31f50e6a580971661f852c4f642b09ead833907318cff0a7e1e2cb 89904 postgresql-plperl-15_15.7-0+deb12u1_ppc64el.deb a6e43250070ff4df6a095475e25dfb17cfff1dca29f97e162a80900bd41682cd 176132 postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_ppc64el.deb 2cdbe6b3e6fd6fa4d2bd836cd9094495cfa6cc50d89071aec45b780bf629d5e3 110448 postgresql-plpython3-15_15.7-0+deb12u1_ppc64el.deb 01822b3ba0a608d803c75fd4696cb20c4a8882212345c1e731c7fa60208fc0d3 79924 postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_ppc64el.deb cf5cf1879900c75f9e729aa6fc70d859b90fe367efadb3aac2288ede410f57ab 41060 postgresql-pltcl-15_15.7-0+deb12u1_ppc64el.deb ade44e68fd8e8dc83d0fd17a52dd2f5568e42729b3ebdab2c2cec2c799d49257 1155204 postgresql-server-dev-15_15.7-0+deb12u1_ppc64el.deb Files: af1df02511cc8e6cf1372ad510402ec5 38728 debug optional libecpg-compat3-dbgsym_15.7-0+deb12u1_ppc64el.deb 5d9dced0038dc1cdb8f46bc0c063d8c8 23544 libs optional libecpg-compat3_15.7-0+deb12u1_ppc64el.deb 111e75e1d62ed8b7aade326f30658116 223376 debug optional libecpg-dev-dbgsym_15.7-0+deb12u1_ppc64el.deb e3714285a0216fb7e43fcaefb81061a6 298312 libdevel optional libecpg-dev_15.7-0+deb12u1_ppc64el.deb 95af46e43e3440ac2966cb4c1de20e79 113248 debug optional libecpg6-dbgsym_15.7-0+deb12u1_ppc64el.deb 84ecbb061530eae125e10034364527ca 64048 libs optional libecpg6_15.7-0+deb12u1_ppc64el.deb 38eb9f697bd99b87f17311733faad91d 90888 debug optional libpgtypes3-dbgsym_15.7-0+deb12u1_ppc64el.deb d4399ebcf79fb762422eebbf42661c05 47740 libs optional libpgtypes3_15.7-0+deb12u1_ppc64el.deb df7e3261a32ec85ec4e7ffce592869f1 155636 libdevel optional libpq-dev_15.7-0+deb12u1_ppc64el.deb 02e595b67af345f8737aa0f406805b96 285188 debug optional libpq5-dbgsym_15.7-0+deb12u1_ppc64el.deb 91d43fb89dc78f7b01c90b329083ba7d 198784 libs optional libpq5_15.7-0+deb12u1_ppc64el.deb ccb9acd3bb3684135f4bd41005f4ff2e 16671264 debug optional postgresql-15-dbgsym_15.7-0+deb12u1_ppc64el.deb b08b2f352eb6b29e7b354cc1d84c180a 17040 database optional postgresql-15_15.7-0+deb12u1_ppc64el-buildd.buildinfo b57c275437483a1a88bb369553853947 17141244 database optional postgresql-15_15.7-0+deb12u1_ppc64el.deb 7d871ed9d8449479bdf1fa6d838fbb98 2314900 debug optional postgresql-client-15-dbgsym_15.7-0+deb12u1_ppc64el.deb 4793b5b10da54e0ff013b0effee08b79 1725396 database optional postgresql-client-15_15.7-0+deb12u1_ppc64el.deb bd9f3b8516398847cf157ba625fb687c 186452 debug optional postgresql-plperl-15-dbgsym_15.7-0+deb12u1_ppc64el.deb f04d9d79f545223ce0af12cf670dd623 89904 database optional postgresql-plperl-15_15.7-0+deb12u1_ppc64el.deb 40ac3d45415372d97193615dc340a4d1 176132 debug optional postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_ppc64el.deb 1feda2906c4a4de41b6389975fdf8185 110448 database optional postgresql-plpython3-15_15.7-0+deb12u1_ppc64el.deb 724d21a55f833d453c62b17464fb4ce8 79924 debug optional postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_ppc64el.deb e12e4e1c9ac9da2831325883801fc2ef 41060 database optional postgresql-pltcl-15_15.7-0+deb12u1_ppc64el.deb 235e1fb002796787f2ad244e37cc2601 1155204 libdevel optional postgresql-server-dev-15_15.7-0+deb12u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEHDNCkvGgp2XShfnByW8ECaj2byoFAmZLyPYACgkQyW8ECaj2 byp2txAAlBCfUddBnt8mX0dZvYk4uY4ffSrxpQaXUfd7En2HVELhEH/Y+42YBZnJ EAAgF8JJ/tkFzpXj2jYt7TxgUXdFe2/NpSAbZk40iRAbOTuJaPbjLivMxBFk/UPY 8D4xsuqUexs10hC1TJlgThGF0m5aoM4ViTvgQn6Y9/PvM8+1VrbYS4vLbC3OdmEu IBxZYxM2s5MTIWbjGaAgWyVvrSeMspS0SaNcAfPW64fxQCY8vSXEez03dE4JLesv Zp6lUclmTrAEuC0CMO0ciXJYWBUdTm+vMauoYTmyCcTHOk+ZgAnF2u+8Q518i8xG ubBXdJROIhx9axxUlc6OUD3pFI1XDMUFzFWxXevetrDj9Rs3nyocTRAIhvFooqGC hb45b40aK4u9ubySNNj/xdlzPn8L8wt+teS7nQUAtKpRsSYFLbCDndehYWSYcBrj +pOUiRG/mqb76VngAMpiOro7vq8UVj1YdQoD9lV+8N844PXQFxjhJjSxd6jOKOqG b2doDypCLLnPHAnV4/f3PvQgp9hFRulqQUVz8/IJNo4GZlJy3BdwWqCYghhi+zck n+zWcq05pGlGlcC7XgC2mEZKB/nJNmzUDVkr2cdSEgsWUAWBNHHEh6PBBAa8IxsK QlDRarkqIEV2VIrnuxRcYoMUhY2Wk5/R+3zrYD9yzzJTolOD+5E= =CWh3 -----END PGP SIGNATURE-----