-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 18 Feb 2025 11:59:37 +0100 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: amd64 Version: 15.12-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.12-0+deb12u1) bookworm; urgency=medium . * New upstream version 15.12. . + Improve behavior of libpq's quoting functions (Andres Freund, Tom Lane) . The changes made for CVE-2025-1094 had one serious oversight: PQescapeLiteral() and PQescapeIdentifier() failed to honor their string length parameter, instead always reading to the input string's trailing null. This resulted in including unwanted text in the output, if the caller intended to truncate the string via the length parameter. With very bad luck it could cause a crash due to reading off the end of memory. . In addition, modify all these quoting functions so that when invalid encoding is detected, an invalid sequence is substituted for just the first byte of the presumed character, not all of it. This reduces the risk of problems if a calling application performs additional processing on the quoted string. Checksums-Sha1: bc78669268cfad0f97c86e3a3271f00511ab38e6 16640 libecpg-compat3-dbgsym_15.12-0+deb12u1_amd64.deb cdb8ecd28fd42b72f80cbdb96dcd846dd934cf21 18800 libecpg-compat3_15.12-0+deb12u1_amd64.deb f76be8caa6ad5ebd45406444424cd509a7ba99b9 281936 libecpg-dev-dbgsym_15.12-0+deb12u1_amd64.deb a46ea8332f5420f554aa01f62466651919bb4ea9 297124 libecpg-dev_15.12-0+deb12u1_amd64.deb d7caacc98680e0d1ac97580962fc3668f89b79b1 113708 libecpg6-dbgsym_15.12-0+deb12u1_amd64.deb d0ddc6b02b4426deb56b03e5c0f5f7589a39e684 63028 libecpg6_15.12-0+deb12u1_amd64.deb 2bbcdd98d1cd9a4d27bb2281e17a6af81e0b1cbf 88256 libpgtypes3-dbgsym_15.12-0+deb12u1_amd64.deb 3c05a2becd8927af31b2ece6455ab22cd65d1ab2 46564 libpgtypes3_15.12-0+deb12u1_amd64.deb 4765ee3660bc63382333dd08c5bc4b3c26b63bc3 146256 libpq-dev_15.12-0+deb12u1_amd64.deb 4b9f715e418b416e07324e69c13dec02e59845d2 277704 libpq5-dbgsym_15.12-0+deb12u1_amd64.deb 590abdbb2bf0051e1969c77653ac372400f775da 192380 libpq5_15.12-0+deb12u1_amd64.deb b511924330dbfb5d140dd89ed123ac2efe1b2a93 16967144 postgresql-15-dbgsym_15.12-0+deb12u1_amd64.deb 4e0279e7eb2e9229053f395ef28a1e2b91c40a9c 17068 postgresql-15_15.12-0+deb12u1_amd64-buildd.buildinfo 4a7a11423ae4d81ae5a6879cf38d417d8729a7c6 16830176 postgresql-15_15.12-0+deb12u1_amd64.deb 3e6cbb2d8e66a773e32d80b01472de3b623420ed 2620680 postgresql-client-15-dbgsym_15.12-0+deb12u1_amd64.deb 72504b40a56a8b413a3cdb67e30c05c35141c3b4 1723828 postgresql-client-15_15.12-0+deb12u1_amd64.deb 77ef7e8eec9f6f04fab3ea4b3e264b03598c3e3c 186812 postgresql-plperl-15-dbgsym_15.12-0+deb12u1_amd64.deb f32f346754dd6f21ffb9e924267497bed75527ed 92088 postgresql-plperl-15_15.12-0+deb12u1_amd64.deb 8baa04b6a15ee27a52249f04f39271882575408c 178804 postgresql-plpython3-15-dbgsym_15.12-0+deb12u1_amd64.deb 044fbf318d2ca8cdc1747db787cd7e7db7accff4 112900 postgresql-plpython3-15_15.12-0+deb12u1_amd64.deb d3259ad8749d583cc5997782bd327d48a19c4b92 79640 postgresql-pltcl-15-dbgsym_15.12-0+deb12u1_amd64.deb ad0cb90c20b24674d6c2c1bb61fb2341f69cc18f 43872 postgresql-pltcl-15_15.12-0+deb12u1_amd64.deb 16b1b8d9c89847496c88f664e6273e95ca8a2663 1149460 postgresql-server-dev-15_15.12-0+deb12u1_amd64.deb Checksums-Sha256: 64323dbcf1debb710a9663bde946c0d57b2b15eb5bd41729e9d93dca6ea01667 16640 libecpg-compat3-dbgsym_15.12-0+deb12u1_amd64.deb 4cdaadbacaadf5b8569b0d0ac1d5e64afdb988245aee4a324e9bf0e8d0f5cc40 18800 libecpg-compat3_15.12-0+deb12u1_amd64.deb be8f189457ff0472015bb9a2fc3b3d0e1b8f5fde4a7909e92af5cee92bc8377c 281936 libecpg-dev-dbgsym_15.12-0+deb12u1_amd64.deb f412c07d37d371bf044b850bfd6f880e49eb53c38131b8824133af97816ce786 297124 libecpg-dev_15.12-0+deb12u1_amd64.deb f1a78c0556eb94c43bd9b2d5596ee425f94727d2c7509e4b0c3eef38332969fe 113708 libecpg6-dbgsym_15.12-0+deb12u1_amd64.deb fd363279b59b1bf3ab1819f5898bb63ded7031c5e2ce618cb24a11ad1c83f0e0 63028 libecpg6_15.12-0+deb12u1_amd64.deb 258cf665da1ab85734212ea49aa989594679e70199e3e7a3a9a95d1d5eaa81fa 88256 libpgtypes3-dbgsym_15.12-0+deb12u1_amd64.deb 039b7b7d1fe8c94a22ca529260fd633d1bf3abd2140c24c036c8248fe82643cc 46564 libpgtypes3_15.12-0+deb12u1_amd64.deb 78d9da884292bfcab2b6f851fe2115035c88523ff9ab432bd5dd9e9432defeaa 146256 libpq-dev_15.12-0+deb12u1_amd64.deb 9e86436abe4e365a2d1495319dc37d27fac09b323c428c9d139619ff3c3d6bc5 277704 libpq5-dbgsym_15.12-0+deb12u1_amd64.deb bd63baa347f5664e2a3737eb1f15b123664b490abdd7da61f6e16fca36099271 192380 libpq5_15.12-0+deb12u1_amd64.deb 96dd303f9ccbeace9da757bc06060be2af52e8c02c988998227e9af5355f973b 16967144 postgresql-15-dbgsym_15.12-0+deb12u1_amd64.deb b98e68d01e01760ff403712820935a69d6d7028b7435b19a7ba4ae09bc031137 17068 postgresql-15_15.12-0+deb12u1_amd64-buildd.buildinfo 3eeb165dfd80d877f0cd1561af5b2600b4c9ab3a33d519ae613b4ec874c91c94 16830176 postgresql-15_15.12-0+deb12u1_amd64.deb fa87e495c7b032bdf41a27a7c1a2f17d3d098efc45be9616c09877a5e1e0bed1 2620680 postgresql-client-15-dbgsym_15.12-0+deb12u1_amd64.deb ee1bcd7210a763bc5b0bc323e4ad8bc75f17c345a1e2267b41a4a876ac0e9afc 1723828 postgresql-client-15_15.12-0+deb12u1_amd64.deb 899ac060433b20992f1a0c7f731336f18e0dded961515a3239876d50a0f770df 186812 postgresql-plperl-15-dbgsym_15.12-0+deb12u1_amd64.deb fec894daad816b3df0280d5532aef2d6a1c5d209166df2c2ed46bb7e09997875 92088 postgresql-plperl-15_15.12-0+deb12u1_amd64.deb d761e06d5c4343f55ea347247d50f55149fa2af8e4696dd871554d1bae158789 178804 postgresql-plpython3-15-dbgsym_15.12-0+deb12u1_amd64.deb aadadb3a8b5d3d3014869e7f84d7011eb0b857fe5bf2a2ee45c5e83bf1af80de 112900 postgresql-plpython3-15_15.12-0+deb12u1_amd64.deb 43b08434a3990e62d3869a1aa9d3e937eae0bb63595b780c70d805b3e65df64f 79640 postgresql-pltcl-15-dbgsym_15.12-0+deb12u1_amd64.deb 2a573841c180d4d28e969e9cad762c16539eff3c9afe17ff7363f5228febde82 43872 postgresql-pltcl-15_15.12-0+deb12u1_amd64.deb 33f5221c781b5440de54d2bac7c8cf159fcee6a81c8a94978165e1664b59122e 1149460 postgresql-server-dev-15_15.12-0+deb12u1_amd64.deb Files: 251d8fbeb181c6c4f861bce54e0cea0e 16640 debug optional libecpg-compat3-dbgsym_15.12-0+deb12u1_amd64.deb 5aeb55e6ff7bb420a6406d274052755f 18800 libs optional libecpg-compat3_15.12-0+deb12u1_amd64.deb 0766026f6221afdbe0fcc5f3d01715c4 281936 debug optional libecpg-dev-dbgsym_15.12-0+deb12u1_amd64.deb 53c62cc91062159c90aad6e21a0350c8 297124 libdevel optional libecpg-dev_15.12-0+deb12u1_amd64.deb e3a42a1d4126006fcc893584fd991b63 113708 debug optional libecpg6-dbgsym_15.12-0+deb12u1_amd64.deb 9fdebfc74a171df7dd662898a7627812 63028 libs optional libecpg6_15.12-0+deb12u1_amd64.deb 1653392beaf0ee26aba59661681650c2 88256 debug optional libpgtypes3-dbgsym_15.12-0+deb12u1_amd64.deb 14bbfa7b14dc7ffaddec608e0698b094 46564 libs optional libpgtypes3_15.12-0+deb12u1_amd64.deb b6a95ee641048c398532ec589924a0e6 146256 libdevel optional libpq-dev_15.12-0+deb12u1_amd64.deb 90b457cd3aca0f80e45ee9693b614b41 277704 debug optional libpq5-dbgsym_15.12-0+deb12u1_amd64.deb 479d02beb837694241b362cbcd76134c 192380 libs optional libpq5_15.12-0+deb12u1_amd64.deb 2fd959186aeafb29c5f59e7a11eae075 16967144 debug optional postgresql-15-dbgsym_15.12-0+deb12u1_amd64.deb 036c92807459ecd1def614a5f5c59f89 17068 database optional postgresql-15_15.12-0+deb12u1_amd64-buildd.buildinfo 1b249031429a5a92b154bf48eef6640e 16830176 database optional postgresql-15_15.12-0+deb12u1_amd64.deb 94f0857faa3a8d544ecfa71aa2402768 2620680 debug optional postgresql-client-15-dbgsym_15.12-0+deb12u1_amd64.deb 5667d7ad74446e929241692a75fec78d 1723828 database optional postgresql-client-15_15.12-0+deb12u1_amd64.deb 44796b693dadb27248e72e45281dec01 186812 debug optional postgresql-plperl-15-dbgsym_15.12-0+deb12u1_amd64.deb 7205bacb53f87fb13f30d0ca687c344a 92088 database optional postgresql-plperl-15_15.12-0+deb12u1_amd64.deb fefbc395f9f4aae0884225e3fe29e83e 178804 debug optional postgresql-plpython3-15-dbgsym_15.12-0+deb12u1_amd64.deb 12d2aa99c3d8ccc2a2cd0bdfce71c0a1 112900 database optional postgresql-plpython3-15_15.12-0+deb12u1_amd64.deb 3df4580cc2d497e026db573121f30e6d 79640 debug optional postgresql-pltcl-15-dbgsym_15.12-0+deb12u1_amd64.deb cd47c46712f9aa9a76d9f35d3673160f 43872 database optional postgresql-pltcl-15_15.12-0+deb12u1_amd64.deb b86582e43073665958fcc0a64ac5d835 1149460 libdevel optional postgresql-server-dev-15_15.12-0+deb12u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEgdRoRGwEM09wlaMzOni7ZmUpKEcFAmfDKzIACgkQOni7ZmUp KEf6dBAAjJ74/sz+nORbPSd90eNz3HKXIe+FVxHDEjgTuPyRUa6pMRoSCOm6r38L 2xo+egd2GP++mx9JVuectjjlUWYTrA1R5v8xlNjw2dTFXRSKbbKbfcV2kljk6vh7 fY3WnXO+lrk7clrNTXRbaaHaFRVz0TVExkJWqnj6WrJzYRkwAgERoqM60ZIR41ww UeEfg6B7VNL+mdep6gCu7Kkzp/IzVOsoHurR6BSmprHx2dllxPcj0fl6VP7e//Ek fprOxdV/ZWdfJ9hoPPr8Ty4np8FfpwfcEn+PJJ6SOF0kN0S+0UWVnHoFQV9jd7Zy ObHAdTFQA3oKwEs4utQNHWA/rIucnuoNmcsRE5+n9AvktbeD7JDzsw46vy8n/BM6 h/FkuMhu6l09XgL1OLvhYgnz4fHNmz0XKgKpnMFYDexTUOrd9iOw9kyuEvAB7pmo Ga5V3zRNQ5ibW/Nz7tAwisfhoYpn9fznX4sqocBT3M8OdpHaZ1iK1VFm29V2vvUT 2jGfbnA2/Csd/K6XNXutyouq6b6MMS3fD7OhrYiY5/P7a/6Anl/i8uwDJiBZxpjs rTrZofsY+QT33CGlT6QIroykAN2f0E8stzPoxFBg3Qp7mxV98pK+Sk0rQ0zmA2x1 fM+gZKel+TsGKMARNPluLBVjhKLVR6e7TLMj5J6Vu17sPZsE22Y= =u0W+ -----END PGP SIGNATURE-----