-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 11 Feb 2025 11:27:41 +0100 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: mips64el Version: 15.11-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-03) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.11-0+deb12u1) bookworm; urgency=medium . * New upstream version 15.11. . + Harden PQescapeString and allied functions against invalidly-encoded input strings (Andres Freund, Noah Misch) . Data-quoting functions supplied by libpq now fully check the encoding validity of their input. If invalid characters are detected, they report an error if possible. For the ones that lack an error return convention, the output string is adjusted to ensure that the server will report invalid encoding and no intervening processing will be fooled by bytes that might happen to match single quote, backslash, etc. . The purpose of this change is to guard against SQL-injection attacks that are possible if one of these functions is used to quote crafted input. There is no hazard when the resulting string is sent directly to a PostgreSQL server (which would check its encoding anyway), but there is a risk when it is passed through psql or other client-side code. Historically such code has not carefully vetted encoding, and in many cases it's not clear what it should do if it did detect such a problem. . This fix is effective only if the data-quoting function, the server, and any intermediate processing agree on the character encoding that's being used. Applications that insert untrusted input into SQL commands should take special care to ensure that that's true. . Applications and drivers that quote untrusted input without using these libpq functions may be at risk of similar problems. They should first confirm the data is valid in the encoding expected by the server. . The PostgreSQL Project thanks Stephen Fewer for reporting this problem. (CVE-2025-1094) Checksums-Sha1: 6ed68711cd2e7d61e9441ff9f70898f5b44c04cb 18092 libecpg-compat3-dbgsym_15.11-0+deb12u1_mips64el.deb 2d5ed0dce95dfcc560dca7f090a6c2f97be6ac68 18236 libecpg-compat3_15.11-0+deb12u1_mips64el.deb 15e4d70f994ef7020d6fbc0208b183563509aa7d 250592 libecpg-dev-dbgsym_15.11-0+deb12u1_mips64el.deb 038519fd7e68fb89d2bd3c3ed824c219ccdc5233 287508 libecpg-dev_15.11-0+deb12u1_mips64el.deb 0a2a356cc02ba297f420f8355dc2a0da2db4b5bb 117256 libecpg6-dbgsym_15.11-0+deb12u1_mips64el.deb 06d61ace62b18a96edb6241537310a6f8215e820 59568 libecpg6_15.11-0+deb12u1_mips64el.deb cb08a2575e60538dbd10d98a6397edf999d4d462 92600 libpgtypes3-dbgsym_15.11-0+deb12u1_mips64el.deb 22ea0ef9eb5e113fb3abe53108acd66f47ccf2ac 44688 libpgtypes3_15.11-0+deb12u1_mips64el.deb b8a0802bcc8517459b05375b753c6a08548f9c3a 151628 libpq-dev_15.11-0+deb12u1_mips64el.deb 3087c9be1fd48039503c2dcff619b8e20f5ba416 286732 libpq5-dbgsym_15.11-0+deb12u1_mips64el.deb 689421f4dfa5913790d5b0810dcd4bad69831634 178856 libpq5_15.11-0+deb12u1_mips64el.deb 71d064b68bfb0a5d2323987ac1eea2197ac7f010 17113888 postgresql-15-dbgsym_15.11-0+deb12u1_mips64el.deb 4ea51afeb24d27d7554ed92f34953f664d363ebd 17078 postgresql-15_15.11-0+deb12u1_mips64el-buildd.buildinfo 7a748b715827588c72f54e0e1926734424805dd5 16377908 postgresql-15_15.11-0+deb12u1_mips64el.deb cb0313732a95ef3b4ff8ff8e9f1358555a029f35 2596536 postgresql-client-15-dbgsym_15.11-0+deb12u1_mips64el.deb ad4348da73445384c6d65a7c6ec18333f2b5660b 1659360 postgresql-client-15_15.11-0+deb12u1_mips64el.deb 3a58ee7861ad7ecfcedf74c2832a9c8cb7f7ccdb 190204 postgresql-plperl-15-dbgsym_15.11-0+deb12u1_mips64el.deb 81c406127dc4c972811fe323c608be11e05ec531 86832 postgresql-plperl-15_15.11-0+deb12u1_mips64el.deb 211f3d778cee98c5e82c56be9c012d0c787280ff 182132 postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_mips64el.deb 9f539e28c892883348dbe66788e0a75b67ff1d41 105444 postgresql-plpython3-15_15.11-0+deb12u1_mips64el.deb 242412041d3c91564d8c92bf991477a82ccc22f9 81384 postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_mips64el.deb 49e80cc79673aa15eb43f3252289f4878a264b65 41084 postgresql-pltcl-15_15.11-0+deb12u1_mips64el.deb dd5a43e793e8362c89f159acc5821e03aa6853cb 1155968 postgresql-server-dev-15_15.11-0+deb12u1_mips64el.deb Checksums-Sha256: 59805325293074c6303ca64befe39fe40fc88032b20459ee72798112a216a90f 18092 libecpg-compat3-dbgsym_15.11-0+deb12u1_mips64el.deb c8e418e9524267d7d449b417c226395f707521dc8746df1cffcc43661d9616c5 18236 libecpg-compat3_15.11-0+deb12u1_mips64el.deb 75dbbd796b2dcacf03314a81c5685b735ebd09e7fb44a6d58f92a1a6723d68ff 250592 libecpg-dev-dbgsym_15.11-0+deb12u1_mips64el.deb ef750c9d9e695bf51e280cbadc53d8f16fd69022a4c2795f6a4570825a27857e 287508 libecpg-dev_15.11-0+deb12u1_mips64el.deb 9a49a3201b65ff78c76f6ab36b6dfc06989cb150846391655d735788322d9eea 117256 libecpg6-dbgsym_15.11-0+deb12u1_mips64el.deb 91f4edc734355b56b8ec2b7673da2c75f3ab3ea8804c2cebe0adc4d0d618224e 59568 libecpg6_15.11-0+deb12u1_mips64el.deb 384feb8226e8ccf843ec383ec84fd063dcb5fcec0f0fdec6d2eaec7635da40c6 92600 libpgtypes3-dbgsym_15.11-0+deb12u1_mips64el.deb 937535072bf19a31b5dfb6c5f28e231fa9d38b6bdebad446be4c3261c740540a 44688 libpgtypes3_15.11-0+deb12u1_mips64el.deb 414fb64824939898b8037e7274a3756ca27acaa8a13f8c31813309ee5b463053 151628 libpq-dev_15.11-0+deb12u1_mips64el.deb 0bfd840fdeb7c50cfd58b8753b3d5156bfba846d8f93fd0c5b9539f034e0d8d5 286732 libpq5-dbgsym_15.11-0+deb12u1_mips64el.deb d1005a1f56d2baafc059912030ac85c81d8c37964d36d090ff63c85fb17dcffc 178856 libpq5_15.11-0+deb12u1_mips64el.deb 33e6e347e3b183c99080a9f9ae138d13df60038ceb0f8df5c1fef3c85f4470e1 17113888 postgresql-15-dbgsym_15.11-0+deb12u1_mips64el.deb f21d82f1f0504f28ca156965844ae75e89fe64e17cc0071f4ccb88f3c7d77b81 17078 postgresql-15_15.11-0+deb12u1_mips64el-buildd.buildinfo 76c22edb3cd8eac56d3e9616cbe310e8b63a80babc34792ff9e3bd2bd7a3adf8 16377908 postgresql-15_15.11-0+deb12u1_mips64el.deb 32633e17b08c43ba51d4e89f7b100a7ffcf47498608f3b2c5271d53e97e363ec 2596536 postgresql-client-15-dbgsym_15.11-0+deb12u1_mips64el.deb 2e975a8c32cd95ace817a87e6c1fc0fe643faa801cd25cb908b624483b57c1b4 1659360 postgresql-client-15_15.11-0+deb12u1_mips64el.deb 665772b032a5abf4cebae557518b41656cbfff51222b29a81a4231152dfc84ff 190204 postgresql-plperl-15-dbgsym_15.11-0+deb12u1_mips64el.deb a91aaa306b292c96d647f5f49a47afe9b93162b30a6201e2b8a122b9dd88aa79 86832 postgresql-plperl-15_15.11-0+deb12u1_mips64el.deb f4428c6d6e6f9767b6c7eb01165f54a8a6da484070acd00fddb3b8e5a6ad38a4 182132 postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_mips64el.deb 3b2729eea2e46e7565803636d00131abc8fb350a9d401e673f64ab7568642d0c 105444 postgresql-plpython3-15_15.11-0+deb12u1_mips64el.deb a746c9213701912408834b610c9e72fea5b8dcea40353135c34eaa78d2fb532a 81384 postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_mips64el.deb 96032ecca0e774cbab9e53af8e325a788dc14c47054529aa4fb8e2022d631af9 41084 postgresql-pltcl-15_15.11-0+deb12u1_mips64el.deb a550b122453dd02714daae94186c5c79323011d8053609a8d9c97bd3140dce9c 1155968 postgresql-server-dev-15_15.11-0+deb12u1_mips64el.deb Files: d1f6de1f9b4b0da02749e77086d28b24 18092 debug optional libecpg-compat3-dbgsym_15.11-0+deb12u1_mips64el.deb b74c06b3d37b99e199cf0139aa130141 18236 libs optional libecpg-compat3_15.11-0+deb12u1_mips64el.deb 60350b200c86e76e87eb696f50ce9c55 250592 debug optional libecpg-dev-dbgsym_15.11-0+deb12u1_mips64el.deb 46ff69368c88ae7dc6c33329c44101a5 287508 libdevel optional libecpg-dev_15.11-0+deb12u1_mips64el.deb e807f1c92cd93561f5d014ff63a9baaf 117256 debug optional libecpg6-dbgsym_15.11-0+deb12u1_mips64el.deb f6fb2f85ed3d0e76ac41a9035a68ea4e 59568 libs optional libecpg6_15.11-0+deb12u1_mips64el.deb d7c1ef8ead9156d1fed06aaa34020c80 92600 debug optional libpgtypes3-dbgsym_15.11-0+deb12u1_mips64el.deb 23317607c1f58695f70abaffadf165f4 44688 libs optional libpgtypes3_15.11-0+deb12u1_mips64el.deb fef425922bdebc64099d909b175656e6 151628 libdevel optional libpq-dev_15.11-0+deb12u1_mips64el.deb a342fa79dcf791ecc7b5226d8d761093 286732 debug optional libpq5-dbgsym_15.11-0+deb12u1_mips64el.deb a95bd6d0150710614919c16a797ead38 178856 libs optional libpq5_15.11-0+deb12u1_mips64el.deb e79b289cb66da8aa8cbb3e4e2e0f3f1d 17113888 debug optional postgresql-15-dbgsym_15.11-0+deb12u1_mips64el.deb 1826c4e30fb69e626fbb87a99be90e7d 17078 database optional postgresql-15_15.11-0+deb12u1_mips64el-buildd.buildinfo 5ecc69743333b8bd62b9d8ddc68ec5bf 16377908 database optional postgresql-15_15.11-0+deb12u1_mips64el.deb cf040414818d04bbe79f369308b6a8dd 2596536 debug optional postgresql-client-15-dbgsym_15.11-0+deb12u1_mips64el.deb f9be6052ccc0033fa6af5adf32605230 1659360 database optional postgresql-client-15_15.11-0+deb12u1_mips64el.deb 775e9292bbc710bbb2068572560889d5 190204 debug optional postgresql-plperl-15-dbgsym_15.11-0+deb12u1_mips64el.deb 84ae6d7fc97950ebaa24a8abdb647f8c 86832 database optional postgresql-plperl-15_15.11-0+deb12u1_mips64el.deb 51ab2ec3944cd547a92210fa93f6aad5 182132 debug optional postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_mips64el.deb 2db177004f7042926eb93b9bcf9e11b4 105444 database optional postgresql-plpython3-15_15.11-0+deb12u1_mips64el.deb e21977e997258f74f8806e8ef83d815c 81384 debug optional postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_mips64el.deb ba41ec75ae28c4110961fb01612b8c65 41084 database optional postgresql-pltcl-15_15.11-0+deb12u1_mips64el.deb dc3efe04bb246fbfc9ca9d88963c86f3 1155968 libdevel optional postgresql-server-dev-15_15.11-0+deb12u1_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEunmvxaaGKuI+hxxClmZGXOM83t8FAmeyIvgACgkQlmZGXOM8 3t+lwxAAoz+ac5Uy1/n80GL7W20MvLee5naohtEvrJmummh5Zii7nT8NTZFFkSVO Pm30IjDtGPEN6d+hD49tA26mIDDYk5lu4JTxYUG1RL6cbCo8vae8p+4D3uMYatpw NckZshh//vPo84b1y9J/EgH6lvJdp8OywBDn42dostfDgPfWkgiWoN0U5AIl0cOb BFIf/YqEH7oPF1LjEWw05zqfubBJUfUrlhfCs+a7M6ITtmzFS+Hel6DTwAQrJHdG fybBt/dbDywG3+Qky0PDsMmGw7DeZJCZ+oLSnmnov5IcDPYTRiYQVIMbQCvKwLXY NcYcKPcR1r6yUJpNObIGOI65wN6UGoF2x0xrOaXCQP0hFSiM2zqDUtUxL9fXQJX4 5v1HkweGguHOSMF+SG47OiDV18eGa/nfgpxuWlm1zwlhJQhVK5hJYndETgM2jowy UpRpIrgPupJ9OdHeErWdLLtu6bC5BOT1czJgXDtkcJOzCcmGcJZEuVmBLmlcNPeg iM6TXBt6Tgwj3LTUDKnt3lG9T9XBam0jNfDjR/6RlIp1q16T1hS97cjHl5JS/QMF 91YzKdZ+lHxcI5RcKVyRET4apmm6hgL8JfbrhVQCrs7W81XynJkSLwXq/ZhZ8CQu CpItjUSaBSt6pjn/MNFDRP8Oz0lWv6hsaKj0xw2UgOa8bOFbI14= =FcKY -----END PGP SIGNATURE-----