-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 07 May 2024 11:24:26 +0200 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: amd64 Version: 15.7-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.7-0+deb12u1) bookworm; urgency=medium . * New upstream version. . + Restrict visibility of pg_stats_ext and pg_stats_ext_exprs entries to the table owner (Nathan Bossart) . These views failed to hide statistics for expressions that involve columns the accessing user does not have permission to read. View columns such as most_common_vals might expose security-relevant data. The potential interactions here are not fully clear, so in the interest of erring on the side of safety, make rows in these views visible only to the owner of the associated table. . The PostgreSQL Project thanks Lukas Fittl for reporting this problem. (CVE-2024-4317) . By itself, this fix will only fix the behavior in newly initdb'd database clusters. If you wish to apply this change in an existing cluster, you will need to do the following: . In each database of the cluster, run the fix-CVE-2024-4317.sql script as superuser. In psql this would look like \i /usr/share/postgresql/15/fix-CVE-2024-4317.sql Any error probably indicates that you've used the wrong script version. It will not hurt to run the script more than once. . Do not forget to include the template0 and template1 databases, or the vulnerability will still exist in databases you create later. To fix template0, you'll need to temporarily make it accept connections. Do that with ALTER DATABASE template0 WITH ALLOW_CONNECTIONS true; and then after fixing template0, undo it with ALTER DATABASE template0 WITH ALLOW_CONNECTIONS false; Checksums-Sha1: fb5f9b183f041d29c366128cfeb36e4dfeebcbdd 38120 libecpg-compat3-dbgsym_15.7-0+deb12u1_amd64.deb 6c95c442e3df4762d0f507998aa2a5cc42ac20e0 22196 libecpg-compat3_15.7-0+deb12u1_amd64.deb 4b95f075612e66485ee360a362bb027b010799c6 280776 libecpg-dev-dbgsym_15.7-0+deb12u1_amd64.deb 0c57bedfa43d034c6810ba0c3bc875a3238bce81 294940 libecpg-dev_15.7-0+deb12u1_amd64.deb f3d6580fced9a7f76ba7145cc3cd83d400f6950d 113144 libecpg6-dbgsym_15.7-0+deb12u1_amd64.deb a9421dc9a6fe99b835dc0006989d70c5a75ead1d 60284 libecpg6_15.7-0+deb12u1_amd64.deb 43a326590d099b7af07cc1e8d71f09de04f3cb44 88328 libpgtypes3-dbgsym_15.7-0+deb12u1_amd64.deb 144ee6f4224326f93d80f361faefba642a91603f 43936 libpgtypes3_15.7-0+deb12u1_amd64.deb 54a6ec88d8a83ac7968746bef2ba27f5e3a55bcb 143308 libpq-dev_15.7-0+deb12u1_amd64.deb 0d5c76bae458019875bec4d820f4460a88c3a57a 277012 libpq5-dbgsym_15.7-0+deb12u1_amd64.deb a93950c51e1f9d2435763f2a114e8e33dbbae58c 188132 libpq5_15.7-0+deb12u1_amd64.deb 73b8502a29bb7eba5c19b773facc12a245602c18 16862388 postgresql-15-dbgsym_15.7-0+deb12u1_amd64.deb ef3bd61302c529d6b88b574b9e5514e9daef76dc 16946 postgresql-15_15.7-0+deb12u1_amd64-buildd.buildinfo ae4bab1dfcb59fceb6a92d6d94fc7a5d0fecdf03 16813416 postgresql-15_15.7-0+deb12u1_amd64.deb 508928a3cac3237fd3cba4f4528f405af95bbee7 2419508 postgresql-client-15-dbgsym_15.7-0+deb12u1_amd64.deb 23406cb0e8f211475bebfeb8f08daeb4666cc86f 1698680 postgresql-client-15_15.7-0+deb12u1_amd64.deb 86b674058884959fab93c2d8d569d1aa4d9b4746 186808 postgresql-plperl-15-dbgsym_15.7-0+deb12u1_amd64.deb 7da527959d070acb0925afe9e1968157e9c9740d 89216 postgresql-plperl-15_15.7-0+deb12u1_amd64.deb 452013333b0d82147afcc2b74a559dfafb912ee5 178236 postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_amd64.deb 282bd0990db78c916d93f5f10255b4b6be51de65 110572 postgresql-plpython3-15_15.7-0+deb12u1_amd64.deb 6dae47d97ace541981c815e940c02494e797f97e 79516 postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_amd64.deb 5380f53bd89caf8c5546ca75b7bf456b85fdab42 40884 postgresql-pltcl-15_15.7-0+deb12u1_amd64.deb 280015a2d19fdd41bc880aea4d9cb142d772e47f 1141320 postgresql-server-dev-15_15.7-0+deb12u1_amd64.deb Checksums-Sha256: 01027aefa2e77f8301ce8a654404055e1e5265a40e607007d98291c897b00b6a 38120 libecpg-compat3-dbgsym_15.7-0+deb12u1_amd64.deb 3669d98784d9dcd057b6e54edaad6c753450b073864b9d9daccbe9cce5770899 22196 libecpg-compat3_15.7-0+deb12u1_amd64.deb d63a440e9f4e7f2fdb3dfa8ff4fe47803be6eeec1737f615818f59144692bfb9 280776 libecpg-dev-dbgsym_15.7-0+deb12u1_amd64.deb 43c058d93ce0b09b995fc54e567eebf8df565035df10281d719d64930aa47be9 294940 libecpg-dev_15.7-0+deb12u1_amd64.deb f4e34cc21b73fea3b61debf189f22131ac090df9992b57e2c9ed32a7ae059947 113144 libecpg6-dbgsym_15.7-0+deb12u1_amd64.deb 295feaef775e93131b7c191042d7842d089e9a79f796594ba56177510e46467d 60284 libecpg6_15.7-0+deb12u1_amd64.deb f2035b74d6be59ebe02b9ad3d797cc9642c1d166a801ab13abf7e8b6593eed9b 88328 libpgtypes3-dbgsym_15.7-0+deb12u1_amd64.deb d140a60c0b5fad143df79d199f6923b206b62e27b1f40bae56724626c2d717ea 43936 libpgtypes3_15.7-0+deb12u1_amd64.deb db752918dd6f65d3fd112cdd2190f323c69aee3f9c6b0271963de44c31af3174 143308 libpq-dev_15.7-0+deb12u1_amd64.deb 0cbbd0563b84c6369064420ff9296e6636d201b66c63f65ea8860db0ea66af28 277012 libpq5-dbgsym_15.7-0+deb12u1_amd64.deb 78c33c472d48be2b26b7f51efe1eaf1bcf597f9da8afa5278ce638eadc6d65d4 188132 libpq5_15.7-0+deb12u1_amd64.deb a1c29de824617dd124610f00762798282a9d0e9cc9813dcbf72f16bc0b4f5b84 16862388 postgresql-15-dbgsym_15.7-0+deb12u1_amd64.deb e975576f3adaebbccc9f5f89e18ecf0b383d6fcecc4ea9ab30e9bc7fa993f4b5 16946 postgresql-15_15.7-0+deb12u1_amd64-buildd.buildinfo 90cd885d5bfa753184d66b2af0862aaaa801ea4449934e0b958dfdb614d83d24 16813416 postgresql-15_15.7-0+deb12u1_amd64.deb 742155568cda53d70c3b6d9678bf35b3bcfd57a090b0a2e6dcae5674f1f1ef24 2419508 postgresql-client-15-dbgsym_15.7-0+deb12u1_amd64.deb 785a7df4c016d7a66bf46e57c93cb541dc5c2c0c79a76c83259a51c6d76b5083 1698680 postgresql-client-15_15.7-0+deb12u1_amd64.deb 61b2b4fe6bb0b98ee7bbfe62f505c638199bb4ae521a5ee9325d5805f0f607dd 186808 postgresql-plperl-15-dbgsym_15.7-0+deb12u1_amd64.deb 3fd404269fd96a7bad3fe8e797b4eba5b721f51a3c54a90ea2dfedd21abdd7e9 89216 postgresql-plperl-15_15.7-0+deb12u1_amd64.deb 5e4f2cf6b9b1500127f1223507e32a549086c94e6cf3357ac5439e284124d2c6 178236 postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_amd64.deb 2eb375370a83d40b18626e1394c153598fbb068b5c0ecddc64739b863f30decd 110572 postgresql-plpython3-15_15.7-0+deb12u1_amd64.deb 478384f491fa925418641b6e23a1b904e70d6130b4692fbfa05fafab9d27e500 79516 postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_amd64.deb 837979ed1761e43cbecf3a6c0607cd051caad0db5583750db460c919d97efcae 40884 postgresql-pltcl-15_15.7-0+deb12u1_amd64.deb 6730ab21b3e5744f0bb3976d72d4b49e5def0c88c515316c8256dec3238a4c14 1141320 postgresql-server-dev-15_15.7-0+deb12u1_amd64.deb Files: 3b7b6cc7f50391f75b1734b944bb6798 38120 debug optional libecpg-compat3-dbgsym_15.7-0+deb12u1_amd64.deb 8b8f96000e5c7e6e3c411a37e473c048 22196 libs optional libecpg-compat3_15.7-0+deb12u1_amd64.deb 553fce489cecf799a0603151fc28ac07 280776 debug optional libecpg-dev-dbgsym_15.7-0+deb12u1_amd64.deb 458efdc83474a5dc82ed27957fa3b6e5 294940 libdevel optional libecpg-dev_15.7-0+deb12u1_amd64.deb 8a4c11f750896aa08cd8b567ccd87b16 113144 debug optional libecpg6-dbgsym_15.7-0+deb12u1_amd64.deb 81c1078f0a4abda7968ee85c478d209d 60284 libs optional libecpg6_15.7-0+deb12u1_amd64.deb 378d6126a327585d6773a11af43d1a08 88328 debug optional libpgtypes3-dbgsym_15.7-0+deb12u1_amd64.deb 3962ea1a04ece45ff9a0a3d6333e4aa1 43936 libs optional libpgtypes3_15.7-0+deb12u1_amd64.deb a96b5092dae3a4a55ee6510f8beae14a 143308 libdevel optional libpq-dev_15.7-0+deb12u1_amd64.deb 2f3cf4c4cd6d961529bf5984d0d14a62 277012 debug optional libpq5-dbgsym_15.7-0+deb12u1_amd64.deb 2dc7eba4a33f0ca6edbfc522063fa04a 188132 libs optional libpq5_15.7-0+deb12u1_amd64.deb e50027452f35f14c9465088ece034513 16862388 debug optional postgresql-15-dbgsym_15.7-0+deb12u1_amd64.deb 1b1cd469b7bdf8acbc3dbaaf27ec62ef 16946 database optional postgresql-15_15.7-0+deb12u1_amd64-buildd.buildinfo d340a7e6e924db045d7c32d6872e9783 16813416 database optional postgresql-15_15.7-0+deb12u1_amd64.deb 1ca56829c447de27ffad2ffae9fb3000 2419508 debug optional postgresql-client-15-dbgsym_15.7-0+deb12u1_amd64.deb 577c7fdd802075fd89acdaa21da6cc2c 1698680 database optional postgresql-client-15_15.7-0+deb12u1_amd64.deb 8e335383a685e11d76c7053d01b3e777 186808 debug optional postgresql-plperl-15-dbgsym_15.7-0+deb12u1_amd64.deb 157fb503ce36301fb38b617b5d447cb2 89216 database optional postgresql-plperl-15_15.7-0+deb12u1_amd64.deb 906aba97a7bb3c82ae621bbcf3294180 178236 debug optional postgresql-plpython3-15-dbgsym_15.7-0+deb12u1_amd64.deb 56187528dbb385f9c8c48bdcc853fb85 110572 database optional postgresql-plpython3-15_15.7-0+deb12u1_amd64.deb 1a3fd0ea32bb29c1d8fe9110e242a31a 79516 debug optional postgresql-pltcl-15-dbgsym_15.7-0+deb12u1_amd64.deb bd5b5c5eca308c7406cebfcf125940b6 40884 database optional postgresql-pltcl-15_15.7-0+deb12u1_amd64.deb 4a0dc51e70dbbc651cd9a6f5f5aea60d 1141320 libdevel optional postgresql-server-dev-15_15.7-0+deb12u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEgdRoRGwEM09wlaMzOni7ZmUpKEcFAmZLzKsACgkQOni7ZmUp KEfKJg//TZ0NorRQazd04KKWa+mvyr9wv0lDlPcry2W/RtQEWnQ+gDN2tyasCOW2 fm80tfHRjCfSASdNzO8O9X/drjr95SQ3fqBcOt1ee8UAy7x5piMOlF/G0XW+SBWZ PNx/umq1DS6XSlexULcDd4zNmV1DVGmjF8RbN0pcvwu10ADiJtYJ1ZrSSslkJl9o JxCEJ7VU5ROkO/wtziTzWd8SRHrigz4Lk3ZshJndMO9d5dPkeLFulvPaHJ6Xvg66 446mxlA3WUcSOC7j8zDfaY16AUgH36k84j6AcSwgco+NVpDQc+ZFKvUQmUOfjosI jff25fmYJI689JqBid7pv9We4dzalYsVGb8mfMy+pA/RpJ/Wjt0XkQEpQaOFTJN3 N4xFocvgeEjsXzqk6lqIDXg+TXoBXomfNpLvNya/BZDe1A1AlbutmdtJy1RFHGzp TC38bRlZ5bCW93TJbseAEMqvnlc6/3tvKyA1FGAZi+cmPUNk7xXowmLvkNB1Xxa8 RzTJErBRyQF/VRaAEnWqBezKyk77rsRzCMGkgRo3aySLQzum3JYB8xHI/hQrlb/6 nMqbt+I0QOaRtAt/s3n04I9CbcghKfvDsmLUppUJe4rmfhuQVplvGcOesVeFU/dv ofLInSusiYCon521EngIjRNkj/L8fm7fKOXxQgdJyTUUuTR2vG0= =id6S -----END PGP SIGNATURE-----