-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 18 Feb 2025 11:59:37 +0100 Source: postgresql-15 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-15 postgresql-15-dbgsym postgresql-client-15 postgresql-client-15-dbgsym postgresql-plperl-15 postgresql-plperl-15-dbgsym postgresql-plpython3-15 postgresql-plpython3-15-dbgsym postgresql-pltcl-15 postgresql-pltcl-15-dbgsym postgresql-server-dev-15 Architecture: armel Version: 15.12-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 15 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-15 - The World's Most Advanced Open Source Relational Database postgresql-client-15 - front-end programs for PostgreSQL 15 postgresql-plperl-15 - PL/Perl procedural language for PostgreSQL 15 postgresql-plpython3-15 - PL/Python 3 procedural language for PostgreSQL 15 postgresql-pltcl-15 - PL/Tcl procedural language for PostgreSQL 15 postgresql-server-dev-15 - development files for PostgreSQL 15 server-side programming Changes: postgresql-15 (15.12-0+deb12u1) bookworm; urgency=medium . * New upstream version 15.12. . + Improve behavior of libpq's quoting functions (Andres Freund, Tom Lane) . The changes made for CVE-2025-1094 had one serious oversight: PQescapeLiteral() and PQescapeIdentifier() failed to honor their string length parameter, instead always reading to the input string's trailing null. This resulted in including unwanted text in the output, if the caller intended to truncate the string via the length parameter. With very bad luck it could cause a crash due to reading off the end of memory. . In addition, modify all these quoting functions so that when invalid encoding is detected, an invalid sequence is substituted for just the first byte of the presumed character, not all of it. This reduces the risk of problems if a calling application performs additional processing on the quoted string. Checksums-Sha1: 3619430c0046e11b773e00fe5c0db059454b2dba 16364 libecpg-compat3-dbgsym_15.12-0+deb12u1_armel.deb fb7702e753b4b5fb472e21a00e05a19eddd5a50d 17572 libecpg-compat3_15.12-0+deb12u1_armel.deb 026104e64207ca8441d92f5bae6cf1c86d510fee 232520 libecpg-dev-dbgsym_15.12-0+deb12u1_armel.deb 00f9cd03851472a7f105952a358cfc6e4bb12e92 274124 libecpg-dev_15.12-0+deb12u1_armel.deb 362c11466d5cbf1e14d298d97d2efa5a7ed22175 111208 libecpg6-dbgsym_15.12-0+deb12u1_armel.deb a1723170b1929175c892c448bcd74fd247f34fa2 56480 libecpg6_15.12-0+deb12u1_armel.deb fb4832d7f347a1324dc7d07e19337d8d01b34350 86572 libpgtypes3-dbgsym_15.12-0+deb12u1_armel.deb e2eddd9b5d023a5fa5e48bf37e91b508879463ef 43048 libpgtypes3_15.12-0+deb12u1_armel.deb 2c017ca860793354721cbd5c61742fa6a66d1a87 134852 libpq-dev_15.12-0+deb12u1_armel.deb e314c471f33b7476c2c819486894ebca0127d456 270332 libpq5-dbgsym_15.12-0+deb12u1_armel.deb 84c4e89bd7fe3d65b9d25a4ef3fc855c5212d1a2 173164 libpq5_15.12-0+deb12u1_armel.deb 1e731ea465f22e7498ef69a2ea493d70be629c62 16192756 postgresql-15-dbgsym_15.12-0+deb12u1_armel.deb 168e843e3e3d13ea50220cf3bf11abfbd3596cec 16919 postgresql-15_15.12-0+deb12u1_armel-buildd.buildinfo 4f0ae6857159c9d698533e82bbb1c4d4fa827172 16133080 postgresql-15_15.12-0+deb12u1_armel.deb 24ed81c0a1fd0f96dd83ac753cfbfce48abbaf4e 2405692 postgresql-client-15-dbgsym_15.12-0+deb12u1_armel.deb 63ea06d6c7f75a8efa9d339d6b1b53745706c724 1612340 postgresql-client-15_15.12-0+deb12u1_armel.deb df30ca981cc8756cd37e3766ce6d91da56fa3d7c 181792 postgresql-plperl-15-dbgsym_15.12-0+deb12u1_armel.deb 69e74c2fffa7989d02f729c3fb0f9bda0beb3463 89016 postgresql-plperl-15_15.12-0+deb12u1_armel.deb e4bdce53a53cb022b2bde0c1ed01fe1a2ea3c96b 172432 postgresql-plpython3-15-dbgsym_15.12-0+deb12u1_armel.deb 39c4ff5224346e8ceeaaef39e4669a685028a14d 107560 postgresql-plpython3-15_15.12-0+deb12u1_armel.deb 95ea6ef871b008c997cbfcf430dd56b47a100e74 78028 postgresql-pltcl-15-dbgsym_15.12-0+deb12u1_armel.deb 224d747fd313c49e5948a2e228c8074cde484479 41180 postgresql-pltcl-15_15.12-0+deb12u1_armel.deb 3857bae7c42beb6f0a864dc87c2940cdffdcdd64 1134476 postgresql-server-dev-15_15.12-0+deb12u1_armel.deb Checksums-Sha256: 550fdec506a39406fd0e30ac19ee56ee6d113b14244c89b298ebec1f967321f7 16364 libecpg-compat3-dbgsym_15.12-0+deb12u1_armel.deb 2d0993564059c98803fbdd638d4742427267eec2418efea66356bcc20ec43ad7 17572 libecpg-compat3_15.12-0+deb12u1_armel.deb 492b5f3ee4e4e8574c777473abf9622107d5468c03ace08eba57783796051c23 232520 libecpg-dev-dbgsym_15.12-0+deb12u1_armel.deb a8cec6ed22b2bff0bfdc9355853fcaa5f1d7a64ecfcc4bcd53866d751428dfc7 274124 libecpg-dev_15.12-0+deb12u1_armel.deb 218b7255b6cd1019c39fc4c286ad1cd7aaa98a37389d6301a04d01701475eef2 111208 libecpg6-dbgsym_15.12-0+deb12u1_armel.deb 51a3f260ba6f58e9c330d4bb830161b475e294f0aeb4ece8f9c76185c0a02cec 56480 libecpg6_15.12-0+deb12u1_armel.deb 3f8dc0371ba31f6b01929d39368078e51bcd8b9c45651edf0a6fea3b08ceb75e 86572 libpgtypes3-dbgsym_15.12-0+deb12u1_armel.deb c19b26561c3eeab1291e847ba6d8038662ec8a3c2a40d1535251eca4b03b7d82 43048 libpgtypes3_15.12-0+deb12u1_armel.deb 4dda4c0a96b7ddc826583c1992d8688f1663fa75bdc8cce307075d5fc5fdebaf 134852 libpq-dev_15.12-0+deb12u1_armel.deb 022aeee41207b8c43b4025685f9d58587e519f6cdba0d8444a9a3abd5857ba24 270332 libpq5-dbgsym_15.12-0+deb12u1_armel.deb b696bac34b131f33bfd226e3bab647c1c011d6c3a3b23e4a2e23f750f39dba30 173164 libpq5_15.12-0+deb12u1_armel.deb e406385268b65cc0c459e1f7243dd04516910ee6807951f14880a508981b69b3 16192756 postgresql-15-dbgsym_15.12-0+deb12u1_armel.deb c73b32a3bec4887780447cc1c83352bfb8ccbb8da6d107ee35a50df7fe8cf4b4 16919 postgresql-15_15.12-0+deb12u1_armel-buildd.buildinfo a3e74a18a595a21bd8e573b475f88d3265120299b30c39f9022dbf0b6a350d40 16133080 postgresql-15_15.12-0+deb12u1_armel.deb 15978a33a5f6b7e76112c6844b4de1ecbdac8aa21d758bea75d810423449e556 2405692 postgresql-client-15-dbgsym_15.12-0+deb12u1_armel.deb 1250a0b6fec42b0e9d23af69c4b204577cacb55473a6d1bc28f5b170a0a4d2e5 1612340 postgresql-client-15_15.12-0+deb12u1_armel.deb bb6f8f8d3f35143564590dcd706826a64b7fc29a0a727d15fd10c4e22287b2d5 181792 postgresql-plperl-15-dbgsym_15.12-0+deb12u1_armel.deb 24d278c8f3144191d84d4df505283f93b985b3f53bf03e011818825c65d71a21 89016 postgresql-plperl-15_15.12-0+deb12u1_armel.deb fdc3854f91b064c3df8fa155482544daee20681d87b675baa3964c1f8591fccd 172432 postgresql-plpython3-15-dbgsym_15.12-0+deb12u1_armel.deb 43d593a48494afedb5f966052cb5cc3d97a3a59cfebbaddf2914dcc138c3810d 107560 postgresql-plpython3-15_15.12-0+deb12u1_armel.deb 25d979114acdb78f2dbcabeeda57af63130f08c62d4ef1d48d69ff14ea31eea4 78028 postgresql-pltcl-15-dbgsym_15.12-0+deb12u1_armel.deb dc4b54043182e3879e588456d6e16237a1be86c4f143067cf3e607a015a3c246 41180 postgresql-pltcl-15_15.12-0+deb12u1_armel.deb a6e8b9f204dda0a950f9d506079ff4cc026edc79a8bccbaab264da94a44939a6 1134476 postgresql-server-dev-15_15.12-0+deb12u1_armel.deb Files: 254b992465d03f0d27f255262f1f6c9d 16364 debug optional libecpg-compat3-dbgsym_15.12-0+deb12u1_armel.deb ea8a82426a7e86554723b42d122ffe57 17572 libs optional libecpg-compat3_15.12-0+deb12u1_armel.deb a907b5727e6bbd9d99ac565d172d18b7 232520 debug optional libecpg-dev-dbgsym_15.12-0+deb12u1_armel.deb f373811b3adbbba72fe6d16a6a27cac2 274124 libdevel optional libecpg-dev_15.12-0+deb12u1_armel.deb 1364cbade1a676ba6fe5879401694b11 111208 debug optional libecpg6-dbgsym_15.12-0+deb12u1_armel.deb f4a9b0ccd7852e8f7fb6343455c51729 56480 libs optional libecpg6_15.12-0+deb12u1_armel.deb 9d945f58bd917e1a5e03f5589c3b73ef 86572 debug optional libpgtypes3-dbgsym_15.12-0+deb12u1_armel.deb a161e0b3bc8357a4a1d5431869119174 43048 libs optional libpgtypes3_15.12-0+deb12u1_armel.deb 42ebbb69e19ba016c469a9183121fd4a 134852 libdevel optional libpq-dev_15.12-0+deb12u1_armel.deb 45e7a452287dade7a9e0cbb4164543a7 270332 debug optional libpq5-dbgsym_15.12-0+deb12u1_armel.deb efd8c56311ed9d8f9a848527d8f247dc 173164 libs optional libpq5_15.12-0+deb12u1_armel.deb 604c820cdcd76c2e96b808a95e0de1dc 16192756 debug optional postgresql-15-dbgsym_15.12-0+deb12u1_armel.deb c048464e484c7f514c33ef77f501ce67 16919 database optional postgresql-15_15.12-0+deb12u1_armel-buildd.buildinfo 8595173ece2faebde79ca04a76b33b4c 16133080 database optional postgresql-15_15.12-0+deb12u1_armel.deb 1b520eb14405d2565983d889e1b0f137 2405692 debug optional postgresql-client-15-dbgsym_15.12-0+deb12u1_armel.deb 94e0408d3f5d7cacf84340d4eaa28ba8 1612340 database optional postgresql-client-15_15.12-0+deb12u1_armel.deb dd03b8192e64b9d3bff6837caaa303ce 181792 debug optional postgresql-plperl-15-dbgsym_15.12-0+deb12u1_armel.deb 3c3c83d2823441b34a619f73d0821e6a 89016 database optional postgresql-plperl-15_15.12-0+deb12u1_armel.deb 213dd2272570145a5fec2008a7a86c72 172432 debug optional postgresql-plpython3-15-dbgsym_15.12-0+deb12u1_armel.deb 6ccf997f9964e28d721a823825dee28d 107560 database optional postgresql-plpython3-15_15.12-0+deb12u1_armel.deb afdcd02f54447a0528cc2803f5750627 78028 debug optional postgresql-pltcl-15-dbgsym_15.12-0+deb12u1_armel.deb 7d84d119c1adee4f6cae21dee01c0b1d 41180 database optional postgresql-pltcl-15_15.12-0+deb12u1_armel.deb 8b8dc0d68b3bcc68200c9c417f207f7c 1134476 libdevel optional postgresql-server-dev-15_15.12-0+deb12u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKAzExpjGvTI78ZO8LARVyvnD3xkFAmfDRj8ACgkQLARVyvnD 3xng4xAAnoxiZmLbKQTK9799q3jMfmMg/t+lUKuElyCed22ChZC/DQlMgALbXw3G TliLIIN3H4PTVnmIf3KOY3PqTkRAHfPlX/YHDcghlkR2w5jzZh42jhMgdSXfSncD SlfeEoUJ774QVlmTNtwafycoQwv7GZ93g3/62ryR/zSaFfgUxpwWJ2bewbOpclms GMd+lSOzYg5yV1C8bA5bbNT6cE12BAamot3Sy2zhbhqr3qpt0RVBT4acZCvHgIOB R0UeNLNSq65YnSDYhr2Bs/3gY+dtRqgIPESBJzrWlxZklwYS7L/srVAlIc8B7TAH 8TjneDuDBy167oXQoGlRS5h6Msmfse4J6VCFYxvM2ZG5hNcbz9vsIPeoVNz5YuPP o7ngJiyvWGKNqwbGhQHYFeG3m7ZV1X1jXSvc8XOfeobSMVeBv3nD70SGL5O81gUO qoul9t4Cw2puzKsJ95VLKTKvDL4uofR2nSwnXvEhFNnJBoNx0Olv2k+T7WPkiZs8 mX5kLcFJ01WyVOBPQeQkMROkahZY3yABHKi8lDN25T9X6ZV4SsYDrv5VrduYMlvR NgrohRimU6g7aF20CMuP6ebXxQgWmaU5L0m2hgRhtxBswSslL2/z98qAXBgNqsjJ mgXnLIloScfTk9fl9M39+XiGbriQlE1G/Mx1nQKS/WiN8f9AIII= =YcvD -----END PGP SIGNATURE-----