-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 18 Feb 2025 11:59:37 +0100 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: armhf Version: 15.12-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.12-0+deb12u1) bookworm; urgency=medium . * New upstream version 15.12. . + Improve behavior of libpq's quoting functions (Andres Freund, Tom Lane) . The changes made for CVE-2025-1094 had one serious oversight: PQescapeLiteral() and PQescapeIdentifier() failed to honor their string length parameter, instead always reading to the input string's trailing null. This resulted in including unwanted text in the output, if the caller intended to truncate the string via the length parameter. With very bad luck it could cause a crash due to reading off the end of memory. . In addition, modify all these quoting functions so that when invalid encoding is detected, an invalid sequence is substituted for just the first byte of the presumed character, not all of it. This reduces the risk of problems if a calling application performs additional processing on the quoted string. Checksums-Sha1: d925132a410d2505863eb2fa401fdb15eca424e5 16672 libecpg-compat3-dbgsym_15.12-0+deb12u1_armhf.deb 90b0e9bc747e564fe786ab76eb5cd95fd88902a0 17596 libecpg-compat3_15.12-0+deb12u1_armhf.deb 73b5cafeaa78d2b44e5290d1b54eb13345e63991 236348 libecpg-dev-dbgsym_15.12-0+deb12u1_armhf.deb 55062e98c0240eeacbb97a51fb1bb745d0b407b1 279180 libecpg-dev_15.12-0+deb12u1_armhf.deb 2b09454ad3d6386c733dfba53558182b78eb9df6 112204 libecpg6-dbgsym_15.12-0+deb12u1_armhf.deb 8b7042d5e7f198df97e57c48e6f0705ef576e507 55228 libecpg6_15.12-0+deb12u1_armhf.deb e71d4527754d563ce9afb955af32896284ba5fa7 88576 libpgtypes3-dbgsym_15.12-0+deb12u1_armhf.deb 0f4d6fbd10d8a55fcb1a2730e2f7d3bc6b20c8ff 42108 libpgtypes3_15.12-0+deb12u1_armhf.deb e35a2b2f4cbcb39e73567d686769758c61d23b76 134644 libpq-dev_15.12-0+deb12u1_armhf.deb 4dc9f9151b7c4ada516ef6ff2e9bec60bc176ffb 274308 libpq5-dbgsym_15.12-0+deb12u1_armhf.deb 8514221bda8243a5e477720ee7834c0759bbb08d 172960 libpq5_15.12-0+deb12u1_armhf.deb 21177af5781b3966ae10622226b5d74ec75e0bfe 16275780 postgresql-15-dbgsym_15.12-0+deb12u1_armhf.deb 9105a7b83025df73af343ec94f72537e6988e346 16921 postgresql-15_15.12-0+deb12u1_armhf-buildd.buildinfo 9247fd5c99bbc8e23a324e21f1dcd28bd41402e5 16062740 postgresql-15_15.12-0+deb12u1_armhf.deb 49f15f58eac013dbb2608ddf2a25c0afb6e66e31 2436924 postgresql-client-15-dbgsym_15.12-0+deb12u1_armhf.deb 696b95db09610914bdb5e6d454c77f13e9d346c6 1627908 postgresql-client-15_15.12-0+deb12u1_armhf.deb 35f6580cf3b425382b0cafff7ebeac875def992f 182844 postgresql-plperl-15-dbgsym_15.12-0+deb12u1_armhf.deb c33d8065ac6da78e3efee95d5c20d5ccb28cca9f 88364 postgresql-plperl-15_15.12-0+deb12u1_armhf.deb 53e5eecba1bac8856da1e0140e1d74141933fb88 172584 postgresql-plpython3-15-dbgsym_15.12-0+deb12u1_armhf.deb 96042982b41b933c7058c8d66c728965d188f338 106784 postgresql-plpython3-15_15.12-0+deb12u1_armhf.deb 3e7ff2d75e54268d8eb5f8995ae57c031b3b2bc5 78300 postgresql-pltcl-15-dbgsym_15.12-0+deb12u1_armhf.deb ec3c5dd1bd8401fb958470de1c2b8de4c42a6e7e 41452 postgresql-pltcl-15_15.12-0+deb12u1_armhf.deb add68832da3fec93b7da60659d0f23251e74d38b 1134360 postgresql-server-dev-15_15.12-0+deb12u1_armhf.deb Checksums-Sha256: 0cfe59844272045ac59e285257b3e6a1b26a8f8b96c780d3b281b2969290c3ff 16672 libecpg-compat3-dbgsym_15.12-0+deb12u1_armhf.deb a39d7b5e4cb393ce12e79427e7b7020173b6f1a3c06d670313f64becf689c89a 17596 libecpg-compat3_15.12-0+deb12u1_armhf.deb 06a0a464c7014a3ea2a318556e46d5d0d01d1852ed7e4922d2224ed9175ceb47 236348 libecpg-dev-dbgsym_15.12-0+deb12u1_armhf.deb dd191e1c450fb8fe9b85807864657e74b7c04e00cf5ecbf9a961bdb53fd6eb8d 279180 libecpg-dev_15.12-0+deb12u1_armhf.deb 809b9de7575f9c0d05cd987f88e1e95d993c4bceb71c811a77de3fc0f6878ae4 112204 libecpg6-dbgsym_15.12-0+deb12u1_armhf.deb 8d154ff3c39bee3f2dbdac43f2fa2bc099bad338317f61df4b11f0c92f3b8050 55228 libecpg6_15.12-0+deb12u1_armhf.deb 494d343f896e629b410a9c85b27b7b28a526908aaa50a1fe1c3ecf49028aef52 88576 libpgtypes3-dbgsym_15.12-0+deb12u1_armhf.deb 441157908529fe46c39c5345965ffd78b927d8bace767c11aeffa30d764b51c5 42108 libpgtypes3_15.12-0+deb12u1_armhf.deb 51c3c9da6567760403ae55d5bf2d3320438b461844c6e89d25af56a9501319f2 134644 libpq-dev_15.12-0+deb12u1_armhf.deb 3da57d20e098ca6f54c1d1634a8468ab5bfc9e3a55eed74f16582439ba9febe4 274308 libpq5-dbgsym_15.12-0+deb12u1_armhf.deb 85d1d987d01bb466fc867808159ac2f6b3ed1800ee7e5a6562a8200675e16648 172960 libpq5_15.12-0+deb12u1_armhf.deb aff8a442763a70d253fbdd8e8abc5e1f5def349b49594f2af25325f800b772fe 16275780 postgresql-15-dbgsym_15.12-0+deb12u1_armhf.deb e4d50f273eead8008be2c17999539478938ac0f3baddd912f5826d7fc6b156ff 16921 postgresql-15_15.12-0+deb12u1_armhf-buildd.buildinfo 66821d36aab8cd86fcbda7255676814cfd75fc972b02d238384488860cb2e7a3 16062740 postgresql-15_15.12-0+deb12u1_armhf.deb b4f33b458e7a6890d81c22fa19bf831c517638f95404ce38eec05c28de650c05 2436924 postgresql-client-15-dbgsym_15.12-0+deb12u1_armhf.deb 2224fc184920233625e1f5225cdea82241dfb7da5cc2497dd534e1bf820ce052 1627908 postgresql-client-15_15.12-0+deb12u1_armhf.deb 9fa3837ba17fe0faace999aca1b626529e0c6f0219b77969d6ec59db52734b50 182844 postgresql-plperl-15-dbgsym_15.12-0+deb12u1_armhf.deb 6e2034c41e98e54e9f63466836b0fb69f721e435e8b4e3486c9b697b17916881 88364 postgresql-plperl-15_15.12-0+deb12u1_armhf.deb 5a3ad0be3d41c0f2f1f535d0ff5cd29859b48a1284cdfd3b92617b4d48bebe10 172584 postgresql-plpython3-15-dbgsym_15.12-0+deb12u1_armhf.deb c424315948f5a48960c98ef2aa8033b7c9728d6d6f4763a4fde11d976b6f376c 106784 postgresql-plpython3-15_15.12-0+deb12u1_armhf.deb 89efa0582ba099c78a97668ec32bcd34736b427d9c2cf0b100ded8035528dd29 78300 postgresql-pltcl-15-dbgsym_15.12-0+deb12u1_armhf.deb f65c4d753830cc1834239866659ef412225a31707aaf08e38c32bed92c66aef9 41452 postgresql-pltcl-15_15.12-0+deb12u1_armhf.deb 2f06b122e47a5fed48c0591bad925d40482967bd5c71cd13aad0f52f2549a7bc 1134360 postgresql-server-dev-15_15.12-0+deb12u1_armhf.deb Files: f50ca64b4e4e06bebf5e3eaafc9fb310 16672 debug optional libecpg-compat3-dbgsym_15.12-0+deb12u1_armhf.deb 97e835dead429a2205c2579d00701a2f 17596 libs optional libecpg-compat3_15.12-0+deb12u1_armhf.deb 37549d45ad338dabec6f94278f8cf99a 236348 debug optional libecpg-dev-dbgsym_15.12-0+deb12u1_armhf.deb 691c92028c46cac7b80510967b4fe849 279180 libdevel optional libecpg-dev_15.12-0+deb12u1_armhf.deb d7e3a48e6e76cce8218da13a7c743697 112204 debug optional libecpg6-dbgsym_15.12-0+deb12u1_armhf.deb 8f940e5e015b5107dc2dbcec1b0b1cbb 55228 libs optional libecpg6_15.12-0+deb12u1_armhf.deb 866bd5647830c02b1845409750d66a41 88576 debug optional libpgtypes3-dbgsym_15.12-0+deb12u1_armhf.deb d40bf879184ed9a2794859550388bb82 42108 libs optional libpgtypes3_15.12-0+deb12u1_armhf.deb 57209af3c3a0f55b11df80c58f2a7ac1 134644 libdevel optional libpq-dev_15.12-0+deb12u1_armhf.deb 147366e6cba1c9a4fc3813f85c7d6fc3 274308 debug optional libpq5-dbgsym_15.12-0+deb12u1_armhf.deb cda688d8d3cc0b496a29ab28b4c69bd2 172960 libs optional libpq5_15.12-0+deb12u1_armhf.deb a7af32bda503ad359e48f970a284be62 16275780 debug optional postgresql-15-dbgsym_15.12-0+deb12u1_armhf.deb 01ea457afcf96a911165089ec5293db0 16921 database optional postgresql-15_15.12-0+deb12u1_armhf-buildd.buildinfo a1725794f45c6119b3c269b0dca5baa3 16062740 database optional postgresql-15_15.12-0+deb12u1_armhf.deb f1a47a63bff341ba7014292746041786 2436924 debug optional postgresql-client-15-dbgsym_15.12-0+deb12u1_armhf.deb 135c555943a9d90c0c5a530bda7ebf0e 1627908 database optional postgresql-client-15_15.12-0+deb12u1_armhf.deb 47b15eabb1fa4611d42795184de02b0a 182844 debug optional postgresql-plperl-15-dbgsym_15.12-0+deb12u1_armhf.deb d2aea55d4fe54b6b8b0dded1254f213c 88364 database optional postgresql-plperl-15_15.12-0+deb12u1_armhf.deb 10e80303f1398b170f1c85645f1e2e62 172584 debug optional postgresql-plpython3-15-dbgsym_15.12-0+deb12u1_armhf.deb e91c0a95853d62f797bf6535abeed7aa 106784 database optional postgresql-plpython3-15_15.12-0+deb12u1_armhf.deb 4ff5b36e3e425946a9f3f7fe590e58e1 78300 debug optional postgresql-pltcl-15-dbgsym_15.12-0+deb12u1_armhf.deb 2488a27c3142047a2a9b57603e114aef 41452 database optional postgresql-pltcl-15_15.12-0+deb12u1_armhf.deb 4428f1b5583b20707423276f0d3d0e3f 1134360 libdevel optional postgresql-server-dev-15_15.12-0+deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEegRwmIwj8f99iF4m4CwlMGxHD8UFAmfDPeYACgkQ4CwlMGxH D8Uo9hAAmqcNQUk81B0dfOkTydogtuWKIw34c6V5H4yTJQmzSeLqi8g+F2nBJUPT q7A+Zz9qJrOsh/2nbO9WXAH/oATywqFgbMKF5EvVv1MytAD0PKVdhsYsANAxESc0 XXSH4V41aHkhQ+tTCMjOdV4aP8sce4LlchcAg6O1rIKxMPyi/Zdk+18ONH4o+dlk nvvG6mZAs0NbnMQ3lNKy0IWtKGVL9J0ypHGHLFSpyvw0SIPs04czi7sOPm3KF5ai le61lpynAdIhRXffG7ea2dtAfPvH1qmCM5WSitbZLNZ9W0070e18OPtl8scjEnot TxXnWZw/iGmb7+3Z/cpV3sV3BMwDjkMcUZhanpu3E/1l0jWaSIXVfjKJzRLpqngw NE09RUgPWUqqxNyUj8yAF/X6f7pXkXJ+E8z726XE0Gfx1N54Cy6cJfnOYnRUuthE mbeeRtNd/HLjfcpe/K2YlI2two+3aP55xGkjko9gIjqn+Mes167GIX5BmadgiXva aFDexmPaS3cSZxx7dopJ76ee4K7MbnvxCNShD4XkvsXj1zsb7TVFK8UTv71zK3DZ nKDG4o3VEnKBf8DiBG3P4yLjflKOfzsvdoLirRjHrg6AcostgK6f11O5nxOh49um N/nF6WlunG/mdh9Jof/reL/u/UFLHTFdaYPSvg8bcv+9Gix/NJM= =OQTO -----END PGP SIGNATURE-----