-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 11 Feb 2025 11:27:41 +0100 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: arm64 Version: 15.11-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-ubc-02) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.11-0+deb12u1) bookworm; urgency=medium . * New upstream version 15.11. . + Harden PQescapeString and allied functions against invalidly-encoded input strings (Andres Freund, Noah Misch) . Data-quoting functions supplied by libpq now fully check the encoding validity of their input. If invalid characters are detected, they report an error if possible. For the ones that lack an error return convention, the output string is adjusted to ensure that the server will report invalid encoding and no intervening processing will be fooled by bytes that might happen to match single quote, backslash, etc. . The purpose of this change is to guard against SQL-injection attacks that are possible if one of these functions is used to quote crafted input. There is no hazard when the resulting string is sent directly to a PostgreSQL server (which would check its encoding anyway), but there is a risk when it is passed through psql or other client-side code. Historically such code has not carefully vetted encoding, and in many cases it's not clear what it should do if it did detect such a problem. . This fix is effective only if the data-quoting function, the server, and any intermediate processing agree on the character encoding that's being used. Applications that insert untrusted input into SQL commands should take special care to ensure that that's true. . Applications and drivers that quote untrusted input without using these libpq functions may be at risk of similar problems. They should first confirm the data is valid in the encoding expected by the server. . The PostgreSQL Project thanks Stephen Fewer for reporting this problem. (CVE-2025-1094) Checksums-Sha1: 1c76a5959b85be3e7a0573a467f58c5038472970 16500 libecpg-compat3-dbgsym_15.11-0+deb12u1_arm64.deb 259e2b9e18c6bb1f3ea4e0e38d4f5fad8db3496e 18200 libecpg-compat3_15.11-0+deb12u1_arm64.deb b75f1996a60e99bba2bfdc0b91cec08ee484760e 274920 libecpg-dev-dbgsym_15.11-0+deb12u1_arm64.deb eea5f23711842676085daadbb9eb61bdb83f8487 281372 libecpg-dev_15.11-0+deb12u1_arm64.deb 902034261521bfad4d7e03b3cce906d9705e62f9 113860 libecpg6-dbgsym_15.11-0+deb12u1_arm64.deb 2ea42f0ffa2e020015f8a05ca391a3608e642f1f 59876 libecpg6_15.11-0+deb12u1_arm64.deb f02bff2e34a92a1673a57c37560fd4360592045c 87336 libpgtypes3-dbgsym_15.11-0+deb12u1_arm64.deb 92c144019012f4396e8d7ade560ec42fcc55f598 43952 libpgtypes3_15.11-0+deb12u1_arm64.deb 3f3338cf678b22a8c8b511c2bc2c0952d7b5b042 142308 libpq-dev_15.11-0+deb12u1_arm64.deb 13adcba1e6a74230954a445e35ca386e53b193b9 275176 libpq5-dbgsym_15.11-0+deb12u1_arm64.deb 82bc2e90b616b770cddc1f14e4d87a6710803611 182328 libpq5_15.11-0+deb12u1_arm64.deb 3b68040cfbee71f95759bf2370fb8f0bb8798c5e 16881244 postgresql-15-dbgsym_15.11-0+deb12u1_arm64.deb 9d02e48d7fb7e8a6b4555eb02fafb32fc7646595 17045 postgresql-15_15.11-0+deb12u1_arm64-buildd.buildinfo 2c081810f89a007d888cf1f7058b9b23d4c60dc4 16384064 postgresql-15_15.11-0+deb12u1_arm64.deb 2695ed298df33ab63f329faebadae16f9a8dafa3 2648480 postgresql-client-15-dbgsym_15.11-0+deb12u1_arm64.deb 8de2cae0c4b49fa774d3476b0aa7326e938413c9 1671436 postgresql-client-15_15.11-0+deb12u1_arm64.deb 492aa41363f8c27865bf7fbe95377a2e10b0b38d 183404 postgresql-plperl-15-dbgsym_15.11-0+deb12u1_arm64.deb 018b60a738bc02ac44d93a1cec8cc80f7bdf1dcd 88236 postgresql-plperl-15_15.11-0+deb12u1_arm64.deb 143cd6008a34a7a13e7ec293314c86b2992d264a 175596 postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_arm64.deb b16706d194b3dd5fd2831c86b64da64f1eaeeed0 108848 postgresql-plpython3-15_15.11-0+deb12u1_arm64.deb d4331b0c57422d1a71678e8682b64490097734f1 79308 postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_arm64.deb 1cb499600b16aab6cffeda370d21740ba6d352b1 42064 postgresql-pltcl-15_15.11-0+deb12u1_arm64.deb 2ddc0c81c5fb544dc2bd579eb3c384e8c3af59f8 1143528 postgresql-server-dev-15_15.11-0+deb12u1_arm64.deb Checksums-Sha256: 5eadf6097edd19e70204d47155ef24c8a72d7003bb841323e1bdba93e35801b3 16500 libecpg-compat3-dbgsym_15.11-0+deb12u1_arm64.deb 772c19be6724c7ea2ec25ff175aa1efa5a29dad0af5611c0731e02288c3621fe 18200 libecpg-compat3_15.11-0+deb12u1_arm64.deb b9cedc2df1dccfd753911546c9fa48d694fa22783c2d250a3b48a001a9cb5f5b 274920 libecpg-dev-dbgsym_15.11-0+deb12u1_arm64.deb 87b4ca8c25f27b77df4919605f42d80178c01da86c7f4595b8bf81a16679009e 281372 libecpg-dev_15.11-0+deb12u1_arm64.deb e54b127e14278e6adb18478162157a4dbd6b46ccac103d3cd9ca630315a44137 113860 libecpg6-dbgsym_15.11-0+deb12u1_arm64.deb 5ae99013c26edd858b99b95cc789d8d00203b02b2961ade1eeaff60c8c3548d0 59876 libecpg6_15.11-0+deb12u1_arm64.deb e64e574ca475da8c5aedba87be97fecfbf874f4e313b88394d0e5b738513290a 87336 libpgtypes3-dbgsym_15.11-0+deb12u1_arm64.deb ed5bba8e29e9b4d2f09c1803913e3f6419c77d6231375de98e90219a1ed4df9b 43952 libpgtypes3_15.11-0+deb12u1_arm64.deb 3ecb00841e756afd19045bc2b98c32d527d2d411fa0c3dfdf250c4bca827d38d 142308 libpq-dev_15.11-0+deb12u1_arm64.deb 589405ed92078145558063b3a554fa7d8427b4dc946c34a09691eb20afa9b50c 275176 libpq5-dbgsym_15.11-0+deb12u1_arm64.deb 46e097a50ba4290c2cf1c14cbb43a677319d5fd69ca12842554114d62a6f5ed2 182328 libpq5_15.11-0+deb12u1_arm64.deb c7cb72eb0244bd24eb0a54a20f72e14e642134ae1d1ff9d23ac9db0a5bbd36e6 16881244 postgresql-15-dbgsym_15.11-0+deb12u1_arm64.deb bc84063d3e07724303e0093425cbac690fb95bbdde882fbb5f69d1bb4dfe91a5 17045 postgresql-15_15.11-0+deb12u1_arm64-buildd.buildinfo 055f5b58e1e01d63f6968a1d1c688dba062638e74d49d596d9bd353fcb6fd7e5 16384064 postgresql-15_15.11-0+deb12u1_arm64.deb ad72d405f077e1f617eaa84f2647adf758bbeadcb0c13f3f4f74ef19162c9e60 2648480 postgresql-client-15-dbgsym_15.11-0+deb12u1_arm64.deb 0ccc90be6c1fe957b4f69edc5cf19158f9e3aba51b04388615ba8e51ffaab670 1671436 postgresql-client-15_15.11-0+deb12u1_arm64.deb 73c7ee6bf576c71e9680aafb2a8c3d244b1d003bb0f83644cb11075395ef8ab9 183404 postgresql-plperl-15-dbgsym_15.11-0+deb12u1_arm64.deb 71e9665e1e1de1436a40df96bc65a9b96f8eb92ba68d7ab87c6a3f4035683b30 88236 postgresql-plperl-15_15.11-0+deb12u1_arm64.deb 66af9a2f508383a724cab0dd8ef412c9c25532fb8d9010eaef1682e417b362d9 175596 postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_arm64.deb da81596473aa734d8fa6c5d2f26be1ff97eda0c3c5035d75c11a9ff165e7093d 108848 postgresql-plpython3-15_15.11-0+deb12u1_arm64.deb 0149fa71c82b4ded63274e7dc8ddce599885d76fc031b3e4b54db717181e3afd 79308 postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_arm64.deb 301dcaf0d7eb8e22b4b5299eb7cdc3400a79fd55142bbd11812145abe0dae920 42064 postgresql-pltcl-15_15.11-0+deb12u1_arm64.deb 30a52a1f308c9a9c89c3f5fec3d7d9cbbac0a166fdad73a503b05b5fde0cf331 1143528 postgresql-server-dev-15_15.11-0+deb12u1_arm64.deb Files: 1a4b05065b69a05e7969c2c9fcd7ad4d 16500 debug optional libecpg-compat3-dbgsym_15.11-0+deb12u1_arm64.deb 5b1ee4fd25510ada42a86beae847db6e 18200 libs optional libecpg-compat3_15.11-0+deb12u1_arm64.deb 683e18f2bb2ce9ba899edc7416aabc8e 274920 debug optional libecpg-dev-dbgsym_15.11-0+deb12u1_arm64.deb f913636f034c46b5462bd491c7fc5d45 281372 libdevel optional libecpg-dev_15.11-0+deb12u1_arm64.deb 915e3226e6cf67844bdbacfc395a1d2d 113860 debug optional libecpg6-dbgsym_15.11-0+deb12u1_arm64.deb 91b998b45ac4b63f2c77256b446a1c3a 59876 libs optional libecpg6_15.11-0+deb12u1_arm64.deb 2a49ad3c4e077fd03630df6b018f1d6e 87336 debug optional libpgtypes3-dbgsym_15.11-0+deb12u1_arm64.deb fa329e8daffc306a0f0be060f821a8b7 43952 libs optional libpgtypes3_15.11-0+deb12u1_arm64.deb 0f186a1e644a933d4290e9c088e2abd4 142308 libdevel optional libpq-dev_15.11-0+deb12u1_arm64.deb ba301d1a1053d3994ae7da065a950907 275176 debug optional libpq5-dbgsym_15.11-0+deb12u1_arm64.deb b1a6a1d6e38e9edc1a86b1e841bdaec0 182328 libs optional libpq5_15.11-0+deb12u1_arm64.deb 8612512cc7f147bb17964b33eb317d22 16881244 debug optional postgresql-15-dbgsym_15.11-0+deb12u1_arm64.deb 6f65bd2aebebcb4e89c7268335f069d5 17045 database optional postgresql-15_15.11-0+deb12u1_arm64-buildd.buildinfo 1d944e0a6abd78c3b93135d0af5f63bb 16384064 database optional postgresql-15_15.11-0+deb12u1_arm64.deb c01b244b33074353fee0990c97dcef3f 2648480 debug optional postgresql-client-15-dbgsym_15.11-0+deb12u1_arm64.deb 3eaa86a0f79566a62f6724e10425ae1a 1671436 database optional postgresql-client-15_15.11-0+deb12u1_arm64.deb 9f1c1d13064d32df970ed958e9dce66f 183404 debug optional postgresql-plperl-15-dbgsym_15.11-0+deb12u1_arm64.deb b7236b3fb2460a1ddffcfa85a6f1dfd8 88236 database optional postgresql-plperl-15_15.11-0+deb12u1_arm64.deb 0d1936f3eeafcc6d26d92ac11edcdd55 175596 debug optional postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_arm64.deb c8fd973d61d0c6de02a3cf2b87691506 108848 database optional postgresql-plpython3-15_15.11-0+deb12u1_arm64.deb cad6a459a4fcd0f5ff1ac4bb4d359f71 79308 debug optional postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_arm64.deb 57ec2679ad84bb57e165b582d95ab604 42064 database optional postgresql-pltcl-15_15.11-0+deb12u1_arm64.deb d67e714bf9d607d1a99fd323064186c0 1143528 libdevel optional postgresql-server-dev-15_15.11-0+deb12u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE9C4sZYDxwNo9XoUDaRWK3AIe28EFAmeyGdYACgkQaRWK3AIe 28EA9xAAoesSLrZjUVguxfIgf3KzHMkqiGCEeflmp8OTc4D3DQbR5470bj1ibpD2 WD/UhBoqh/UyDm3lQeT5mhHSq6NRo7mi7MqUaiSiGsuzN6PmQPNpB500OBoSOmkV CeDWciMYgR2J0MyAZiY+bCTpCipiDUK3D8CGz09AF2rEPJeAGhqLK41aNRedErEp C3JO921xEHIzDfrLa4TBKfG9s4/u1lRShrgAw1SKvYqpcbwRcKaB0BAOLH6biVpN r5B2K6HpmY4n7O6LUrhA++82SsvJ/hpn6ct5wvH6N0sGxunrZKQbjcVkFEG41K2z /J9u8Gp6zvK6YU90O/FGi+Fufbj5C9NQf5/0AG6ttniaNf+qywO0eANChPCqAqOh 9khbm1F35Ft9DT2Z7vf2RBvZwXd/d20N8Q8JuodrsyQIjgAPgrO6kGPNml2DWFE7 18HxFSsybBs6Gk/Fyif9+aHh3x9CJJDMjWxl/jkArz5gYJlIxtGmSRkNFdDnM8HS Pm7CtLOooZ9ElFIXAkAjjfKtdXudNQhSLOnOKAZzUCvp8X3RlTiW+8Wnu+BeKAQU VimztoYzRBFXAe9yigtr1X+qXofpMW0P1c8J04EXhGfowiHMNrRmNB3U7ZaFqynx E2L9EeapyiJDL7od25nI7hjcrJP6vPBnuniDGOHqINFLZa9SQ6U= =A0hB -----END PGP SIGNATURE-----