-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 18 Feb 2025 11:59:37 +0100 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: arm64 Version: 15.12-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-conova-04) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.12-0+deb12u1) bookworm; urgency=medium . * New upstream version 15.12. . + Improve behavior of libpq's quoting functions (Andres Freund, Tom Lane) . The changes made for CVE-2025-1094 had one serious oversight: PQescapeLiteral() and PQescapeIdentifier() failed to honor their string length parameter, instead always reading to the input string's trailing null. This resulted in including unwanted text in the output, if the caller intended to truncate the string via the length parameter. With very bad luck it could cause a crash due to reading off the end of memory. . In addition, modify all these quoting functions so that when invalid encoding is detected, an invalid sequence is substituted for just the first byte of the presumed character, not all of it. This reduces the risk of problems if a calling application performs additional processing on the quoted string. Checksums-Sha1: 922527564536700d1bd2608091e7f0203be17f46 16500 libecpg-compat3-dbgsym_15.12-0+deb12u1_arm64.deb 4dd50dfa64b949e00cdd2b1d4cddddb9837cefcb 18516 libecpg-compat3_15.12-0+deb12u1_arm64.deb 70944074182ebd1f86e8f8d85cec39d22eb843df 274932 libecpg-dev-dbgsym_15.12-0+deb12u1_arm64.deb c930c1f0f5f29eeab9b99743795438faa90e8106 281884 libecpg-dev_15.12-0+deb12u1_arm64.deb d7eff0c4302cbd594f2d0e8133aac852bb54f8c0 113880 libecpg6-dbgsym_15.12-0+deb12u1_arm64.deb a3309b6b7a824bdb0cf4ffa10d56e7462cccd6ba 59984 libecpg6_15.12-0+deb12u1_arm64.deb a4c245e2ed39caad76f308767a13bcbf3839616d 87336 libpgtypes3-dbgsym_15.12-0+deb12u1_arm64.deb b3b99a3da99d1c78708cf7adb2b8c1b6f406f606 44268 libpgtypes3_15.12-0+deb12u1_arm64.deb c9f135ef84e1dcd5d9c72c9ae78760ade430d5c4 142632 libpq-dev_15.12-0+deb12u1_arm64.deb 0e278498a028506711641d2703175c341790a9a1 275052 libpq5-dbgsym_15.12-0+deb12u1_arm64.deb b8531df90f32426fd172660bffe8cebdad3c1755 184280 libpq5_15.12-0+deb12u1_arm64.deb 186f09f8eea98bbb0643b79f7eaa7e53e242fdcd 16887992 postgresql-15-dbgsym_15.12-0+deb12u1_arm64.deb dc0a9f916ad713c00c0dbfa6f01dcc4081a99704 17045 postgresql-15_15.12-0+deb12u1_arm64-buildd.buildinfo f1f473556811d8cfe4ba4111f4d7a99f2803ec21 16360436 postgresql-15_15.12-0+deb12u1_arm64.deb 4fb8235789a316e4a69ed56d936fd0efbe2eaf9f 2641468 postgresql-client-15-dbgsym_15.12-0+deb12u1_arm64.deb 78cec840d1eca87b82d5bc5a979ca229ed3a5b1d 1673232 postgresql-client-15_15.12-0+deb12u1_arm64.deb dc65b7c2270240b1c4a72002de1f61d25a2af513 183380 postgresql-plperl-15-dbgsym_15.12-0+deb12u1_arm64.deb e24fe9e21e31e0dd28c7788b5f3e3c5862cbde3d 88532 postgresql-plperl-15_15.12-0+deb12u1_arm64.deb 5b59b952d1925934c453134237f5ef4071fa1ae6 175604 postgresql-plpython3-15-dbgsym_15.12-0+deb12u1_arm64.deb a8103572f71e5bfeec24aee7be04ed719282aa74 109320 postgresql-plpython3-15_15.12-0+deb12u1_arm64.deb e8ed38c262ad979cdfad97cb9bea64a48a2354b5 79312 postgresql-pltcl-15-dbgsym_15.12-0+deb12u1_arm64.deb 7215a67bed3ead7b1742b41147dd0364f60e8ff4 42364 postgresql-pltcl-15_15.12-0+deb12u1_arm64.deb 77380c0ee9a2c03e7ebd5ba77612c33638d9a2e6 1144040 postgresql-server-dev-15_15.12-0+deb12u1_arm64.deb Checksums-Sha256: 5378f235a8878ef008f9a939e847baaa8e68ebe0a5877c5ebae6f5f2061a0408 16500 libecpg-compat3-dbgsym_15.12-0+deb12u1_arm64.deb 788aa5976eba4aadb5ee8cb35049a094e3c148ac00133500e976acfff20bf930 18516 libecpg-compat3_15.12-0+deb12u1_arm64.deb 1c581a840b2f7b19e587144abffbb7d37c35074f9841e0cf3b8178ca2ce06f0f 274932 libecpg-dev-dbgsym_15.12-0+deb12u1_arm64.deb 880320151da46b83cd1af1eddec6a1b8ce6798a36a26966bbe45c8ea78ea0939 281884 libecpg-dev_15.12-0+deb12u1_arm64.deb fc23b68c013ca6a8a86672281f35444943994fbad89b6ba6a38426767ced0867 113880 libecpg6-dbgsym_15.12-0+deb12u1_arm64.deb 407540205d9e45c8eb6813d12cd59e82d95544e3b2c6ded236ba6f0d203c8859 59984 libecpg6_15.12-0+deb12u1_arm64.deb 08b6b3382d4a22d35c1a8e5249655672178f6b3f4f0fd02f1f1ad5aaa2650b74 87336 libpgtypes3-dbgsym_15.12-0+deb12u1_arm64.deb 9a958a117cdc6d7fcc911b79c4f567e151c035dfc46788c4b0c2db80cddfd736 44268 libpgtypes3_15.12-0+deb12u1_arm64.deb b130b2929ff98b067364212e903b0af49b7501f03bcaa2a8941faf3701134c95 142632 libpq-dev_15.12-0+deb12u1_arm64.deb 4b59b94e88d364a6c66c36155e94bc75483e77d0cf8c720750452de574ebab33 275052 libpq5-dbgsym_15.12-0+deb12u1_arm64.deb 7048633dd45b04951e1c491fd7c4db52061dce37cce7854dcc41cbd38da6c1cc 184280 libpq5_15.12-0+deb12u1_arm64.deb f915bac8978b37f352e6a38ccb3e34ad8ff98038a409028efd969d3c9cc403e0 16887992 postgresql-15-dbgsym_15.12-0+deb12u1_arm64.deb e726bf54c3c34b43ab5eb194d2c0c3f75c828973bd58c0c5803fa47e4ab677ea 17045 postgresql-15_15.12-0+deb12u1_arm64-buildd.buildinfo 8475bc645b7b267818fdace37900c92c279ade9f2a8ea9d97beaa6876a05b5f7 16360436 postgresql-15_15.12-0+deb12u1_arm64.deb 3c90220fbe0178f98b714429c7f9f337685c445149a46ab36adc3a7701bb1b07 2641468 postgresql-client-15-dbgsym_15.12-0+deb12u1_arm64.deb 43f2c36bc9c58ddecb44895ec64f749f51c06ca0cc1a71a7e1bdafe6491c6e9b 1673232 postgresql-client-15_15.12-0+deb12u1_arm64.deb 8646cfb0364e7c4a5d4b70d3f3979d7c91485ae5e87f1dab3f8f406a6dcf3f86 183380 postgresql-plperl-15-dbgsym_15.12-0+deb12u1_arm64.deb 556106859447da9fd90e4973873b98cbf7bf7cfadb315681f35142619253521d 88532 postgresql-plperl-15_15.12-0+deb12u1_arm64.deb 199d6f71f325abcd5a576892c1736ad95ce24edde2c0ce319607db2550b7aca2 175604 postgresql-plpython3-15-dbgsym_15.12-0+deb12u1_arm64.deb 9b1321d4191aa821c4f72c8c48b0d6c25821ea465bc8068ef43168f3a588e477 109320 postgresql-plpython3-15_15.12-0+deb12u1_arm64.deb 51cc98bc2af20f11cb37520f8dcb036d14372bbbc33709454a7d2527b8d95921 79312 postgresql-pltcl-15-dbgsym_15.12-0+deb12u1_arm64.deb 0cffd2f4f090304d32c60bf900c8378b15bb32d5e7072338eca4cf400aa916cc 42364 postgresql-pltcl-15_15.12-0+deb12u1_arm64.deb bd330a01a0436419860f273e17d33c9c07930b6ba9025728b790d87d606fb694 1144040 postgresql-server-dev-15_15.12-0+deb12u1_arm64.deb Files: 1436b562da3b3964d7816b68d9e762eb 16500 debug optional libecpg-compat3-dbgsym_15.12-0+deb12u1_arm64.deb a69e3bd3e4af8d36660f917a850e9158 18516 libs optional libecpg-compat3_15.12-0+deb12u1_arm64.deb b6c212fffd254504bbd81503c43261dd 274932 debug optional libecpg-dev-dbgsym_15.12-0+deb12u1_arm64.deb c832baf775061716d00f61498a2d52a7 281884 libdevel optional libecpg-dev_15.12-0+deb12u1_arm64.deb c80cdcf5b554ad7fb3f20b6d277531d0 113880 debug optional libecpg6-dbgsym_15.12-0+deb12u1_arm64.deb a639b8e751d39c519f48e49810583752 59984 libs optional libecpg6_15.12-0+deb12u1_arm64.deb e8eaef73c83a0b2ed86f935c0f56c1f1 87336 debug optional libpgtypes3-dbgsym_15.12-0+deb12u1_arm64.deb 76be7214be77afcdbabff5c6e405ea2f 44268 libs optional libpgtypes3_15.12-0+deb12u1_arm64.deb 956ebdff30cae63668c3e15efb57736d 142632 libdevel optional libpq-dev_15.12-0+deb12u1_arm64.deb 5b8ef667b2848c9b8d32716c6aadbd9a 275052 debug optional libpq5-dbgsym_15.12-0+deb12u1_arm64.deb 9397982831aad9683b8915c1dcbc032c 184280 libs optional libpq5_15.12-0+deb12u1_arm64.deb 084da301d0258cc8cb066d104b475af5 16887992 debug optional postgresql-15-dbgsym_15.12-0+deb12u1_arm64.deb 0e2ff793f9a78f25ecc41a509b2fae05 17045 database optional postgresql-15_15.12-0+deb12u1_arm64-buildd.buildinfo 6d24d108b1886084a83e1a0542dea50c 16360436 database optional postgresql-15_15.12-0+deb12u1_arm64.deb e6b7d02158c3a3c7187190491c3febb1 2641468 debug optional postgresql-client-15-dbgsym_15.12-0+deb12u1_arm64.deb a7c1cc1e3e96f63fe6a5ec02621c7e8c 1673232 database optional postgresql-client-15_15.12-0+deb12u1_arm64.deb a9f75dca38832d0d59296b56cbe0008c 183380 debug optional postgresql-plperl-15-dbgsym_15.12-0+deb12u1_arm64.deb acd4a5d73d681b247534eabb7f0b9732 88532 database optional postgresql-plperl-15_15.12-0+deb12u1_arm64.deb ed90560d1b1adc445405df8e3cafbaca 175604 debug optional postgresql-plpython3-15-dbgsym_15.12-0+deb12u1_arm64.deb 7d8c59080935db85282df9a99a687d35 109320 database optional postgresql-plpython3-15_15.12-0+deb12u1_arm64.deb 6e84978db72cd36029bce007087dd711 79312 debug optional postgresql-pltcl-15-dbgsym_15.12-0+deb12u1_arm64.deb f575c14f27d56f690b17a66e7ebf65c2 42364 database optional postgresql-pltcl-15_15.12-0+deb12u1_arm64.deb 2806ffe809a4f648a05c3b030ef0f6e0 1144040 libdevel optional postgresql-server-dev-15_15.12-0+deb12u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEvEwFZ4bqkVI+Rh6t+N4VxR6LZYEFAmfDPnoACgkQ+N4VxR6L ZYEy2A/8D0sEcN2xhWj7dYJgy1yvZ4w/b9PHxToopMagiiACP10Q6IHWzxeZnxUz mlaQMSCPKquKWLI/XwDVXvPyViGwU7/NRnCSFzsWhQmGovIBoHulmqxJ+VdgeuEE vljPiVpKMPnpeaJOhYQJcigx4zcivq+JFAjIhbgFf3pS9FeyjnkINYhPN831wDwT pmF9HeA1uu/Wy8hyXprwAqm4gNLUUVwOMo0k3aRc++Kzru86OtR53fti/hWCGInG k4UzbMo3MLrEPoAmMfAemdi5eoGx777P1l9Vyydd02495O9A7a5weuNow/UOMooe 74AR88myZDSAevRCQg2n+J1yE0D/oQQQ6MmEOd+A1F5Le7+J1xkj1p1joRkW8jHr QOCVhFjQtm15lP5PkwDv17E73fu1DjCucI54wMr470HdJv97M0U+l6niGTXuXK8R Wql81/62r7Vm1UGaj19OJ/ye9P57YMS1Yyu2BxlrIOFwgXcgaYiZ1St5jqxO0wCi dW5TpEstQxdDLN29GdALBOMBjDSO1s59iCzegN81MoEZDeOeh67z8vewjC9aTuQm uDpBMNIxmNoessr5K1LdN9lmcpYhIyGFCvZdsmDqegIe0U6muHExylLdoncqRnH9 4fmHPhEfIudSdCMTvAhRAAVp0Xl4V6FjdJ8wK5ZEcayT4R8F09c= =a7dO -----END PGP SIGNATURE-----