-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 18 Feb 2025 11:59:37 +0100 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: i386 Version: 15.12-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.12-0+deb12u1) bookworm; urgency=medium . * New upstream version 15.12. . + Improve behavior of libpq's quoting functions (Andres Freund, Tom Lane) . The changes made for CVE-2025-1094 had one serious oversight: PQescapeLiteral() and PQescapeIdentifier() failed to honor their string length parameter, instead always reading to the input string's trailing null. This resulted in including unwanted text in the output, if the caller intended to truncate the string via the length parameter. With very bad luck it could cause a crash due to reading off the end of memory. . In addition, modify all these quoting functions so that when invalid encoding is detected, an invalid sequence is substituted for just the first byte of the presumed character, not all of it. This reduces the risk of problems if a calling application performs additional processing on the quoted string. Checksums-Sha1: 0bc3c240e924eed6ab1f970afd8f96f3372bdbf7 14404 libecpg-compat3-dbgsym_15.12-0+deb12u1_i386.deb 0fb6616888dac60b8147f8ab0c418470507f8531 19268 libecpg-compat3_15.12-0+deb12u1_i386.deb 2223676c935a230a90178ba336bcfb49332be525 270788 libecpg-dev-dbgsym_15.12-0+deb12u1_i386.deb 8d53fe841b10b97fc536d4bbe270e1480fa15751 307364 libecpg-dev_15.12-0+deb12u1_i386.deb b96799ab02624e2fe713b30e72ab2c1ec38679e2 102324 libecpg6-dbgsym_15.12-0+deb12u1_i386.deb 3ac82d32edbbdf9e07df3e24cf1994eda0b85bbc 66876 libecpg6_15.12-0+deb12u1_i386.deb 4047ffa6ec1d76d1decc139109f7ee2c2671f9ef 80756 libpgtypes3-dbgsym_15.12-0+deb12u1_i386.deb 99660c79de7209380020de83c312df7acc632dc8 48676 libpgtypes3_15.12-0+deb12u1_i386.deb 1aaf6cc72ff3a975c65d00a96bdf45f6b527b7db 156620 libpq-dev_15.12-0+deb12u1_i386.deb 48d57803afb0c37fa7a614ba48aa30b5ff98da97 242264 libpq5-dbgsym_15.12-0+deb12u1_i386.deb ee0b812c5331b669966c7fbf5554af0de4f04ef5 199780 libpq5_15.12-0+deb12u1_i386.deb 7bb6d176a49d57aaccf1b3e864369b2eedec0129 15367788 postgresql-15-dbgsym_15.12-0+deb12u1_i386.deb 4b21fb2274b337522c7dc1b526b6395b9ff31e77 16964 postgresql-15_15.12-0+deb12u1_i386-buildd.buildinfo a5d185fc46983b9005595d13a1570a4e183577d5 17069264 postgresql-15_15.12-0+deb12u1_i386.deb 56725332f4f24f8cde44eda5acfd61a7daa94ddd 2257924 postgresql-client-15-dbgsym_15.12-0+deb12u1_i386.deb b092156cd9976f30d617461e488d91961ded2d71 1743232 postgresql-client-15_15.12-0+deb12u1_i386.deb 92b1ab5943f4ba7bd332f40927d133a203bb8926 173976 postgresql-plperl-15-dbgsym_15.12-0+deb12u1_i386.deb ba37dcf5111859eab8caa688a678766ee06c2fdd 95388 postgresql-plperl-15_15.12-0+deb12u1_i386.deb d390d314432f5f7e5337e547e39e05d6736364e2 164008 postgresql-plpython3-15-dbgsym_15.12-0+deb12u1_i386.deb 343ce23cc5cd975b663654a71b17b9382b8c49d6 115708 postgresql-plpython3-15_15.12-0+deb12u1_i386.deb 9ebf9a948f77554eb39bf6a7bf00f85dd0e62ea1 74144 postgresql-pltcl-15-dbgsym_15.12-0+deb12u1_i386.deb 0f5858c1628898a82e6ecaee5b8228967ed45616 45444 postgresql-pltcl-15_15.12-0+deb12u1_i386.deb 27a4c00c8c2040728d6c4a2141b0bb86fed856a7 1163136 postgresql-server-dev-15_15.12-0+deb12u1_i386.deb Checksums-Sha256: 25f75b76bdaeb18266b0560c1c0580e322e8d088b0d7689bd396e4c9acb73da9 14404 libecpg-compat3-dbgsym_15.12-0+deb12u1_i386.deb bcea3a2dff78a553d4a09790fcbc30e51d11b6b34bbe06e2a51781f4daf0336e 19268 libecpg-compat3_15.12-0+deb12u1_i386.deb f84e92b4f0d4a26cd0ef38c37e3883cea40afa0f5b4936fd302da5fe0bb07c0b 270788 libecpg-dev-dbgsym_15.12-0+deb12u1_i386.deb f09009a946562ff84e42579b56df4c7d0aaa29912e58fb1ed9e570642bc181cf 307364 libecpg-dev_15.12-0+deb12u1_i386.deb 414ebb13d0817b07f55316040a92507dc5eebeb7da7ad4b72526c612d52f2de2 102324 libecpg6-dbgsym_15.12-0+deb12u1_i386.deb 40c5023c2afa6536fa0041f21341b3c7b0d4a85f4a67b238fbf9722059642ddc 66876 libecpg6_15.12-0+deb12u1_i386.deb 50f7f648dbedbb6d6aface0bff3e3522854ca26406d44e9a0124aa856bca538a 80756 libpgtypes3-dbgsym_15.12-0+deb12u1_i386.deb 147434917dce3a50f5f51b64d8d73887623287af1e4ac95c74d16d62276b7613 48676 libpgtypes3_15.12-0+deb12u1_i386.deb a8745412289d444b91b6ed4037c658e3b9b422d8dc8cb9e4f1aa9081f8762e16 156620 libpq-dev_15.12-0+deb12u1_i386.deb 546e2327289ef2f0e07b18ffb48ec534bf9594ce13809efd4521c1519405a35a 242264 libpq5-dbgsym_15.12-0+deb12u1_i386.deb f616130bc73de5810f1482e2add9703270f6b356ec182d60530bc53e4e32b38c 199780 libpq5_15.12-0+deb12u1_i386.deb 337c61d7a40789711437348174acf8f2d28073edf34665c75b6c251c180a78c9 15367788 postgresql-15-dbgsym_15.12-0+deb12u1_i386.deb 5ba08d4675ed8a37214c7f5d9999dd63c8c9daf006d5d5f934e5ddaa6f7718bd 16964 postgresql-15_15.12-0+deb12u1_i386-buildd.buildinfo fa9c82629ec03b7dee839b3b91f4b3446158f23b971ca8c9ffcf1905a1f330d6 17069264 postgresql-15_15.12-0+deb12u1_i386.deb 05167117882cb5b036ef9d3ee592ff8d83d894c4fe7083670af8dcf5f9704170 2257924 postgresql-client-15-dbgsym_15.12-0+deb12u1_i386.deb 108778b62ffab6ac06ff44bbb01dfcaded7530742148077dbc7ec10bd0529d44 1743232 postgresql-client-15_15.12-0+deb12u1_i386.deb 508c9fec65344be8b9cf80af08f12480e5ab3b8e873b512d7625d94b5ff548ea 173976 postgresql-plperl-15-dbgsym_15.12-0+deb12u1_i386.deb fba2f3119dadae8532aea2a28063cfbfeec9b610ea85e5198c0f12580482f408 95388 postgresql-plperl-15_15.12-0+deb12u1_i386.deb caa412f517c49aab0b6b02ef79dee07e6b0e4290c3950166d514c8f48e533518 164008 postgresql-plpython3-15-dbgsym_15.12-0+deb12u1_i386.deb 11020b5271bb0e61e098a1c10f5648e8981b53aa8776e9572d127f25e1503833 115708 postgresql-plpython3-15_15.12-0+deb12u1_i386.deb 6d099c72609ffcf02e4a1fdd1917f1c8febea866225c6f0eb7071b460462fc5f 74144 postgresql-pltcl-15-dbgsym_15.12-0+deb12u1_i386.deb 2bdd95e7db4f56798ab20d1905e9aaad8971f658461d733b12f094986c525fa4 45444 postgresql-pltcl-15_15.12-0+deb12u1_i386.deb 0423ac83813594ac9b7cd237998665c2e14cfcd6a9dc32db0ffb78c4fc655d42 1163136 postgresql-server-dev-15_15.12-0+deb12u1_i386.deb Files: 3d75024953dda53b00172b0d0e817416 14404 debug optional libecpg-compat3-dbgsym_15.12-0+deb12u1_i386.deb 1b50e660f028ac811d08f3a4119670e5 19268 libs optional libecpg-compat3_15.12-0+deb12u1_i386.deb 0d9273ec8ecd1b2fc4438d0985642a3f 270788 debug optional libecpg-dev-dbgsym_15.12-0+deb12u1_i386.deb 152891d09fc43c085b509074b0100cce 307364 libdevel optional libecpg-dev_15.12-0+deb12u1_i386.deb a24d20dce60cfe0a49c379015dd3ca06 102324 debug optional libecpg6-dbgsym_15.12-0+deb12u1_i386.deb 657d718deb30249130a0a301254b5d72 66876 libs optional libecpg6_15.12-0+deb12u1_i386.deb 24dcd2db9ae57147dc336fe3cae8995d 80756 debug optional libpgtypes3-dbgsym_15.12-0+deb12u1_i386.deb 6e1b5be673ff9bb9a1325a9d1213f3e7 48676 libs optional libpgtypes3_15.12-0+deb12u1_i386.deb 79d1c2f80d97fefa1b5edcce1d9f84fc 156620 libdevel optional libpq-dev_15.12-0+deb12u1_i386.deb 7c5d2490006cf87518d8dfac66be7c82 242264 debug optional libpq5-dbgsym_15.12-0+deb12u1_i386.deb 0b7c6bf9d684aa578f8eaf01a144675a 199780 libs optional libpq5_15.12-0+deb12u1_i386.deb 9ff8b3b9cfdbae33bb4627c4a8309d1b 15367788 debug optional postgresql-15-dbgsym_15.12-0+deb12u1_i386.deb 95e66ad52be30fb51d7d87c3c8cda86f 16964 database optional postgresql-15_15.12-0+deb12u1_i386-buildd.buildinfo c848b719a04c66c689b3496a9d04d66f 17069264 database optional postgresql-15_15.12-0+deb12u1_i386.deb e906c2d7cef0754fd82a59e9c37d68ad 2257924 debug optional postgresql-client-15-dbgsym_15.12-0+deb12u1_i386.deb 9385786a1c17397d161c5eec955585c8 1743232 database optional postgresql-client-15_15.12-0+deb12u1_i386.deb 6ff9ef8c8c7c4426d3d432c932114574 173976 debug optional postgresql-plperl-15-dbgsym_15.12-0+deb12u1_i386.deb ae4985966d6808b3ef79b1662cd2557c 95388 database optional postgresql-plperl-15_15.12-0+deb12u1_i386.deb 8a4d2cd4f1a46e4f25b5a8893cf2671e 164008 debug optional postgresql-plpython3-15-dbgsym_15.12-0+deb12u1_i386.deb a42dbf7de193f4d0ae868790eb9c392b 115708 database optional postgresql-plpython3-15_15.12-0+deb12u1_i386.deb d9fca3c609321f3dc1a07e8763fee8db 74144 debug optional postgresql-pltcl-15-dbgsym_15.12-0+deb12u1_i386.deb 7b59c38b3390abd4129b3d3744fce4e7 45444 database optional postgresql-pltcl-15_15.12-0+deb12u1_i386.deb 1b25ebebf14086baa659d873b06e2aa1 1163136 libdevel optional postgresql-server-dev-15_15.12-0+deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEyTfXx8sBpQ0Lh3cUU9a0/LcaTpMFAmfDLGMACgkQU9a0/Lca TpMc+A//ZJAvUGaMqafHbIDna7OFE5t2iIUXckZlvBZ6nOTyAW1n2yeRA5lzVM52 cXWd/F3dO8sVXR/G39ASWFsIrxxMa9Y+BNv+4EqueFdyY3y12shTeQaglqj51eri V9+u3W243fjDkHtMh2PQ8K1Mt+Kt/NMEUBj+BLnbeHAyB19WePwf4X3arP7zMh36 8ZczcX0sFoyqDrxOAMQH7HDTMCtyo8IKNDSQNMwt8E6ou6qVgmjKOwADIAw0noKZ ObJYEuZiGaUQqMWrUm9Xet9CakLZDyko/HRqbJpHQZ7Mw3gy0/U9JW/rdA2TAZ8Q HT4SL+8SEU2KSuuyee5tiRdFTyq6Fs3zxihsdFFTXq7XrwV2HQH0NDTw9u85MudH 1Cyy0fUsqvrV7bIs+a/ii/fMFMs9Z+Qm0c8ZkYWjCaOU8ldSE4lk7Ec/SGrzh7nH hqgw16zT5vimcPN+ncaOtKUaIyI2SXPspInsOvmuT4quc1BHSUf/1bSlkhUdPMc1 EO7TLnP9xX1qMzGQMP/Xqx4id409CbE0MgaypbFWWBOUW9enFUCViaY6wd42Y+YW UpMR9m5UdUxWIZJM2ripax55AMrcjnk3tvq3HoPzhgBC3OQsQFgwpaYP6gLdc/ub RQtIFz8E24/uyzO1Qw4e+79hrrcwP9ukGd+RHJub3G/IoXBKT1E= =iOIU -----END PGP SIGNATURE-----