-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 18 Feb 2025 11:59:37 +0100 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: s390x Version: 15.12-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: s390x Build Daemon (zani) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.12-0+deb12u1) bookworm; urgency=medium . * New upstream version 15.12. . + Improve behavior of libpq's quoting functions (Andres Freund, Tom Lane) . The changes made for CVE-2025-1094 had one serious oversight: PQescapeLiteral() and PQescapeIdentifier() failed to honor their string length parameter, instead always reading to the input string's trailing null. This resulted in including unwanted text in the output, if the caller intended to truncate the string via the length parameter. With very bad luck it could cause a crash due to reading off the end of memory. . In addition, modify all these quoting functions so that when invalid encoding is detected, an invalid sequence is substituted for just the first byte of the presumed character, not all of it. This reduces the risk of problems if a calling application performs additional processing on the quoted string. Checksums-Sha1: efa140266cac5c3ec00b9be8f6ba0a3127cca7b1 16492 libecpg-compat3-dbgsym_15.12-0+deb12u1_s390x.deb 4a2d0129782f10752b4700e379fcb0946e813b9c 18552 libecpg-compat3_15.12-0+deb12u1_s390x.deb ebffb4cc65bc7527b5c479f2abbca574674cc362 214680 libecpg-dev-dbgsym_15.12-0+deb12u1_s390x.deb 51086ea90bf14b8069bdfe72e0bca3217b44c751 281300 libecpg-dev_15.12-0+deb12u1_s390x.deb d92838911a1f855077cc45eceef838145f906c22 112848 libecpg6-dbgsym_15.12-0+deb12u1_s390x.deb 0da9dc324cdb9edd27cc1574ce32ab4b7a763197 60384 libecpg6_15.12-0+deb12u1_s390x.deb 57e34038c3f26f43150ed69882612a9cb6b44b49 88372 libpgtypes3-dbgsym_15.12-0+deb12u1_s390x.deb ec88b322ebafc7ba050d8baf2f3efc50d4be067a 45412 libpgtypes3_15.12-0+deb12u1_s390x.deb 89aa2dcb20f775e6230d61cb5ec25d53198ca8ca 139512 libpq-dev_15.12-0+deb12u1_s390x.deb cc439aa361776215c6a9bab096bc3f6098f8b796 273176 libpq5-dbgsym_15.12-0+deb12u1_s390x.deb 1b12e1db1343f82d85aeeeddac907e880a628c57 181504 libpq5_15.12-0+deb12u1_s390x.deb 5baa1e2dbbcc90d927cdef12ec85604cb57a8e17 15456888 postgresql-15-dbgsym_15.12-0+deb12u1_s390x.deb db7a7b044cc5a593c41a90cc327ed6b6512706cc 16000 postgresql-15_15.12-0+deb12u1_s390x-buildd.buildinfo 7ce5f01a5948ec52288401d84d5c97ce995f25a0 5630920 postgresql-15_15.12-0+deb12u1_s390x.deb 3cbfeddc3b6f90fc4cd60e371d77f576130595dd 2439456 postgresql-client-15-dbgsym_15.12-0+deb12u1_s390x.deb 4724d50c7f2d7f829c81738475b0bcb2815d3bf9 1662788 postgresql-client-15_15.12-0+deb12u1_s390x.deb ec1571da3f158d54b84c4a1997d84bfbfc4d2f19 180508 postgresql-plperl-15-dbgsym_15.12-0+deb12u1_s390x.deb 0006454d7f8f4907104d2c2ca6ef419da2d4d833 66912 postgresql-plperl-15_15.12-0+deb12u1_s390x.deb 2bb6eeb2183db0808ee3c2335509488250728780 169980 postgresql-plpython3-15-dbgsym_15.12-0+deb12u1_s390x.deb bf9bc843968febb855546cf346fb6b66fb4f1377 89852 postgresql-plpython3-15_15.12-0+deb12u1_s390x.deb 2622cf678c7f0077a5611c8ca0d607e4f459dbd9 77740 postgresql-pltcl-15-dbgsym_15.12-0+deb12u1_s390x.deb 68089ff86589d0811c9468e9c8c87b23c09fa919 42544 postgresql-pltcl-15_15.12-0+deb12u1_s390x.deb 0aad72d0430569afa48f61a65a5d5f65c28daf74 1140620 postgresql-server-dev-15_15.12-0+deb12u1_s390x.deb Checksums-Sha256: 271658889f2f74e5b712792d108c6463d6c525ef1e8ea83e51474a34fb028333 16492 libecpg-compat3-dbgsym_15.12-0+deb12u1_s390x.deb acb0a22084fffe6c3e9bbfa19b9837d8c0ddc752ae848d1cd90e2637039019c2 18552 libecpg-compat3_15.12-0+deb12u1_s390x.deb d687f6d63de7c4c2fb6be6f4d023c137d816af5b7a28f1765c3747c58f577b38 214680 libecpg-dev-dbgsym_15.12-0+deb12u1_s390x.deb 81d32706c3ddabeb15d60b223e650742067aa4d90ec247563745dfcd539a053e 281300 libecpg-dev_15.12-0+deb12u1_s390x.deb 8b0126beba5b4405e76db68ab4380ba3a1629dae1b8a1fd7a7fe5d8f5dc3e3f1 112848 libecpg6-dbgsym_15.12-0+deb12u1_s390x.deb 04c703655c3d4ed70c659a4513d6035b21a2e83da6acdef27d22880ae3cd6e90 60384 libecpg6_15.12-0+deb12u1_s390x.deb 25505a2b9aaa069a81c62db76e9b38546b8e334cec8fc0ceb268e43bb3e64f26 88372 libpgtypes3-dbgsym_15.12-0+deb12u1_s390x.deb a507456f121c21ac3ee2bcb78e464fe104237eba19f2907a791502444e3a15a9 45412 libpgtypes3_15.12-0+deb12u1_s390x.deb cc15d929ea0226b76c75c9c1ef289b07b1d5712a45233e67388d12c6e57ebbf3 139512 libpq-dev_15.12-0+deb12u1_s390x.deb 9a603a5246fa4e91a3c639359bd3d22c22f7ff0dc27108bbe108e202f8479119 273176 libpq5-dbgsym_15.12-0+deb12u1_s390x.deb 800fa58d5e1dbb04057874dcbde7df1decee464c8e22aef162c77e5fa6a6ed1f 181504 libpq5_15.12-0+deb12u1_s390x.deb f082633dca2777fb06e9bcdbd2f3ca7f1459f249188ef18a5d524f529fcd1b1d 15456888 postgresql-15-dbgsym_15.12-0+deb12u1_s390x.deb bc0b11d9f6abd746c35a7d6056c499702740698263597c099499bbcaee6e50f8 16000 postgresql-15_15.12-0+deb12u1_s390x-buildd.buildinfo e7293cb4462b704bb3b985ad668d77e18df2db58323d017309e824a6a8e64291 5630920 postgresql-15_15.12-0+deb12u1_s390x.deb 917ce4d9927aa6b8725de6567a7626fbb8fa2dfd6297646b405e960d19a7813a 2439456 postgresql-client-15-dbgsym_15.12-0+deb12u1_s390x.deb 3a3e8511f847c5f896b80678dfb374492cfcbc8e929cd7db1b06f13e7a8992b2 1662788 postgresql-client-15_15.12-0+deb12u1_s390x.deb 3fb241ceff57ba569f0a9032cd8591a0f461ebd018567b8912553133c0064ae5 180508 postgresql-plperl-15-dbgsym_15.12-0+deb12u1_s390x.deb 400198c4da676a0c0deb235494cb99a06490763f756a42580aacbb45d56de71f 66912 postgresql-plperl-15_15.12-0+deb12u1_s390x.deb 17cc0c6a0b23ba88191dd0c6d961acb15707480bd17495654bc6f334ac8110d7 169980 postgresql-plpython3-15-dbgsym_15.12-0+deb12u1_s390x.deb 6273c8054219056fd7a70b536d0bc331b2700721f7db64085c00c77db67ae2d7 89852 postgresql-plpython3-15_15.12-0+deb12u1_s390x.deb 18512705b1e06497fd9d3f1f930e56b08469c59ac296899014d5ff7a202a078a 77740 postgresql-pltcl-15-dbgsym_15.12-0+deb12u1_s390x.deb 6a9918d04b78bd61700cdd49a78c7c318c5a58d8257286d69741ea0b17b076bd 42544 postgresql-pltcl-15_15.12-0+deb12u1_s390x.deb 402d67e5d1816183adcff2a36bfc4d2cae5f6ae9bab4e34a977c28adcce5c228 1140620 postgresql-server-dev-15_15.12-0+deb12u1_s390x.deb Files: 33413b2f322af1d5ab1041d4e35aa4a2 16492 debug optional libecpg-compat3-dbgsym_15.12-0+deb12u1_s390x.deb c71bd0ee4e4b6d00cd377a246d565eb0 18552 libs optional libecpg-compat3_15.12-0+deb12u1_s390x.deb c1b4a6d444093d6dcb1e62adaf9f3535 214680 debug optional libecpg-dev-dbgsym_15.12-0+deb12u1_s390x.deb 96956a7e6c98b0b25c68e8b5f910ec21 281300 libdevel optional libecpg-dev_15.12-0+deb12u1_s390x.deb c8951563cc24e297a1de10defed37d50 112848 debug optional libecpg6-dbgsym_15.12-0+deb12u1_s390x.deb b7848db2ba64633667143079c796a97e 60384 libs optional libecpg6_15.12-0+deb12u1_s390x.deb 535b04e6d716e01dc37df84d65af4bb0 88372 debug optional libpgtypes3-dbgsym_15.12-0+deb12u1_s390x.deb ed85ba3c81a2e0e889e32c9c4abfa85d 45412 libs optional libpgtypes3_15.12-0+deb12u1_s390x.deb ee6f7027e4aaff1b56ab41eb4594cdf6 139512 libdevel optional libpq-dev_15.12-0+deb12u1_s390x.deb 9352ca73696b7062b2b1691c3ab2f8f2 273176 debug optional libpq5-dbgsym_15.12-0+deb12u1_s390x.deb 14eac9d7886db1bfe4e22a02e565128a 181504 libs optional libpq5_15.12-0+deb12u1_s390x.deb 0bdf1b0abe0e2a19a476ddd62f72592d 15456888 debug optional postgresql-15-dbgsym_15.12-0+deb12u1_s390x.deb 17cbab5b8de29d6278b62c9670b4a98c 16000 database optional postgresql-15_15.12-0+deb12u1_s390x-buildd.buildinfo c0ae8d62a93c32ddf1e6dbfc75fc8af8 5630920 database optional postgresql-15_15.12-0+deb12u1_s390x.deb 1bdb9297177e7b1c54e23dcc9dcc0083 2439456 debug optional postgresql-client-15-dbgsym_15.12-0+deb12u1_s390x.deb f42994c231a0c0caed008efb7360429a 1662788 database optional postgresql-client-15_15.12-0+deb12u1_s390x.deb 9579ca510bfe9312ed2577a911646336 180508 debug optional postgresql-plperl-15-dbgsym_15.12-0+deb12u1_s390x.deb 87b953a426e637069d79d305c4a73559 66912 database optional postgresql-plperl-15_15.12-0+deb12u1_s390x.deb a88eb8f1f3e46c3ea99524b4fcbae44c 169980 debug optional postgresql-plpython3-15-dbgsym_15.12-0+deb12u1_s390x.deb 54bf16212fa3be13f4235462b49ab067 89852 database optional postgresql-plpython3-15_15.12-0+deb12u1_s390x.deb 7342ffe5816abd6e72b36c016ad08f2e 77740 debug optional postgresql-pltcl-15-dbgsym_15.12-0+deb12u1_s390x.deb f50cd0e76de3f67051bd0a9f743e7809 42544 database optional postgresql-pltcl-15_15.12-0+deb12u1_s390x.deb 9438e4babed130e1db7aad4a720ac22e 1140620 libdevel optional postgresql-server-dev-15_15.12-0+deb12u1_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEZTC4/c20pi1/n7UBUhVQ83ojQ7QFAmfDI3kACgkQUhVQ83oj Q7SzNw//bNkpbYmlNzs+giDyVcIuXPNcz8NncCw5wDcKyXphBbw9F+HX/szF6GGY IT0DBap9xTbCBW6qsOMrU8weiHooDJnL3TJVMKFFmcV43Qc4JUcbZElzub2HTXIL MTyWNOzH+B8+Pf5SrQW/aJZsTPbxLD1vat5vbtP8wAdsoz84vv6HrnchvTF7IhSV uc79KhKOEfb66vVYjOSmgDXe5yLInal7Spq+pKBCWk2rC7wy9L77GHB5VsLB6dQD Dk8DolooarVxgCm44MS5tVH/rvilG/xxNkyPEqWaBwGNvuH9IYOpVn5t4lw/qEmD r7pF768kefuGd+DjlMUOSAL2pmkVTbtP+BH31FwmXDhlIfMHhzsNJG4pGuFjY8mS FUQKCNKLl8ZIOrOtW4z9ouiu8JvjrqCpWSKIIHMhQdTOE2+GkQtfIhFHUNCKINWL Oh4FiZ9O1RjXIrpZaAeYtULtsnPXZ7oSaJt8akVDBsnDwpVCeUUjDzLVcYbD4GPj X27B7JEoRAgcs2Aq2fDtGu3JivJc8QhXBJ5x5p/gtjdB3Up8fRc46uHzs5RVQ4wz 5ySpFOKBmXHWXZ0/+1U27iU0hpSHwi5zqtZwxT0UfqofW3TB0lUz4XgIentJQIxf oEg0JO3R/czHJLBXEWXymygzAgZnBYsrI48hCMsO95AI7Sr/rm0= =5uiq -----END PGP SIGNATURE-----