-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 11 Feb 2025 11:27:41 +0100 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: s390x Version: 15.11-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: s390x Build Daemon (zandonai) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.11-0+deb12u1) bookworm; urgency=medium . * New upstream version 15.11. . + Harden PQescapeString and allied functions against invalidly-encoded input strings (Andres Freund, Noah Misch) . Data-quoting functions supplied by libpq now fully check the encoding validity of their input. If invalid characters are detected, they report an error if possible. For the ones that lack an error return convention, the output string is adjusted to ensure that the server will report invalid encoding and no intervening processing will be fooled by bytes that might happen to match single quote, backslash, etc. . The purpose of this change is to guard against SQL-injection attacks that are possible if one of these functions is used to quote crafted input. There is no hazard when the resulting string is sent directly to a PostgreSQL server (which would check its encoding anyway), but there is a risk when it is passed through psql or other client-side code. Historically such code has not carefully vetted encoding, and in many cases it's not clear what it should do if it did detect such a problem. . This fix is effective only if the data-quoting function, the server, and any intermediate processing agree on the character encoding that's being used. Applications that insert untrusted input into SQL commands should take special care to ensure that that's true. . Applications and drivers that quote untrusted input without using these libpq functions may be at risk of similar problems. They should first confirm the data is valid in the encoding expected by the server. . The PostgreSQL Project thanks Stephen Fewer for reporting this problem. (CVE-2025-1094) Checksums-Sha1: d1caab02039ede98cd06c27fa6538e92dbfae65f 16492 libecpg-compat3-dbgsym_15.11-0+deb12u1_s390x.deb 1d32772fb4ac99f15f6cb0951256e6074c601f85 18256 libecpg-compat3_15.11-0+deb12u1_s390x.deb 217b6bde6cfbc5e19f54b0261938f982dfba5246 214684 libecpg-dev-dbgsym_15.11-0+deb12u1_s390x.deb 2fd40cf340b48f0c358e206312a1ec1d7b6ca510 281128 libecpg-dev_15.11-0+deb12u1_s390x.deb f501824d03e5c02097ec38c56199858fb643adac 112848 libecpg6-dbgsym_15.11-0+deb12u1_s390x.deb d4d3679ed78587094ba4949ab29e100637700542 60016 libecpg6_15.11-0+deb12u1_s390x.deb d7e7b9933a6a1818312e0cfd47b2447a65f102b0 88384 libpgtypes3-dbgsym_15.11-0+deb12u1_s390x.deb f01155259522c34fd0c9f465b255c2814bef5bda 45080 libpgtypes3_15.11-0+deb12u1_s390x.deb f6f049936d6e7ab75bec6eb19f43330fd9453bf1 139452 libpq-dev_15.11-0+deb12u1_s390x.deb 3717ef1e48d849dbd477dbdbe684b013c3268b35 273332 libpq5-dbgsym_15.11-0+deb12u1_s390x.deb be20a4968734904a7755a2463d1188dda30745b2 180240 libpq5_15.11-0+deb12u1_s390x.deb f29d2e12cd639f77e9fe9c558ba090f5b2b12662 15459744 postgresql-15-dbgsym_15.11-0+deb12u1_s390x.deb 7d8069b16b483e8324e61755c02a3f7ee78a7705 15984 postgresql-15_15.11-0+deb12u1_s390x-buildd.buildinfo ec4c7a368803e49b5e8533cd8e2648907017f58b 5651268 postgresql-15_15.11-0+deb12u1_s390x.deb a2de8b5517631cb0e3a217b9b236e8b86f307977 2441100 postgresql-client-15-dbgsym_15.11-0+deb12u1_s390x.deb 38d822512e2457fde56fdcebd5b2559a06fdd9f0 1662624 postgresql-client-15_15.11-0+deb12u1_s390x.deb 034ba5ec11366f5087a358d5b53666ec92bf1b62 180500 postgresql-plperl-15-dbgsym_15.11-0+deb12u1_s390x.deb 72c335c2e38fc46466c9df7d8a1a2e46f7b2bde4 66592 postgresql-plperl-15_15.11-0+deb12u1_s390x.deb 4cd3e3a5df66d8ed46840c157521d2d5068f4cfe 169972 postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_s390x.deb 81c596be4cef20bf43d9daba0709c1e4b5993bd3 89352 postgresql-plpython3-15_15.11-0+deb12u1_s390x.deb 470a93973919b1469d2e7c9ec2de4d4293082eb0 77740 postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_s390x.deb 751bd6732ed7dfa56101d749ad19ecb80aba7d06 42224 postgresql-pltcl-15_15.11-0+deb12u1_s390x.deb 75faa4c4a130f1c77bd76d4d2b69f52e5b0d8939 1140604 postgresql-server-dev-15_15.11-0+deb12u1_s390x.deb Checksums-Sha256: ad39ac7d7a3618e5ad01de915c7dec7f9d495b73b08037476c4fc14a64cf1d43 16492 libecpg-compat3-dbgsym_15.11-0+deb12u1_s390x.deb c155a9831c648166ee5ff03092fbe0440f341a119874ccb143d210e9b24aebe5 18256 libecpg-compat3_15.11-0+deb12u1_s390x.deb f7ff0bea67dba3324263b2c1294ba635eeff873ba310d7864b23da751f0c67ea 214684 libecpg-dev-dbgsym_15.11-0+deb12u1_s390x.deb 39806067874cee5769411ddc9a95fbc47709b960bbe64034b7ef30bd1d1cb662 281128 libecpg-dev_15.11-0+deb12u1_s390x.deb 0d91dffb48599f88be7c25af76d0c08fa240a66ffab075324ba1a3102db43f4c 112848 libecpg6-dbgsym_15.11-0+deb12u1_s390x.deb cfcfd25b33d636ee012de75d3be525f222c5c385ce06b8e816d0cc51ee394d00 60016 libecpg6_15.11-0+deb12u1_s390x.deb 1e297200031e920d648e933e280b9360729a4ecfd3b58ace22f43f9f7a4d8998 88384 libpgtypes3-dbgsym_15.11-0+deb12u1_s390x.deb 87ed37337318c55e6d608156b38879563491b495046e2224d75548f5df3ba806 45080 libpgtypes3_15.11-0+deb12u1_s390x.deb 343c7ed5efa173491ccb44bf75d088d4b31b35a50771b31a9f56dc15e2ec04bc 139452 libpq-dev_15.11-0+deb12u1_s390x.deb a15a99ee49f19839e1097fa85d0a31419a25f2bd1e583d40c63e7b3935e22c0f 273332 libpq5-dbgsym_15.11-0+deb12u1_s390x.deb 808a38287fc8fc6c527830df7a241e59a2fd390d3c8e4597ea776a8f92733601 180240 libpq5_15.11-0+deb12u1_s390x.deb cfa0a172db1deba7a2941c3102443b67badc1c4f92ef7104c88c7e1082f461a9 15459744 postgresql-15-dbgsym_15.11-0+deb12u1_s390x.deb 7aea68e5d7ab41c53ac7b03b888d5846b85c0d4fe563702cf919a0c54279852d 15984 postgresql-15_15.11-0+deb12u1_s390x-buildd.buildinfo 8d10be3a9ebe43b96fac64945ff8d1df37eac5abde5e6f30378d1babb92b3cdb 5651268 postgresql-15_15.11-0+deb12u1_s390x.deb eb2aa68cef6d2a8ffe4cbea8c59f008a251247afc95fecaf8cc3174d90b5291d 2441100 postgresql-client-15-dbgsym_15.11-0+deb12u1_s390x.deb eda9124b774a0a493b30df85f0128b223a8fa5cd72fe8a227981fabcb0e99a91 1662624 postgresql-client-15_15.11-0+deb12u1_s390x.deb 2872897573c2234185dfd9e23d537a9134b6a000ddd3386a8613da73c967eed5 180500 postgresql-plperl-15-dbgsym_15.11-0+deb12u1_s390x.deb aa1609822db0ed5d159f4141b84e78500d7aa9c8b8018e387943fa8e8c9727af 66592 postgresql-plperl-15_15.11-0+deb12u1_s390x.deb e3e251f200cd777ddea137ad0bfa593d0a34d1cbb21d459d367e9cfa6436ff2c 169972 postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_s390x.deb 898441c70de1504640c08440ca642346d3e3d68c17072076c0aa8186986c8489 89352 postgresql-plpython3-15_15.11-0+deb12u1_s390x.deb 9d647555f738662478f53b793cc12c2abf5c416148d3fb47072d92c9cce8186c 77740 postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_s390x.deb d464859044c7d1de8b1f0c1744cb019f717ed55a5666814973cce102d1f05836 42224 postgresql-pltcl-15_15.11-0+deb12u1_s390x.deb 42e0018c2957e5de46d1ba280d8930432715386e1d59bded2f5a8dc203d2dfae 1140604 postgresql-server-dev-15_15.11-0+deb12u1_s390x.deb Files: f8ef0136574ff35e49aa32a93ab82672 16492 debug optional libecpg-compat3-dbgsym_15.11-0+deb12u1_s390x.deb 56b0a08c3368c2dfe88897e8a05d1ba5 18256 libs optional libecpg-compat3_15.11-0+deb12u1_s390x.deb d0fc062029e8c9f6ee0fb628a5f5e881 214684 debug optional libecpg-dev-dbgsym_15.11-0+deb12u1_s390x.deb 6b2ff0f186531fb540a51c0e2a2e0055 281128 libdevel optional libecpg-dev_15.11-0+deb12u1_s390x.deb 8e9de1288de3a8ab5a93f27e350b6d05 112848 debug optional libecpg6-dbgsym_15.11-0+deb12u1_s390x.deb ffbae5f7c485e730b5cec026dd628d60 60016 libs optional libecpg6_15.11-0+deb12u1_s390x.deb 70d2814bdd6b6b9d2104597ff3347f27 88384 debug optional libpgtypes3-dbgsym_15.11-0+deb12u1_s390x.deb c43ee492f5a681ca99faf7e42a6c2480 45080 libs optional libpgtypes3_15.11-0+deb12u1_s390x.deb 4c938abff27fbd25330cb698d812771a 139452 libdevel optional libpq-dev_15.11-0+deb12u1_s390x.deb b738762e186504e71d93a0bf4e80aa93 273332 debug optional libpq5-dbgsym_15.11-0+deb12u1_s390x.deb be80eda71fa0ddfa59b7d0f5cda75f2b 180240 libs optional libpq5_15.11-0+deb12u1_s390x.deb efd5dd8214aa95d5914dfbaaa09f8437 15459744 debug optional postgresql-15-dbgsym_15.11-0+deb12u1_s390x.deb 3ac51a5f858131d4114b60baa28924bc 15984 database optional postgresql-15_15.11-0+deb12u1_s390x-buildd.buildinfo 734d2e10682b5a00adb731ca77d8f656 5651268 database optional postgresql-15_15.11-0+deb12u1_s390x.deb 07467dc620a543c5d344d45316e46ef7 2441100 debug optional postgresql-client-15-dbgsym_15.11-0+deb12u1_s390x.deb 04ceae2f3963789e53a7e08737d14968 1662624 database optional postgresql-client-15_15.11-0+deb12u1_s390x.deb 72046dcc88ba8b92d36d3b257bc9f901 180500 debug optional postgresql-plperl-15-dbgsym_15.11-0+deb12u1_s390x.deb af9179ca638fddd229c8e121f1aa5c6c 66592 database optional postgresql-plperl-15_15.11-0+deb12u1_s390x.deb 3072839a3c0bdaa9ed5a6dd758c85009 169972 debug optional postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_s390x.deb f289f795650b0ec741e202cff4566658 89352 database optional postgresql-plpython3-15_15.11-0+deb12u1_s390x.deb 72b0cfd270a04d573bd3757852240be5 77740 debug optional postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_s390x.deb 2e0989a7453ca1f049aaf8f98dfbd00c 42224 database optional postgresql-pltcl-15_15.11-0+deb12u1_s390x.deb 09f683068b1d646c345f07d4bf7283a0 1140604 libdevel optional postgresql-server-dev-15_15.11-0+deb12u1_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEu0D/YpnnSxv8epH9AKOyQzsWVasFAmeyAoAACgkQAKOyQzsW Vasa5w//RQ3ziuoOuawRov0gmr2RdmNaadqnTCYm6+c05LHHl8kOPAqjgziVf0ym bnVM08uUgF9VQETCxfFIfNIsb7ItQbcXWTqHarwAgwwF9AUtNpvObap0MUIWe0ye Z2cXAiUk+d3mh3/X7LOV/rH+b3NIh4nm5bGljk7mb32zVIF6kQ11NG6DvDmeAz+A 57q4X9IjnzLW0p5lPpVoo8fwjb9W8cpsWGLuM8Qe95d5njYfy3Fos9w3AqHAjxbf c5WIM52l9im5+fnQY2ukzlJpACHqMdyHETiXmAT565RldxIbNhCQEVu+4UB6MhOA o/yetFsD02MwpUlcEz+aKvj73jT5KAnIpVER9iJ8TD5OX1f0LGarBTHy3nm2kQQQ lv8g5JUGwKTdqpWON2rSnlTUBE04A54hRI6WVoRcp/djpzZ1q7vFOLWUm8i7fxZo VYM4j617kxDrS5IiTTjlF36cXY4UbfLqfLqkgf9Ov2e/8bYogKHhGuzb2/tQM/CV vCMozlO6OuQ+Td4Mz03BbpLhtAAfkZpQFWsmegrUquVfJf3G25bRHBech4MW56fh 0dXSHdPVnACFiVN7wF1+12imJYYFWIM7mpP3ANAI3KPw6ZVYt0iOh6OvLnN+YCeB ZURgJFTRR82RDz+902KXsRBYg3pfMbQRekAYQcsWcjOeXw71EFU= =zFVB -----END PGP SIGNATURE-----