postgresql-12 12.4-1 source package in Ubuntu

Changelog

postgresql-12 (12.4-1) unstable; urgency=medium

  * New upstream version.
    + Set a secure search_path in logical replication walsenders and apply
      workers (Noah Misch)

      A malicious user of either the publisher or subscriber database could
      potentially cause execution of arbitrary SQL code by the role running
      replication, which is often a superuser.  Some of the risks here are
      equivalent to those described in CVE-2018-1058, and are mitigated in
      this patch by ensuring that the replication sender and receiver execute
      with empty search_path settings. (As with CVE-2018-1058, that change
      might cause problems for under-qualified names used in replicated
      tables' DDL.)  Other risks are inherent in replicating objects that
      belong to untrusted roles; the most we can do is document that there is
      a hazard to consider. (CVE-2020-14349)

    + Make contrib modules' installation scripts more secure (Tom Lane)

      Attacks similar to those described in CVE-2018-1058 could be carried out
      against an extension installation script, if the attacker can create
      objects in either the extension's target schema or the schema of some
      prerequisite extension.  Since extensions often require superuser
      privilege to install, this can open a path to obtaining superuser
      privilege.  To mitigate this risk, be more careful about the search_path
      used to run an installation script; disable check_function_bodies within
      the script; and fix catalog-adjustment queries used in some contrib
      modules to ensure they are secure.  Also provide documentation to help
      third-party extension authors make their installation scripts secure.
      This is not a complete solution; extensions that depend on other
      extensions can still be at risk if installed carelessly.
      (CVE-2020-14350)

  * DH 13.

 -- Christoph Berg <email address hidden>  Tue, 11 Aug 2020 12:07:26 +0200

Upload details

Uploaded by:
Debian PostgreSQL Maintainers
Uploaded to:
Sid
Original maintainer:
Debian PostgreSQL Maintainers
Architectures:
any all
Section:
misc
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
postgresql-12_12.4-1.dsc 3.5 KiB 483e2c17b982240256bdd5812b3ed0669c5017e4be645423e0bbb409fb759d6f
postgresql-12_12.4.orig.tar.bz2 19.7 MiB bee93fbe2c32f59419cb162bcc0145c58da9a8644ee154a30b9a5ce47de606cc
postgresql-12_12.4-1.debian.tar.xz 23.2 KiB 525e1a0bc8f14cf5a437f1c8775be501c6490f8c55a45d9b87f905cfd6d5c87b

No changes file available.

Binary packages built by this source

libecpg-compat3: No summary available for libecpg-compat3 in ubuntu groovy.

No description available for libecpg-compat3 in ubuntu groovy.

libecpg-compat3-dbgsym: No summary available for libecpg-compat3-dbgsym in ubuntu groovy.

No description available for libecpg-compat3-dbgsym in ubuntu groovy.

libecpg-dev: No summary available for libecpg-dev in ubuntu groovy.

No description available for libecpg-dev in ubuntu groovy.

libecpg-dev-dbgsym: No summary available for libecpg-dev-dbgsym in ubuntu groovy.

No description available for libecpg-dev-dbgsym in ubuntu groovy.

libecpg6: No summary available for libecpg6 in ubuntu groovy.

No description available for libecpg6 in ubuntu groovy.

libecpg6-dbgsym: No summary available for libecpg6-dbgsym in ubuntu groovy.

No description available for libecpg6-dbgsym in ubuntu groovy.

libpgtypes3: No summary available for libpgtypes3 in ubuntu hirsute.

No description available for libpgtypes3 in ubuntu hirsute.

libpgtypes3-dbgsym: No summary available for libpgtypes3-dbgsym in ubuntu hirsute.

No description available for libpgtypes3-dbgsym in ubuntu hirsute.

libpq-dev: No summary available for libpq-dev in ubuntu groovy.

No description available for libpq-dev in ubuntu groovy.

libpq5: No summary available for libpq5 in ubuntu groovy.

No description available for libpq5 in ubuntu groovy.

libpq5-dbgsym: No summary available for libpq5-dbgsym in ubuntu hirsute.

No description available for libpq5-dbgsym in ubuntu hirsute.

postgresql-12: No summary available for postgresql-12 in ubuntu groovy.

No description available for postgresql-12 in ubuntu groovy.

postgresql-12-dbgsym: No summary available for postgresql-12-dbgsym in ubuntu groovy.

No description available for postgresql-12-dbgsym in ubuntu groovy.

postgresql-client-12: No summary available for postgresql-client-12 in ubuntu hirsute.

No description available for postgresql-client-12 in ubuntu hirsute.

postgresql-client-12-dbgsym: No summary available for postgresql-client-12-dbgsym in ubuntu groovy.

No description available for postgresql-client-12-dbgsym in ubuntu groovy.

postgresql-doc-12: No summary available for postgresql-doc-12 in ubuntu groovy.

No description available for postgresql-doc-12 in ubuntu groovy.

postgresql-plperl-12: No summary available for postgresql-plperl-12 in ubuntu groovy.

No description available for postgresql-plperl-12 in ubuntu groovy.

postgresql-plperl-12-dbgsym: No summary available for postgresql-plperl-12-dbgsym in ubuntu groovy.

No description available for postgresql-plperl-12-dbgsym in ubuntu groovy.

postgresql-plpython3-12: No summary available for postgresql-plpython3-12 in ubuntu groovy.

No description available for postgresql-plpython3-12 in ubuntu groovy.

postgresql-plpython3-12-dbgsym: No summary available for postgresql-plpython3-12-dbgsym in ubuntu groovy.

No description available for postgresql-plpython3-12-dbgsym in ubuntu groovy.

postgresql-pltcl-12: No summary available for postgresql-pltcl-12 in ubuntu groovy.

No description available for postgresql-pltcl-12 in ubuntu groovy.

postgresql-pltcl-12-dbgsym: No summary available for postgresql-pltcl-12-dbgsym in ubuntu groovy.

No description available for postgresql-pltcl-12-dbgsym in ubuntu groovy.

postgresql-server-dev-12: No summary available for postgresql-server-dev-12 in ubuntu hirsute.

No description available for postgresql-server-dev-12 in ubuntu hirsute.