-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 11 Feb 2025 11:27:41 +0100 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: armhf Version: 15.11-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.11-0+deb12u1) bookworm; urgency=medium . * New upstream version 15.11. . + Harden PQescapeString and allied functions against invalidly-encoded input strings (Andres Freund, Noah Misch) . Data-quoting functions supplied by libpq now fully check the encoding validity of their input. If invalid characters are detected, they report an error if possible. For the ones that lack an error return convention, the output string is adjusted to ensure that the server will report invalid encoding and no intervening processing will be fooled by bytes that might happen to match single quote, backslash, etc. . The purpose of this change is to guard against SQL-injection attacks that are possible if one of these functions is used to quote crafted input. There is no hazard when the resulting string is sent directly to a PostgreSQL server (which would check its encoding anyway), but there is a risk when it is passed through psql or other client-side code. Historically such code has not carefully vetted encoding, and in many cases it's not clear what it should do if it did detect such a problem. . This fix is effective only if the data-quoting function, the server, and any intermediate processing agree on the character encoding that's being used. Applications that insert untrusted input into SQL commands should take special care to ensure that that's true. . Applications and drivers that quote untrusted input without using these libpq functions may be at risk of similar problems. They should first confirm the data is valid in the encoding expected by the server. . The PostgreSQL Project thanks Stephen Fewer for reporting this problem. (CVE-2025-1094) Checksums-Sha1: 5e6d11cfed92ed863880b97298513c63f532e43a 16664 libecpg-compat3-dbgsym_15.11-0+deb12u1_armhf.deb ca17b770a2fd5d866d9ba3c7abc7daf5b150f4a0 17284 libecpg-compat3_15.11-0+deb12u1_armhf.deb e4f6fa317c6755e603f685246a0456ffbbd7455f 236360 libecpg-dev-dbgsym_15.11-0+deb12u1_armhf.deb c42676018c1b7357546eb4edf4985aa0e1711948 278524 libecpg-dev_15.11-0+deb12u1_armhf.deb 2ade8ad5a0a9845a2220c8d8eb233763709f3e3f 112208 libecpg6-dbgsym_15.11-0+deb12u1_armhf.deb 1bf3a56b026144958103ec02bc0f99bf51eba247 54912 libecpg6_15.11-0+deb12u1_armhf.deb 9b72df462b2aa6c13c318747f3f779aab80a34d0 88588 libpgtypes3-dbgsym_15.11-0+deb12u1_armhf.deb 5775ccd9b9f7da07c3dac3ce5159be2ec3c00680 41776 libpgtypes3_15.11-0+deb12u1_armhf.deb 19af035fbbbf34abb2885f9588cb0cf68ec77d46 134348 libpq-dev_15.11-0+deb12u1_armhf.deb b5d1f557407167d4a32fe3a992ead6da1b3ed967 274276 libpq5-dbgsym_15.11-0+deb12u1_armhf.deb 455e807451bdf03e7e33d9c40f745bc67e63be37 171580 libpq5_15.11-0+deb12u1_armhf.deb f8a8aca69fd6f5c188d30bd4082bc56f128c3c3c 16280848 postgresql-15-dbgsym_15.11-0+deb12u1_armhf.deb ea53b9eca4747e0e07f44e885d754a82d6eb6b82 16921 postgresql-15_15.11-0+deb12u1_armhf-buildd.buildinfo 3c1513fe38b6ccc31b81490b8be7deaa50a20770 16077756 postgresql-15_15.11-0+deb12u1_armhf.deb 0488fced20bce274332066eb4aa5a1a6c301710f 2434892 postgresql-client-15-dbgsym_15.11-0+deb12u1_armhf.deb 23afc9c051faf3708738e88b92097aa916b0496d 1627648 postgresql-client-15_15.11-0+deb12u1_armhf.deb 85c85adf8323ac7ba0a6a1dc4209ffa35ae02573 182816 postgresql-plperl-15-dbgsym_15.11-0+deb12u1_armhf.deb aaa1e503b819cfefb81061b8fb35328c41bec14a 88404 postgresql-plperl-15_15.11-0+deb12u1_armhf.deb 8e619ba637a28f46ba878cb74838dd1ce9e99022 172572 postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_armhf.deb d7f7530c27658e563af30429215c28fdd7313488 106372 postgresql-plpython3-15_15.11-0+deb12u1_armhf.deb 83f58507259f85d08aa765b77f50516bbf03f499 78280 postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_armhf.deb 2e2c34173a886a44b270a3597eae12da970c3fd3 40944 postgresql-pltcl-15_15.11-0+deb12u1_armhf.deb 1c1919f6df49baf6b899913160f65039c862a159 1133544 postgresql-server-dev-15_15.11-0+deb12u1_armhf.deb Checksums-Sha256: 43a8f9c4ef7560752b72c978829e21d654efff4e0772998679af3b955a6cda03 16664 libecpg-compat3-dbgsym_15.11-0+deb12u1_armhf.deb 96e1e34f65253974b727f3a05c3b1388cc01f251386d17b7bf074dcce2f146f1 17284 libecpg-compat3_15.11-0+deb12u1_armhf.deb 1ccd89a12483f05980546c8718f50c2b4e3b2c6d278c18d8bc8ec793f950e62c 236360 libecpg-dev-dbgsym_15.11-0+deb12u1_armhf.deb 62dcb8435486c58afd96afa6f465bcb214070f1bdede5c555281aee809848bb5 278524 libecpg-dev_15.11-0+deb12u1_armhf.deb 89cf2eabc163c9fc14e79cbb6181cb42a1414e3712ed63ecefae5c8ee9b23af7 112208 libecpg6-dbgsym_15.11-0+deb12u1_armhf.deb 17bce4e9833ae660911606f78febd811fc6974c0740926e5f02b567b4d0e2929 54912 libecpg6_15.11-0+deb12u1_armhf.deb 26bf64a57326e1ec06f97d218e6a27c455869facf406616e544162fc5efc9d09 88588 libpgtypes3-dbgsym_15.11-0+deb12u1_armhf.deb 2bf91b830ba5bf4523302b2b4be65a4106585cf6b68f23186234c44abbdb7e19 41776 libpgtypes3_15.11-0+deb12u1_armhf.deb 3ad34b4d3fd7a4e49555a2da4fe7af4c4086ab5f19d00110b16361b304118fec 134348 libpq-dev_15.11-0+deb12u1_armhf.deb 2b9cb191ece63d9a3c56148cadfe6e2c9aebdc4c06ac150d762b1503a76f308f 274276 libpq5-dbgsym_15.11-0+deb12u1_armhf.deb 8dd8c64ec030cf5c8635c9a4289b459d488e1b129e0462bd0b155e72d8e1dd22 171580 libpq5_15.11-0+deb12u1_armhf.deb 0be6c6cce36189dae738b46f6a568068f363eb9a8d54e776575145252d9f6481 16280848 postgresql-15-dbgsym_15.11-0+deb12u1_armhf.deb 67fb8e70c35cd157fc905b7266de473113b2017db2eaccc9e5c0924991b48988 16921 postgresql-15_15.11-0+deb12u1_armhf-buildd.buildinfo eefdb9bfb149828923cbed21a1fac055629b8a5612e27099c7f13031fc10c436 16077756 postgresql-15_15.11-0+deb12u1_armhf.deb 5eb870c5fc45afbdfb4bd0ada3abca64a64e98ee5a29c9df35c31afa81bbc495 2434892 postgresql-client-15-dbgsym_15.11-0+deb12u1_armhf.deb 3f94db3f0f3d93ec1e478a5310c0e0f26c1ec4c8219d08c8e89894878339bb69 1627648 postgresql-client-15_15.11-0+deb12u1_armhf.deb c536615d83114319fe9242756f1786c119d71cea32f93f54c3aab88543dfb588 182816 postgresql-plperl-15-dbgsym_15.11-0+deb12u1_armhf.deb 9ac64915887157300735f3af6951f24675c8ed87356f7589107a5f42414c6eee 88404 postgresql-plperl-15_15.11-0+deb12u1_armhf.deb 54a01a75f3419ab792029e7247af7ca384300dd9e083f4886a2868b108347f63 172572 postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_armhf.deb c08e09452a22bed4bce477e0fb0b6012fa91d66c3f25b6536332d82836740f7d 106372 postgresql-plpython3-15_15.11-0+deb12u1_armhf.deb baad440ca17b35c1f528553a4a1f32d42c8ab8f6191c56f1101489935a94460a 78280 postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_armhf.deb fd2ed3d94a74573b99cec1b959701a15cd2371a50952a60a9815ba0c05971026 40944 postgresql-pltcl-15_15.11-0+deb12u1_armhf.deb ba03273e649fecfd8ab7662fa8209790662fbee0167b09fab1df28f16709ccb5 1133544 postgresql-server-dev-15_15.11-0+deb12u1_armhf.deb Files: 32ea3e1c13aab2b5db263ffb618e8d25 16664 debug optional libecpg-compat3-dbgsym_15.11-0+deb12u1_armhf.deb d577580ecee850eb7c7c0dccbb04fddc 17284 libs optional libecpg-compat3_15.11-0+deb12u1_armhf.deb 8d28f5405aab8955b30c3a7bc29b31b9 236360 debug optional libecpg-dev-dbgsym_15.11-0+deb12u1_armhf.deb 8e6fcbafcf45ff6c3cde6681fc28f48b 278524 libdevel optional libecpg-dev_15.11-0+deb12u1_armhf.deb 0550f7f54682fa1bd8311e26c6c0b833 112208 debug optional libecpg6-dbgsym_15.11-0+deb12u1_armhf.deb b5d059e2822c7dfbbf10938e45934819 54912 libs optional libecpg6_15.11-0+deb12u1_armhf.deb d207185fe00e866f2436c6dc3f225fcc 88588 debug optional libpgtypes3-dbgsym_15.11-0+deb12u1_armhf.deb 9c4040ce1a4dad7a984d1b596e174b1f 41776 libs optional libpgtypes3_15.11-0+deb12u1_armhf.deb c93e1bafce9737107ecc1fe5c760eeef 134348 libdevel optional libpq-dev_15.11-0+deb12u1_armhf.deb 56ecd3198a21f2a72dd968993feface7 274276 debug optional libpq5-dbgsym_15.11-0+deb12u1_armhf.deb 7d2cc6c4831ffc05ca3029b7764d4599 171580 libs optional libpq5_15.11-0+deb12u1_armhf.deb 3d3182db6ad7eea89a7dcb6088281fb4 16280848 debug optional postgresql-15-dbgsym_15.11-0+deb12u1_armhf.deb 1fa7a85ab8ee66a8083ff60e1aec17a3 16921 database optional postgresql-15_15.11-0+deb12u1_armhf-buildd.buildinfo ffdddcb219fe127cf90ee5ecd4943c8f 16077756 database optional postgresql-15_15.11-0+deb12u1_armhf.deb 649bc96d727987c0b5f934af326204cb 2434892 debug optional postgresql-client-15-dbgsym_15.11-0+deb12u1_armhf.deb 8ab25b49d11748070386c565719ef657 1627648 database optional postgresql-client-15_15.11-0+deb12u1_armhf.deb 4ab1154d97d0dea58e242fdf23ab2a21 182816 debug optional postgresql-plperl-15-dbgsym_15.11-0+deb12u1_armhf.deb 77ac2c65079dae6b586df617129f4917 88404 database optional postgresql-plperl-15_15.11-0+deb12u1_armhf.deb 3004a2d47c2c184824e3cf8b205fb5c7 172572 debug optional postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_armhf.deb 0f66b1206f6ad4a8c71e7965eebbc188 106372 database optional postgresql-plpython3-15_15.11-0+deb12u1_armhf.deb ef88aab48cfe7b10145da8ab5ff89e07 78280 debug optional postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_armhf.deb 1df69badac3971d98a97ec520f63d691 40944 database optional postgresql-pltcl-15_15.11-0+deb12u1_armhf.deb 63ff91ed9f66bbf9ecafce6342b31faa 1133544 libdevel optional postgresql-server-dev-15_15.11-0+deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEegRwmIwj8f99iF4m4CwlMGxHD8UFAmeyChMACgkQ4CwlMGxH D8US7RAAxxluMfR0M102rfxBxQlxTGnP+fw0ZIUgkmB3wZrY/DPEWHI3pWU+pyqW 5rvbSykaF5vsz3aBiN3E/6a/mge0vuGtlNKZRGmKySM+M8yddBcEyUYfudDKQM8o DfzeVi97UoqC1wlGP1ewys/8TQs3HE6OBRFq6nG4n2TDYyUtsncYyjtXgNp4qC3P xSMiqgCtnAE37w+m03i3U5RIvmIai06XQ/+JoizjacU0BjejGmeCSYpuyj3rqCZC 9nWEhHNMLwD0d4Lvn4i7YXgkTxkor3q6+xbZs4frfjdyHNxU3lWP6/9ixxYJ648K LWXJCTnWxZRdI+UHoEM8CxrMqGebwQf0JnT+l9NoIJZt4S5bBhqWply9DzUnNWeJ 0eESCT6K0jozhyz0eV9USky2t8wNOyToNotlFJdE7UmeVTaT2gPnwPwRxW2Hpl9T ta3OEYnUMo9cC5V2egxoX0hMfaYNg5W/C6aUnlNTUsUPDwzNsiqogfdQakJD/qjN 5lZeEkmF4C6nAv5xgpE9A4hjkfqm8ZB56g0dbE2M5f6bZQ1iCelNwDV3ZpALF8oa Ji+H4mCT40vm1UI8k9lq4JtWr8mWSdHSy5Ak4JDGGg81Tv8POW0AI5FHyrNcZaBf f3dOFYUNpLI7Ztf+ktRDJOLH8x/JAbFSKX12Qm4bdqDSYqZIGDE= =C+sZ -----END PGP SIGNATURE-----