-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 11 Feb 2025 11:27:41 +0100 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: mipsel Version: 15.11-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.11-0+deb12u1) bookworm; urgency=medium . * New upstream version 15.11. . + Harden PQescapeString and allied functions against invalidly-encoded input strings (Andres Freund, Noah Misch) . Data-quoting functions supplied by libpq now fully check the encoding validity of their input. If invalid characters are detected, they report an error if possible. For the ones that lack an error return convention, the output string is adjusted to ensure that the server will report invalid encoding and no intervening processing will be fooled by bytes that might happen to match single quote, backslash, etc. . The purpose of this change is to guard against SQL-injection attacks that are possible if one of these functions is used to quote crafted input. There is no hazard when the resulting string is sent directly to a PostgreSQL server (which would check its encoding anyway), but there is a risk when it is passed through psql or other client-side code. Historically such code has not carefully vetted encoding, and in many cases it's not clear what it should do if it did detect such a problem. . This fix is effective only if the data-quoting function, the server, and any intermediate processing agree on the character encoding that's being used. Applications that insert untrusted input into SQL commands should take special care to ensure that that's true. . Applications and drivers that quote untrusted input without using these libpq functions may be at risk of similar problems. They should first confirm the data is valid in the encoding expected by the server. . The PostgreSQL Project thanks Stephen Fewer for reporting this problem. (CVE-2025-1094) Checksums-Sha1: e6c70e0d94d7d42276a6c5a25062057ffa095074 17872 libecpg-compat3-dbgsym_15.11-0+deb12u1_mipsel.deb c67eb1698047f81c79dfd369413092ded64ec14d 17984 libecpg-compat3_15.11-0+deb12u1_mipsel.deb 1140797d7e724001cc9a3c7596e36c5d3c7a9af6 261424 libecpg-dev-dbgsym_15.11-0+deb12u1_mipsel.deb fd2e4414848685264aa717d9773060c1911d2c90 283932 libecpg-dev_15.11-0+deb12u1_mipsel.deb 4b8564989f7e8fee863264ab147908c378d68ee7 115700 libecpg6-dbgsym_15.11-0+deb12u1_mipsel.deb 9ae155065afe0a5b82f22a7b2932cdee93426d47 59956 libecpg6_15.11-0+deb12u1_mipsel.deb 87173d8616010c076f00dc09e1f0c90e90d7c4f2 91636 libpgtypes3-dbgsym_15.11-0+deb12u1_mipsel.deb 1796843673e50e54f83cf81e869e9a482f7e900a 45240 libpgtypes3_15.11-0+deb12u1_mipsel.deb 7d9de88d43f36888383be848b5c6cdbd1f9a9bf7 151228 libpq-dev_15.11-0+deb12u1_mipsel.deb d20825af081271d7b705f5794fcc5537e0ac61be 283580 libpq5-dbgsym_15.11-0+deb12u1_mipsel.deb 512c0ea34d36e81f737a6d8421ab5ba9ecff3c96 178312 libpq5_15.11-0+deb12u1_mipsel.deb a41da13a1aebb6e82a579952f81d30f7d760e896 16705416 postgresql-15-dbgsym_15.11-0+deb12u1_mipsel.deb db5d1961e6c49738f3d45d59beea943ccac314ed 16935 postgresql-15_15.11-0+deb12u1_mipsel-buildd.buildinfo 86ffdba81bffa5798a76d7372d349cb9916eb8a7 16300844 postgresql-15_15.11-0+deb12u1_mipsel.deb c2d396b35b75e64ad59b81668a2f85a3c3a48c4d 2531152 postgresql-client-15-dbgsym_15.11-0+deb12u1_mipsel.deb 01121257813de010498c3fc46988027ce5a95325 1662648 postgresql-client-15_15.11-0+deb12u1_mipsel.deb 964209ffeaaf93326558c5e8387a5b8e0291a94a 184624 postgresql-plperl-15-dbgsym_15.11-0+deb12u1_mipsel.deb b1fbb619a131a4ca6bc63f8a635eb47d3db3823f 86756 postgresql-plperl-15_15.11-0+deb12u1_mipsel.deb eced0d9d31dc93c9debeabb6f6c2cb22732961c9 175924 postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_mipsel.deb 1316c0c57b90c53d2819745edcafd51701b2b44f 105116 postgresql-plpython3-15_15.11-0+deb12u1_mipsel.deb 568620812a1de4d5799013334ba696fa90e6aac2 80144 postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_mipsel.deb 99c374ecd809414aea04999074b2499201ab4219 41068 postgresql-pltcl-15_15.11-0+deb12u1_mipsel.deb d238275cbf20421b2d918f3428faea0934323004 1155652 postgresql-server-dev-15_15.11-0+deb12u1_mipsel.deb Checksums-Sha256: a956edc81240b1b88d98c7de3f909cf482aa214558ed202b0a22cb71350453dd 17872 libecpg-compat3-dbgsym_15.11-0+deb12u1_mipsel.deb ef1018446df9f326dd352a3dfdad6827e040b6cfe94a51187eb3bc45f95494a5 17984 libecpg-compat3_15.11-0+deb12u1_mipsel.deb 27aaa42297e7b8fb6108e1c05420bf8853ab3c81755b9850df23a01a908cc52f 261424 libecpg-dev-dbgsym_15.11-0+deb12u1_mipsel.deb b062529777176b39135b27c14ce60b77f92b9fd7a3059536a822902857bc3638 283932 libecpg-dev_15.11-0+deb12u1_mipsel.deb 8c8b8ea39f7b5f1a627d3478b8209dbfa0ba601a0a0d3e06c855b9dc21094425 115700 libecpg6-dbgsym_15.11-0+deb12u1_mipsel.deb 826702b760509e9f1266c01a05749d23c433123030209145111c7a4a870498a6 59956 libecpg6_15.11-0+deb12u1_mipsel.deb 9c332d497603cde2286d26766b109000bfc06abe2dea2726e714633fca60322f 91636 libpgtypes3-dbgsym_15.11-0+deb12u1_mipsel.deb 94ae72987aaf6e3ca86504e628f3773232fdda7ef97e54c3e94406a6c80c712a 45240 libpgtypes3_15.11-0+deb12u1_mipsel.deb d066a70d2ca43568453c69c3437d1b2f5cebdc9c765bd913cb7eec51dac3f69d 151228 libpq-dev_15.11-0+deb12u1_mipsel.deb 859281142be0f0c76a7363fb729e8a6337d7541868f6e6970d4e06c94d7272f5 283580 libpq5-dbgsym_15.11-0+deb12u1_mipsel.deb 0b7b59ad1869f13ded259f185949397eb9fc419442c7a5554b4e51e4a439bd45 178312 libpq5_15.11-0+deb12u1_mipsel.deb af5415cfad5975007fe2d354f86fdd33d11966f20eda3e3ddfca21c321380e36 16705416 postgresql-15-dbgsym_15.11-0+deb12u1_mipsel.deb ed1fbeaff8536449036c1839edf2c60a3c4f5e0612a22c653920bf746f030eab 16935 postgresql-15_15.11-0+deb12u1_mipsel-buildd.buildinfo acebd8064e62a33df07737f7f0178cae6faced42df357e3366582d07c35b1b93 16300844 postgresql-15_15.11-0+deb12u1_mipsel.deb 1c0e8c89b52e70b4d282c787368b42cb34a9f54fe1b0257bd7e5ae3ddbbfb206 2531152 postgresql-client-15-dbgsym_15.11-0+deb12u1_mipsel.deb 36519aed9a0b7285b1aead96da0e395ec2fe6030e38c1f3971c0e61e6687280f 1662648 postgresql-client-15_15.11-0+deb12u1_mipsel.deb 0673b7c958a77597a4e3b6b03e7db39f1ef48bed51e2d0484af814903e23e578 184624 postgresql-plperl-15-dbgsym_15.11-0+deb12u1_mipsel.deb e190050befca3deff003cf76bedab9852ed1ea2e023637c571dcab01be5b1953 86756 postgresql-plperl-15_15.11-0+deb12u1_mipsel.deb e25dd6fc0332a2589e76db2b132263ac97fe30cce4fe3687cc2fc3c374d8ed8e 175924 postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_mipsel.deb ea67cf63cfd5c341224a36fe5847c8a56a490eb5dc6bff59b3fb39b69c6ea584 105116 postgresql-plpython3-15_15.11-0+deb12u1_mipsel.deb 0c77df44687bbe68ac0e90e2256521bb5bf85c347c0c01ca5faac2a5fc0cc426 80144 postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_mipsel.deb 8eef4330ee46de4b1bee288035b7288d2e7d875de7ff2c5a4b0b99e86fa925de 41068 postgresql-pltcl-15_15.11-0+deb12u1_mipsel.deb 070ef9bb6785b68a3a994ff653093aeb137f94e69bf33317a2a56ad3fd3ddf61 1155652 postgresql-server-dev-15_15.11-0+deb12u1_mipsel.deb Files: c628e5bd20763940c55bdcb3d34ef50d 17872 debug optional libecpg-compat3-dbgsym_15.11-0+deb12u1_mipsel.deb 2a33831c96256efc6565980a85df6365 17984 libs optional libecpg-compat3_15.11-0+deb12u1_mipsel.deb a5421bcc4ce4513455aeaff83069a641 261424 debug optional libecpg-dev-dbgsym_15.11-0+deb12u1_mipsel.deb 488a4993cd082e57f3ed1b7c370ad953 283932 libdevel optional libecpg-dev_15.11-0+deb12u1_mipsel.deb ed1015ec308b5e81d29ac388f41111d5 115700 debug optional libecpg6-dbgsym_15.11-0+deb12u1_mipsel.deb 6ea878922cca9de4789850164878971e 59956 libs optional libecpg6_15.11-0+deb12u1_mipsel.deb 9e6097afa082c72377e719e016c85e84 91636 debug optional libpgtypes3-dbgsym_15.11-0+deb12u1_mipsel.deb 943cf09af6a698164aed3d9d15383500 45240 libs optional libpgtypes3_15.11-0+deb12u1_mipsel.deb 8076286c871dccd59f652f032cdef2eb 151228 libdevel optional libpq-dev_15.11-0+deb12u1_mipsel.deb 6944fcfb03007dcdaf51808ca51169ae 283580 debug optional libpq5-dbgsym_15.11-0+deb12u1_mipsel.deb e70964c3a6a6466cb4023626502be018 178312 libs optional libpq5_15.11-0+deb12u1_mipsel.deb 9385a4eb04b4ae77adaac5fddbe9a602 16705416 debug optional postgresql-15-dbgsym_15.11-0+deb12u1_mipsel.deb 1a84cafd685d5822737ed1ee82302d66 16935 database optional postgresql-15_15.11-0+deb12u1_mipsel-buildd.buildinfo 916f11c6da2b1903fc78133c2573f563 16300844 database optional postgresql-15_15.11-0+deb12u1_mipsel.deb 0bda5c32fbe6561424eacfaa9c52adf8 2531152 debug optional postgresql-client-15-dbgsym_15.11-0+deb12u1_mipsel.deb 89946cef7d67d32f9a6ae3d21e043e65 1662648 database optional postgresql-client-15_15.11-0+deb12u1_mipsel.deb 9ad296ae6922a786e38ed7c4cb5baa5d 184624 debug optional postgresql-plperl-15-dbgsym_15.11-0+deb12u1_mipsel.deb 2cccbd45c0ec8015b55456aa5102fcd7 86756 database optional postgresql-plperl-15_15.11-0+deb12u1_mipsel.deb efc4d931c9abb862516670779b002694 175924 debug optional postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_mipsel.deb dc9fa348ff1904942047beeba93c39a5 105116 database optional postgresql-plpython3-15_15.11-0+deb12u1_mipsel.deb 77d90858dc4029776b93f5745b529d23 80144 debug optional postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_mipsel.deb 8f3adeb27010185d50db2aa3299d9df5 41068 database optional postgresql-pltcl-15_15.11-0+deb12u1_mipsel.deb f6f0dc85da3c59a5f26d5e6ac883a095 1155652 libdevel optional postgresql-server-dev-15_15.11-0+deb12u1_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEuQAPGkYIXAAfq7z1C2Vm2FYVKKAFAmeyJbMACgkQC2Vm2FYV KKA0cg/9FwFH68NGCmkZC2AdsmPcTHzAGQimanpGoOj7MEymtC233aE6ANzthYQV oJkZ8XIM/yazQtDghzgCFYJ5Hvi4BaWhitegz0c1nYe7LJqvz2rV6iPjOQSwzsaQ Aor1ABub8l8dDPi+ijvZ8SXDpRLq5hgkhF2LunqoGNKhB/+m52nq8DxFLnqkBQev wJyyUe/o5YppH2C5oQvbIiL+OHi0FPBtGU/7u1F5/CDtMFZnQO9lbSrZdV7HBZe+ S9txbbc9vysNCXMLJtafAtsdZ3wYaMgdPx3HVlklRjGOnSAMucY8p2zbuA+dTIHW yDb8bLlGe3kjBuHd3b09l3CXalyDqD7H24xxrDRPReGCcbQsfaoLw3y5vvmki0Ha 4x5haHMj6ZAuuRfut2gUQq3gqR9eaMNkUiqre8Tzi3+UG9fwKgfEwwSGhz51+4Jr ZhpFhiFiUNlxkHE7VylO2IJeJeBIMcJF4HBJ24rLiYh4S5IoBBNqV9/Y8vlreIwU lyfFBRJW2f7jhlhb7mMhva6mq74oAvodTVmPGyUUXE6tswacyB12xNv8zxEYXKvJ dNQkk6V9bX9nh7+BacEXEyeS0HgHu8ryILGHmbOhyG8xVoAXIiNtdacbr2t7P0aX sGFPMoyEeqK2vYLU29JT7PEZs4w8ZsQw+dewN8NH+zvkfBiED4k= =hmhM -----END PGP SIGNATURE-----