-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 11 Feb 2025 11:27:41 +0100 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: ppc64el Version: 15.11-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-conova-02) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.11-0+deb12u1) bookworm; urgency=medium . * New upstream version 15.11. . + Harden PQescapeString and allied functions against invalidly-encoded input strings (Andres Freund, Noah Misch) . Data-quoting functions supplied by libpq now fully check the encoding validity of their input. If invalid characters are detected, they report an error if possible. For the ones that lack an error return convention, the output string is adjusted to ensure that the server will report invalid encoding and no intervening processing will be fooled by bytes that might happen to match single quote, backslash, etc. . The purpose of this change is to guard against SQL-injection attacks that are possible if one of these functions is used to quote crafted input. There is no hazard when the resulting string is sent directly to a PostgreSQL server (which would check its encoding anyway), but there is a risk when it is passed through psql or other client-side code. Historically such code has not carefully vetted encoding, and in many cases it's not clear what it should do if it did detect such a problem. . This fix is effective only if the data-quoting function, the server, and any intermediate processing agree on the character encoding that's being used. Applications that insert untrusted input into SQL commands should take special care to ensure that that's true. . Applications and drivers that quote untrusted input without using these libpq functions may be at risk of similar problems. They should first confirm the data is valid in the encoding expected by the server. . The PostgreSQL Project thanks Stephen Fewer for reporting this problem. (CVE-2025-1094) Checksums-Sha1: 59a03ba782e40195e732dd83b96ec79b8c571595 17576 libecpg-compat3-dbgsym_15.11-0+deb12u1_ppc64el.deb ebffe4201adae73eb564d03e1d319f7269002ea8 19532 libecpg-compat3_15.11-0+deb12u1_ppc64el.deb 74e7e22c6cbd73db0c18e73ee08e5411168b8c6a 224244 libecpg-dev-dbgsym_15.11-0+deb12u1_ppc64el.deb 4befaf33bd39810ffe5e44c47b56635e87c365fe 301152 libecpg-dev_15.11-0+deb12u1_ppc64el.deb 610e34f8db8746931e8b5bd1e4648fd3f2c9c3c2 113940 libecpg6-dbgsym_15.11-0+deb12u1_ppc64el.deb fff86ff346e2fd5cc783ca08fd4fe4969da99a4e 66544 libecpg6_15.11-0+deb12u1_ppc64el.deb 6ef18cff0d99ef44ea7c8567f76f17e81fe12275 90904 libpgtypes3-dbgsym_15.11-0+deb12u1_ppc64el.deb c8c8af6161deb13d5d63a0c8604e24404951e7cc 50124 libpgtypes3_15.11-0+deb12u1_ppc64el.deb 3a729e86ce1987b4a11132cb4ac66f03f65f2c55 158252 libpq-dev_15.11-0+deb12u1_ppc64el.deb 74cc0f9b756f7377a2696e2bd78bc876966387cf 285984 libpq5-dbgsym_15.11-0+deb12u1_ppc64el.deb 66b26c1ad5414ae113d5754eee896eac8c55fc97 201556 libpq5_15.11-0+deb12u1_ppc64el.deb e0e4bac2c4f664adf0915b812f61de02a132f065 16773868 postgresql-15-dbgsym_15.11-0+deb12u1_ppc64el.deb 239177b05038df022e5bfd8e33e84baf9e47c4dc 17162 postgresql-15_15.11-0+deb12u1_ppc64el-buildd.buildinfo f71a9438e61e484ab75f60b85e428367533ab0fe 17166740 postgresql-15_15.11-0+deb12u1_ppc64el.deb 443f30a8bb35aee59a06cd108ba0a68f08cc8df4 2505468 postgresql-client-15-dbgsym_15.11-0+deb12u1_ppc64el.deb 38814155e8846498ba57f2a35e6d4c8574ded8cd 1749492 postgresql-client-15_15.11-0+deb12u1_ppc64el.deb 0facdbb1a95bd3af6ea8fc591d02ce7b90ccc093 186448 postgresql-plperl-15-dbgsym_15.11-0+deb12u1_ppc64el.deb acd0c77667e867fc7821998b6ce006fa1fee6eac 92440 postgresql-plperl-15_15.11-0+deb12u1_ppc64el.deb 356c2354650a5230ef9a15c35a3711a083866830 176780 postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_ppc64el.deb 4f4f56a8ce9b427f89c34963b93598133bfab7ea 112760 postgresql-plpython3-15_15.11-0+deb12u1_ppc64el.deb f2eb2595938392d9864a09d622d1b6fe52c2d0c0 80068 postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_ppc64el.deb ab8997ec4a8e573794c8cd238bebffe1f785a585 43740 postgresql-pltcl-15_15.11-0+deb12u1_ppc64el.deb cc6af9a94083b7853d3ddd5b0388536b8dac0b35 1162812 postgresql-server-dev-15_15.11-0+deb12u1_ppc64el.deb Checksums-Sha256: 66f555556a606f5a35dec96f92c766b80e2fa9f2a9bc06e55f23474c34a63be0 17576 libecpg-compat3-dbgsym_15.11-0+deb12u1_ppc64el.deb b8e87c3555fc541b09ac9235e65422942e0627a53d491e8cfdc13e78052affd6 19532 libecpg-compat3_15.11-0+deb12u1_ppc64el.deb dfcc02d3b004169e8a5c4ee1efd2d3b8afe2b9cf8f71febbfe5afbe6dfec2e95 224244 libecpg-dev-dbgsym_15.11-0+deb12u1_ppc64el.deb 0375733fa1bcf4c24fffc38c3f56e750074538117dda588c9a90330fc835e909 301152 libecpg-dev_15.11-0+deb12u1_ppc64el.deb ef46c94948fe9e4336f8962993d13405e2019125af5829737dd0bad8d8f02b2b 113940 libecpg6-dbgsym_15.11-0+deb12u1_ppc64el.deb d8a5737707ea2cd1463248371e738cf6d933e250efb2c365fcd984e79e19b1b7 66544 libecpg6_15.11-0+deb12u1_ppc64el.deb 4ef1f3a314e9a208f21c8a3eefd99b2daf4401e667fd87454cc81dc4927b63a8 90904 libpgtypes3-dbgsym_15.11-0+deb12u1_ppc64el.deb 0f7286b1593b4a0874b472cffe55367b376d79e4d39119176bf799f58a18efb9 50124 libpgtypes3_15.11-0+deb12u1_ppc64el.deb d1242471ab9799a5eafc56fb62efaaa07bfecda1eefb6a33f8d6098d0e785a56 158252 libpq-dev_15.11-0+deb12u1_ppc64el.deb fc6a394adff457a1f47ebe29fca507c43a02cabf4f18c78183b94b09de4f867e 285984 libpq5-dbgsym_15.11-0+deb12u1_ppc64el.deb d7a61e9c8313f5b2687a57b0761915ac3d67ae116c1039aa5a85b981995cf317 201556 libpq5_15.11-0+deb12u1_ppc64el.deb d6ae88290f0021ed7c4c322408d2eec8f9bc1d12e1fb6c6c01b43134181c6632 16773868 postgresql-15-dbgsym_15.11-0+deb12u1_ppc64el.deb 7e1c2cdbf02e360a41fb5418bea9c4e2b5cc268ef4368a04c925dd6d77f16afe 17162 postgresql-15_15.11-0+deb12u1_ppc64el-buildd.buildinfo fa5f8b138f8630ddd62f7015bca8da2450d8bb2987c820bc2f558a97d7cace0a 17166740 postgresql-15_15.11-0+deb12u1_ppc64el.deb 21b662a20de6b4efa58b28a18ee9d264a1a43053320450e8959d0619f6c2ed13 2505468 postgresql-client-15-dbgsym_15.11-0+deb12u1_ppc64el.deb a3e54200303ec4c43372b9c74c391e028738af7ecedbabde4bd1209f17271e5d 1749492 postgresql-client-15_15.11-0+deb12u1_ppc64el.deb 990495ff59f8ad2df6d777a7bc5d24e3940e1477d1eb9077b0f88ac1c69208f3 186448 postgresql-plperl-15-dbgsym_15.11-0+deb12u1_ppc64el.deb c2c733689be4e34f9fcf1d56e37e082b36a363288692a37afab61a74d56b2124 92440 postgresql-plperl-15_15.11-0+deb12u1_ppc64el.deb 36354926281c3a7ce72390cebda9167ca82286ce54df5b9668e8fc5c61c5cc03 176780 postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_ppc64el.deb 0d72adae62ad6013db0be61c51ecbadc3073fe03b17f10897ba95a673d477b26 112760 postgresql-plpython3-15_15.11-0+deb12u1_ppc64el.deb ab7746f64a278b9cbeef44ae098d6457a2a21c5cefa230aca089dfae6964bcce 80068 postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_ppc64el.deb e3d708d6a07e3bdf1c3aa42eb990f60bc77121dbda71fc9e9018ae55c517a256 43740 postgresql-pltcl-15_15.11-0+deb12u1_ppc64el.deb 2b628ac7ac9365ee14fd308ef3b1217d0a0ceed3dca5c4d8516ad23b110883b9 1162812 postgresql-server-dev-15_15.11-0+deb12u1_ppc64el.deb Files: 7d9d5c8da1f893646e2e9ec6c2072355 17576 debug optional libecpg-compat3-dbgsym_15.11-0+deb12u1_ppc64el.deb e825f1418422466020a85f011e839315 19532 libs optional libecpg-compat3_15.11-0+deb12u1_ppc64el.deb cce380184893d0a7a7421919cbbcdee5 224244 debug optional libecpg-dev-dbgsym_15.11-0+deb12u1_ppc64el.deb 44acf2feecbed444526343720374e4af 301152 libdevel optional libecpg-dev_15.11-0+deb12u1_ppc64el.deb 3c783d98895f49d0371d2915b1b6ab4d 113940 debug optional libecpg6-dbgsym_15.11-0+deb12u1_ppc64el.deb 221d609fd573d74133a7f128f308bbc7 66544 libs optional libecpg6_15.11-0+deb12u1_ppc64el.deb eb1fa5bdf1bed2fecd2da465f58282a0 90904 debug optional libpgtypes3-dbgsym_15.11-0+deb12u1_ppc64el.deb 76d6ff6b70b1b7568624220c4749e457 50124 libs optional libpgtypes3_15.11-0+deb12u1_ppc64el.deb b004376366892654b80fc8eba3d952db 158252 libdevel optional libpq-dev_15.11-0+deb12u1_ppc64el.deb c88c530922415958fef4eb35c9e23256 285984 debug optional libpq5-dbgsym_15.11-0+deb12u1_ppc64el.deb 2828bd1a897e25a5faa384a64dc515cd 201556 libs optional libpq5_15.11-0+deb12u1_ppc64el.deb 84a968f555866153ccdc3f5bc731acb5 16773868 debug optional postgresql-15-dbgsym_15.11-0+deb12u1_ppc64el.deb c61f592a8190a9e06cb67d31d85d9e83 17162 database optional postgresql-15_15.11-0+deb12u1_ppc64el-buildd.buildinfo 525dc1c1b94b3e6633f61cff430e3ebc 17166740 database optional postgresql-15_15.11-0+deb12u1_ppc64el.deb 8d8dc9b29f72b27500f1b7f8749fe4db 2505468 debug optional postgresql-client-15-dbgsym_15.11-0+deb12u1_ppc64el.deb ca1aa7d80432eced639970ace413a032 1749492 database optional postgresql-client-15_15.11-0+deb12u1_ppc64el.deb b4c6c1ab6202750d68830c080cbfc56d 186448 debug optional postgresql-plperl-15-dbgsym_15.11-0+deb12u1_ppc64el.deb 131196b42f5f9e48da72bef83bfb1a45 92440 database optional postgresql-plperl-15_15.11-0+deb12u1_ppc64el.deb 776f5b0d7cd0d34189e8119afffc2323 176780 debug optional postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_ppc64el.deb 743d6632a7a79a33dacd8fb6ee583377 112760 database optional postgresql-plpython3-15_15.11-0+deb12u1_ppc64el.deb e30121fb6664a15eca567b5316285aea 80068 debug optional postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_ppc64el.deb be304a606b98aca79d012f33d401fc5b 43740 database optional postgresql-pltcl-15_15.11-0+deb12u1_ppc64el.deb 7890f1b4c2f59af6c1e9f5c20f00506c 1162812 libdevel optional postgresql-server-dev-15_15.11-0+deb12u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEZAv/jpGRqS40qyb11oy1TpxF0ZAFAmeyB/IACgkQ1oy1TpxF 0ZBcnRAAoEsfBjMZEKy1CGS6FFegozrJR+1D7u9X5Vg4UP6ompDKZLoShXti01lQ bzS/+MOEkdC1Hh7ucz37UrPhoRP15st8ICqcOQ75xGHvUSIKuJkGtx73j8rxEcbZ TDBD5NDvwR7qDbQO5IrYMm2koJkve0R4xmfpsnTQGMUr32EUQB2UBkVUKHyTrH39 iIHX3b1SCUlHpNSSqYMI5YVpCn6GwB+zVrquGqBUzaicJ2aCnuEFu9IyIPD3fshP VHReYeVl1a+iAsIy1ol8eTh0pkcNknCRiurKBeX6RM52ojbjJzsGJxH98L1GNA+p Lm3kHqbZRNPjNZuDDDkXq8qi8a7STI5/pQKOfhrc949ghcJgzs9m1wDKmJ8Km67G MjdS+tPZFDcCflX2TB57ieYEaeqCyGuBLoQvhLy6AnS/+8hHdGWRQdzFynRcV/zE qNj/gIDOebZ+9esqdWx2CAUmRYn7ODUQabsNee6mLAKHvh/aqnc697W0DqmNBN+o /YiK5C0J6ex3sDpQWVuVdzSGQRwmWrxZjzEX+1XcjAiMus+Al/c+fMSs3PAaWR+E iDNZTk/ZKpqQI1LjmsSeH95Tef9c2OT360Qp0FPDQCqRtx9HDeOlNnEyRs5Scpt2 SF2Enn2lzrH3LRm8rmqMmMrUULjO09QBogtaTryr0RIlyrjkpSc= =oMB8 -----END PGP SIGNATURE-----