-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 11 Feb 2025 11:27:41 +0100 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: armel Version: 15.11-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-ubc-03) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.11-0+deb12u1) bookworm; urgency=medium . * New upstream version 15.11. . + Harden PQescapeString and allied functions against invalidly-encoded input strings (Andres Freund, Noah Misch) . Data-quoting functions supplied by libpq now fully check the encoding validity of their input. If invalid characters are detected, they report an error if possible. For the ones that lack an error return convention, the output string is adjusted to ensure that the server will report invalid encoding and no intervening processing will be fooled by bytes that might happen to match single quote, backslash, etc. . The purpose of this change is to guard against SQL-injection attacks that are possible if one of these functions is used to quote crafted input. There is no hazard when the resulting string is sent directly to a PostgreSQL server (which would check its encoding anyway), but there is a risk when it is passed through psql or other client-side code. Historically such code has not carefully vetted encoding, and in many cases it's not clear what it should do if it did detect such a problem. . This fix is effective only if the data-quoting function, the server, and any intermediate processing agree on the character encoding that's being used. Applications that insert untrusted input into SQL commands should take special care to ensure that that's true. . Applications and drivers that quote untrusted input without using these libpq functions may be at risk of similar problems. They should first confirm the data is valid in the encoding expected by the server. . The PostgreSQL Project thanks Stephen Fewer for reporting this problem. (CVE-2025-1094) Checksums-Sha1: 4fe046ebaebe74267a32ee2ecf003bf193a95d7a 16372 libecpg-compat3-dbgsym_15.11-0+deb12u1_armel.deb b698049ba2e5c22238137d56405bb483966c7102 17256 libecpg-compat3_15.11-0+deb12u1_armel.deb 463ad49e57ee3a03a33b87364c3c2773adcf331d 232528 libecpg-dev-dbgsym_15.11-0+deb12u1_armel.deb 9ca965cd918c70a3c56850c87f4b15d31586ad8f 273528 libecpg-dev_15.11-0+deb12u1_armel.deb f6fc0fede0cc209e2f2d2e52154342ebb3ffe9ca 111208 libecpg6-dbgsym_15.11-0+deb12u1_armel.deb 50333ad4a79cd44409dca773b8112dcb723f22d2 56460 libecpg6_15.11-0+deb12u1_armel.deb ddfcb86e2a46dc41e04f34cfe75fa132c5a74e3b 86568 libpgtypes3-dbgsym_15.11-0+deb12u1_armel.deb 246daf5448a47658c41e3f7dc113f9786326bfff 42724 libpgtypes3_15.11-0+deb12u1_armel.deb 94e59b7a17ba6bdeb325d98fa45c458cbfd872d7 134516 libpq-dev_15.11-0+deb12u1_armel.deb 5bc722219e3b4cf2fb4ff79e8c267f9d49bbd6f4 270440 libpq5-dbgsym_15.11-0+deb12u1_armel.deb 0b9bf52a298ecfe3627b6f86ee49f3ded5d792d1 171776 libpq5_15.11-0+deb12u1_armel.deb fd7f2765456a99bb44a5e312d453dd344b48207e 16195892 postgresql-15-dbgsym_15.11-0+deb12u1_armel.deb 23f5da0588b81ec3ad24afcc1cce6d123ad5f41d 16919 postgresql-15_15.11-0+deb12u1_armel-buildd.buildinfo 0f93b3d03afad470be9627cd7192f14791bf5039 16143160 postgresql-15_15.11-0+deb12u1_armel.deb 17faeb9c46a20cfecdb293e06300e4951e650e39 2409548 postgresql-client-15-dbgsym_15.11-0+deb12u1_armel.deb b620e3b2637485e07cac4d720927a98b62c51087 1612432 postgresql-client-15_15.11-0+deb12u1_armel.deb f59d545714b2508b09047182d567b6e656eeb9cb 181792 postgresql-plperl-15-dbgsym_15.11-0+deb12u1_armel.deb cb60b537aeabf4ab0b6fa9de1388d4806555a585 88268 postgresql-plperl-15_15.11-0+deb12u1_armel.deb c64cdfcd437db190dfbf0c4e33baacc0d2200f05 172404 postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_armel.deb 967c6237fc0a1e0660c45ec1e8aa8e40925db966 107052 postgresql-plpython3-15_15.11-0+deb12u1_armel.deb 0283b2380395eaa12789e7ae681bbcdec82d8ab3 78032 postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_armel.deb 5806cbda93f58a4c29bdea9e820fbd806935b422 41044 postgresql-pltcl-15_15.11-0+deb12u1_armel.deb 4cd16b3d336282e8935e89fcd86b988a8975b23f 1135444 postgresql-server-dev-15_15.11-0+deb12u1_armel.deb Checksums-Sha256: 78c0efc894a3581b7d10bb45604fa1e5f45e2140ed0c2dd99d8ed99eddfb9113 16372 libecpg-compat3-dbgsym_15.11-0+deb12u1_armel.deb fe6827fdd71a2080aa82e334fc77d1e42a97b2166f45f16d0c90cd6bc92b22d8 17256 libecpg-compat3_15.11-0+deb12u1_armel.deb 0f83e152f2e7c7e9c78f80a549575f91e0931b17b9c18d3e99092e35c017aec7 232528 libecpg-dev-dbgsym_15.11-0+deb12u1_armel.deb 8e54bec0c333ec05af1bf4fbe290fa3b72da547ff3d0f02a0846230b979913b3 273528 libecpg-dev_15.11-0+deb12u1_armel.deb 3293e739fe4b33bd1dfb290a7274b8c7ce3e9f043f559917370ecbec52d0c3cb 111208 libecpg6-dbgsym_15.11-0+deb12u1_armel.deb 70b72c526dd5e6f95c17f91514d7aa1ab4d22a088409502c0b2a85b4abe683ea 56460 libecpg6_15.11-0+deb12u1_armel.deb 89c644eaa6cee6399d3e1587f1db664c35135251310d7760e2ec78c14f494066 86568 libpgtypes3-dbgsym_15.11-0+deb12u1_armel.deb 8850ea32b2ae15593231c3dda97498400355bc4f4ada6b137168a6cc31af00a6 42724 libpgtypes3_15.11-0+deb12u1_armel.deb b18bbe4d7ac1f756ca605981401f78ecf274c4e59ccd5e9224c236d9fa7d616a 134516 libpq-dev_15.11-0+deb12u1_armel.deb c76c83e7c12fbf080ea51c90ffd9539b4e2d527bd4c992211bc777246881f5d3 270440 libpq5-dbgsym_15.11-0+deb12u1_armel.deb 9e90c0e9017db642ec5b20518f3c4e4e03edc53d3f1cc64dbd455d0f56556da5 171776 libpq5_15.11-0+deb12u1_armel.deb 6fc3020548e62bf81443c1a0fd11abcca457e4c9caee412242ea853b367eb90c 16195892 postgresql-15-dbgsym_15.11-0+deb12u1_armel.deb 33dd219062e0d9eb126faf78e06b65ba02c690ef3e39c978a4f88f628a9bd67f 16919 postgresql-15_15.11-0+deb12u1_armel-buildd.buildinfo f20dabb4dce985c89cb93f1d1cc580edb76c257b3d3f391598b17cb2c8f6f5fd 16143160 postgresql-15_15.11-0+deb12u1_armel.deb 8a5c38a708658082e0ccedc5c66678b028b4596f90810009aa6959147165a1b8 2409548 postgresql-client-15-dbgsym_15.11-0+deb12u1_armel.deb 10dfe868f5a847fe7d060132805570006ec59a47dfa3223d5186684f70ac468e 1612432 postgresql-client-15_15.11-0+deb12u1_armel.deb 614e99e5b7402efd53faf87fa18a6d080e478060599783271232fa24c30afbd8 181792 postgresql-plperl-15-dbgsym_15.11-0+deb12u1_armel.deb 5ad0e912a1bf85e7d4629bad7a6387014f95e250803f367b9f250f898044fa85 88268 postgresql-plperl-15_15.11-0+deb12u1_armel.deb 5667725ed1232bd2d47d866e845e756254e445bdb659e9affe08016a69bc1c3f 172404 postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_armel.deb 6e88530b9a8aaf49ae545cf5bcde52485ea089ce58a07099daeadaade93c81d9 107052 postgresql-plpython3-15_15.11-0+deb12u1_armel.deb ec72255d476cbfe2fd15ac95543185d2c4a7cfe9e150892160f1640a7e37b880 78032 postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_armel.deb d3f61bd6e1c01947519f3f77726716d4ebbda5a0961f4104f9cad297050c7216 41044 postgresql-pltcl-15_15.11-0+deb12u1_armel.deb d907cf80fb86afb66edbdbfd7d9e9094ebc85d3f04c82d8bc965733b7fc9f12f 1135444 postgresql-server-dev-15_15.11-0+deb12u1_armel.deb Files: 0504413b5eae2d04db576c76f4b1e81a 16372 debug optional libecpg-compat3-dbgsym_15.11-0+deb12u1_armel.deb d3fabad38de252e62845e2f31de0f536 17256 libs optional libecpg-compat3_15.11-0+deb12u1_armel.deb bfa8ac6ff37ed3e202c850e887afee91 232528 debug optional libecpg-dev-dbgsym_15.11-0+deb12u1_armel.deb 25e7035cafdbe77d74ac53e671c8a2ca 273528 libdevel optional libecpg-dev_15.11-0+deb12u1_armel.deb 324afc361caa96818ca5f24db85a85be 111208 debug optional libecpg6-dbgsym_15.11-0+deb12u1_armel.deb d0eb6857e4374308ff91c2da1d72669d 56460 libs optional libecpg6_15.11-0+deb12u1_armel.deb 58064dd2d5d33bb0c84974fb70b55d6f 86568 debug optional libpgtypes3-dbgsym_15.11-0+deb12u1_armel.deb 12c5d0f807ad7292ad39dd504ef48225 42724 libs optional libpgtypes3_15.11-0+deb12u1_armel.deb c0cb37911420f5c9c25fe137ff11602d 134516 libdevel optional libpq-dev_15.11-0+deb12u1_armel.deb 44bf8f5a9c7343d3e4fe5712fc6c1ce7 270440 debug optional libpq5-dbgsym_15.11-0+deb12u1_armel.deb fd9970672c5b01e4d2cfd4fe8df38984 171776 libs optional libpq5_15.11-0+deb12u1_armel.deb 4316b251ad4a1f1bb68d427cf0d63947 16195892 debug optional postgresql-15-dbgsym_15.11-0+deb12u1_armel.deb 83c8654eda742a06fd24f56143b194c3 16919 database optional postgresql-15_15.11-0+deb12u1_armel-buildd.buildinfo f3c46c59d0b7829d92daf9e96e254fb6 16143160 database optional postgresql-15_15.11-0+deb12u1_armel.deb 7b68cabac3cd55cc9c5bf2744e3bbbda 2409548 debug optional postgresql-client-15-dbgsym_15.11-0+deb12u1_armel.deb 63af2fcb6de63bcc5ae049edec5fa0d9 1612432 database optional postgresql-client-15_15.11-0+deb12u1_armel.deb 702e034019bb1a187f137fe527077458 181792 debug optional postgresql-plperl-15-dbgsym_15.11-0+deb12u1_armel.deb dd3f447a299a1029cd5a26cd362ee182 88268 database optional postgresql-plperl-15_15.11-0+deb12u1_armel.deb abb70302587af38e689f22f32dec5e32 172404 debug optional postgresql-plpython3-15-dbgsym_15.11-0+deb12u1_armel.deb 55215176a0e4d8d53c314e3d7da75304 107052 database optional postgresql-plpython3-15_15.11-0+deb12u1_armel.deb cd478e2636ea1f962d07088da00ad9f1 78032 debug optional postgresql-pltcl-15-dbgsym_15.11-0+deb12u1_armel.deb c8f25ce309c0e4555eef6398af9a0cae 41044 database optional postgresql-pltcl-15_15.11-0+deb12u1_armel.deb 4ce353dc1c929afeddd447b281b275fb 1135444 libdevel optional postgresql-server-dev-15_15.11-0+deb12u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0+FegZ3qs8CHnZkx+XaKpT5fkBIFAmeyIH4ACgkQ+XaKpT5f kBIetg//UVdMYUvYxMS8bWHOOALTD9gUI+91z0NrHFnwWKLNChHUlFHI+FBRv37b l+Dx3j5aw4SxyRARGO+US8BwDZlkOR4Q3Kl+2j4npfYnVAR9+vvmhhMWddekKfq9 DJj0jiuXb2Ms0vJSbC0hys875Aq+b6mG1jTfYJguy0jIIBRJuI2CaQy2CQz1vULC TMSMVUKbU9376vDal6JlZTZTqvc1lI3QSctzUue1kkLyY5pPsVnflRf/Lr4+NFlk W2QpC5hJ2+8VpSZKFHDGh5g3/FP7aQ6stJj/Vi8HnWEruGb9CgzDksK22Ltso42r uTS0ET6O3W8eLYVrQ5v9WSvUDyzGQZfxw/v0sS+gf7k3m0xiXP07TkoDEPcEbUnj uoY6nvl01B05gGbcbTZugHJv0bUBiUZNq09epy/rGaeXP+S9IwJ71zB/+Bl5vqwi KTqm354e9Wn1/DRfxh3LbQhiy6aNNyLoCT7gmH5v4i5UyCRnrOSktzA4zvhIWaYc OiinzRXssXJhwTZpKCcX+bSNizIPXz8cbe20i9MICslYg4x1k0rhzZBb5MnmH+ho LVVieX8rjzUUifXhsGCavToMckPcxl6dVpfP90udTaBSjh94kHN69rBb0dPXNvNS DZNQjPDlGOROAoGCJz9cr23+y8T8z0lRTIJqOaZyEKyZcASxOHU= =oDCE -----END PGP SIGNATURE-----