Format: 1.8 Date: Wed, 20 May 2015 10:50:22 +0200 Source: postgresql-9.4 Binary: libpq-dev libpq5 libecpg6 libecpg-dev libecpg-compat3 libpgtypes3 postgresql-9.4 postgresql-9.4-dbg postgresql-client-9.4 postgresql-server-dev-9.4 postgresql-doc-9.4 postgresql-contrib-9.4 postgresql-plperl-9.4 postgresql-plpython-9.4 postgresql-plpython3-9.4 postgresql-pltcl-9.4 Architecture: ppc64el ppc64el_translations Version: 9.4.2-1 Distribution: wily-proposed Urgency: medium Maintainer: Ubuntu Build Daemon Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 9.4 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-9.4 - object-relational SQL database, version 9.4 server postgresql-9.4-dbg - debug symbols for postgresql-9.4 postgresql-client-9.4 - front-end programs for PostgreSQL 9.4 postgresql-contrib-9.4 - additional facilities for PostgreSQL postgresql-doc-9.4 - documentation for the PostgreSQL database management system postgresql-plperl-9.4 - PL/Perl procedural language for PostgreSQL 9.4 postgresql-plpython-9.4 - PL/Python procedural language for PostgreSQL 9.4 postgresql-plpython3-9.4 - PL/Python 3 procedural language for PostgreSQL 9.4 postgresql-pltcl-9.4 - PL/Tcl procedural language for PostgreSQL 9.4 postgresql-server-dev-9.4 - development files for PostgreSQL 9.4 server-side programming Closes: 781361 Changes: postgresql-9.4 (9.4.2-1) unstable; urgency=medium . * New upstream version. . + Avoid possible crash when client disconnects just before the authentication timeout expires (Benkocs Norbert Attila) . If the timeout interrupt fired partway through the session shutdown sequence, SSL-related state would be freed twice, typically causing a crash and hence denial of service to other sessions. Experimentation shows that an unauthenticated remote attacker could trigger the bug somewhat consistently, hence treat as security issue. (CVE-2015-3165) . + Improve detection of system-call failures (Noah Misch) . Our replacement implementation of snprintf() failed to check for errors reported by the underlying system library calls; the main case that might be missed is out-of-memory situations. In the worst case this might lead to information exposure, due to our code assuming that a buffer had been overwritten when it hadn't been. Also, there were a few places in which security-relevant calls of other system library functions did not check for failure. . It remains possible that some calls of the *printf() family of functions are vulnerable to information disclosure if an out-of-memory error occurs at just the wrong time. We judge the risk to not be large, but will continue analysis in this area. (CVE-2015-3166) . + In contrib/pgcrypto, uniformly report decryption failures as Wrong key or corrupt data (Noah Misch) . Previously, some cases of decryption with an incorrect key could report other error message texts. It has been shown that such variance in error reports can aid attackers in recovering keys from other systems. While it's unknown whether pgcrypto's specific behaviors are likewise exploitable, it seems better to avoid the risk by using a one-size-fits-all message. (CVE-2015-3167) . + Protect against wraparound of multixact member IDs (Álvaro Herrera, Robert Haas, Thomas Munro) . Under certain usage patterns, the existing defenses against this might be insufficient, allowing pg_multixact/members files to be removed too early, resulting in data loss. The fix for this includes modifying the server to fail transactions that would result in overwriting old multixact member ID data, and improving autovacuum to ensure it will act proactively to prevent multixact member ID wraparound, as it does for transaction ID wraparound. . + pg_dump -Fd -Z compression level fixed. (Closes: #781361) . * Make postgresql-9.4 Recommends: postgresql-contrib-9.4. * Enable TAP tests. * Repository moved to git, update Vcs headers. Checksums-Sha1: cc98422816d31691d01738236db0445cc0418778 147666 libpq-dev_9.4.2-1_ppc64el.deb 031cee42ed764b3998f9ad9c283bc0600f770db3 77710 libpq5_9.4.2-1_ppc64el.deb 5c406c9539f4b5e9a0e0937d022841ddfc10c230 33420 libecpg6_9.4.2-1_ppc64el.deb 806d2621b6f88c2934ac7d2a3173cfcb57e4fcb4 202884 libecpg-dev_9.4.2-1_ppc64el.deb faea1ee1ec17fe07502328ce7a90a81d4e5fbb1e 10328 libecpg-compat3_9.4.2-1_ppc64el.deb af867fa2d6760653fdf70ce4d6714fc069ada7ef 36990 libpgtypes3_9.4.2-1_ppc64el.deb 6f057e6c8070ffb58869cc32b62fb35028ac8be3 2779940 postgresql-9.4_9.4.2-1_ppc64el.deb de93da2e5248593d09e63df77db4f8e3beea176e 13431310 postgresql-9.4-dbg_9.4.2-1_ppc64el.deb 35092ca0e5293b865030f2a6d803a3e57a856551 796860 postgresql-client-9.4_9.4.2-1_ppc64el.deb 44a6be73a682c9463a114b5c64487ae7ebe68d54 630584 postgresql-server-dev-9.4_9.4.2-1_ppc64el.deb 7a7f32a7796ec83d2fa943cb1c7da4b6e57e9e5b 446236 postgresql-contrib-9.4_9.4.2-1_ppc64el.deb adaa69b3c3880ea69aea86c63369e183e93226f7 37888 postgresql-plperl-9.4_9.4.2-1_ppc64el.deb 0b5888ef91fd85617e8699864fc77e4fa3d0e1cb 36170 postgresql-plpython-9.4_9.4.2-1_ppc64el.deb 74311093c845065a553c17f44d62e84a606b9ca9 35816 postgresql-plpython3-9.4_9.4.2-1_ppc64el.deb 62364afdcdefca93eb4435bc79bb28408e92e70b 20380 postgresql-pltcl-9.4_9.4.2-1_ppc64el.deb f5dfb08de7bda8a1d09f9ef091c7e642a450a5ce 934 libpq-dev-dbgsym_9.4.2-1_ppc64el.ddeb 6877e78c9dce65a91dde8b8bb607cc1ac4ae367a 1020 libpq5-dbgsym_9.4.2-1_ppc64el.ddeb 938195730991b32bf1342aee0d2892658b06ac2f 908 libecpg6-dbgsym_9.4.2-1_ppc64el.ddeb f5c91b866a1d419fa1a6bdebe551cdb5ec1b516a 1016 libecpg-dev-dbgsym_9.4.2-1_ppc64el.ddeb 792227ca6ece84ab52405ae8022978b7bf653aef 914 libecpg-compat3-dbgsym_9.4.2-1_ppc64el.ddeb 6286c22b905198cbf2801141c1ee858327d23956 908 libpgtypes3-dbgsym_9.4.2-1_ppc64el.ddeb df30722822726fae87118f5f550946ceafadbebb 1224 postgresql-9.4-dbgsym_9.4.2-1_ppc64el.ddeb 342759a4a8bc696d80ee4849374780b1494bb95f 1074 postgresql-client-9.4-dbgsym_9.4.2-1_ppc64el.ddeb ed1699ae9677641f9466ddb08dead94ca2079734 1022 postgresql-server-dev-9.4-dbgsym_9.4.2-1_ppc64el.ddeb bddd913f2e4f649eb9246f2d29b2a989c45a13b8 2214 postgresql-contrib-9.4-dbgsym_9.4.2-1_ppc64el.ddeb eb90c0e35ed5d235bbf5d194466575531b4826eb 960 postgresql-plperl-9.4-dbgsym_9.4.2-1_ppc64el.ddeb 2ef98f7c330ea8b62289a4a36fe444a1c271abcc 964 postgresql-plpython-9.4-dbgsym_9.4.2-1_ppc64el.ddeb 6c01d0b47c1bc90b9fe3c8a4e90441c247539e28 964 postgresql-plpython3-9.4-dbgsym_9.4.2-1_ppc64el.ddeb 8bb888b5349ab85919e98a10656d2b115c022eaf 960 postgresql-pltcl-9.4-dbgsym_9.4.2-1_ppc64el.ddeb 02c968f597e35e80315a3494660d69c8b5645ccd 5366830 postgresql-9.4_9.4.2-1_ppc64el_translations.tar.gz Checksums-Sha256: 53453bdf9f75e0a8637c3cfdd8bd730fd87cb0f2cb169c086b060dbe83fb887b 147666 libpq-dev_9.4.2-1_ppc64el.deb 16014604ac1cce1e8e4c3719bf4c8aee624e381a1884f60416e63a0ff5acb299 77710 libpq5_9.4.2-1_ppc64el.deb eef1eb4306ecf5b4c2ae13b898c4e158634a4edde14077faa175649db58d3f24 33420 libecpg6_9.4.2-1_ppc64el.deb 5c6e45d0a84cb70cb5e5bfb22b7e41cb67229e365f3ad174df34f1a532a87735 202884 libecpg-dev_9.4.2-1_ppc64el.deb 716d48a89ba4f7726123bb7dda773318c1e81281f4208104abe781d243a34d62 10328 libecpg-compat3_9.4.2-1_ppc64el.deb bfaf4c68f163b86f06484636d754f4d735253be44f8f6a79c7f8a17ca5222145 36990 libpgtypes3_9.4.2-1_ppc64el.deb 29f1271fb380a1e27265387253e84a91ba443515e3f44e9b5541f338d4b70951 2779940 postgresql-9.4_9.4.2-1_ppc64el.deb fa7b63dd5b7483e9641fd912177c64712797d22824cc758fe8fc2f70839e78b8 13431310 postgresql-9.4-dbg_9.4.2-1_ppc64el.deb 7e2e289f84f22710aafa6b1492bae6bd3936f000c53df51038cef16e3dd0f8bb 796860 postgresql-client-9.4_9.4.2-1_ppc64el.deb 2a67a0de5cfdb17f71467e8ebaa40d05c641e1fedfddca85666c44896d13a20f 630584 postgresql-server-dev-9.4_9.4.2-1_ppc64el.deb 5b33dbdb1fbf0dceb53700e229aab9e29b168c2894511c3314845840f07db63a 446236 postgresql-contrib-9.4_9.4.2-1_ppc64el.deb 49259691761e40403be343d740d09d72ddc6a32b535160438d52115d6e2f3504 37888 postgresql-plperl-9.4_9.4.2-1_ppc64el.deb 5aed3adacf88ec7f9ebc1880f19310193de2fa358f51a27cacbed753c5d41e8b 36170 postgresql-plpython-9.4_9.4.2-1_ppc64el.deb a196c3b91de4fe75170ced3c14fd5425759ad5150b09204bc6debea523c7b924 35816 postgresql-plpython3-9.4_9.4.2-1_ppc64el.deb 7a53dfdc5cbd2dd56854988d2e7ed1e347a698c9c7adf589009740060752127a 20380 postgresql-pltcl-9.4_9.4.2-1_ppc64el.deb d265fc24c1a575d1e7b9f88e293ce0f28d1a63f8fd9fcec868d4ea6835c5213d 934 libpq-dev-dbgsym_9.4.2-1_ppc64el.ddeb 8676d75ab90592613d2127b0f0cc0f095ae25ab33897c958b6bbeef670fb3baf 1020 libpq5-dbgsym_9.4.2-1_ppc64el.ddeb 268eff022cc0a53ee678cf9218db30e260a2e507a33c37ae5bdd073786f9cdb2 908 libecpg6-dbgsym_9.4.2-1_ppc64el.ddeb 008f7528008d88f6fa0f3c644ab291aa114954a4f40e380c0f3c1bbdcb581a55 1016 libecpg-dev-dbgsym_9.4.2-1_ppc64el.ddeb 97d073ca239be2d8a7c81dafd4bbf13e6d0cb45436b5387654f0022cfea61d5d 914 libecpg-compat3-dbgsym_9.4.2-1_ppc64el.ddeb a7a4dfe8e5913aff39e08cae83f6a7cb6db3796481e075754dc1ded949669ad5 908 libpgtypes3-dbgsym_9.4.2-1_ppc64el.ddeb 63b0d21e546b414520281ac08717d1f605d65ce9b49f30438303077ef70394e4 1224 postgresql-9.4-dbgsym_9.4.2-1_ppc64el.ddeb 28d0b4d18b4a47b2903856d78d1d6bd8ab553963b2ea01174004766a5448724e 1074 postgresql-client-9.4-dbgsym_9.4.2-1_ppc64el.ddeb 4342fc50a491f3226e680e8e25df1b91ceb76523904f69fa552e7a44bd7cffc1 1022 postgresql-server-dev-9.4-dbgsym_9.4.2-1_ppc64el.ddeb e86e33f7fc958a5da430763388efe2bf859f018288780f41ee52784194a6bf30 2214 postgresql-contrib-9.4-dbgsym_9.4.2-1_ppc64el.ddeb 2315b0f6b8929138e8cdd6355c78eac82cad8c19309e7d4df8007ffe19d1a42b 960 postgresql-plperl-9.4-dbgsym_9.4.2-1_ppc64el.ddeb ce11a966eefe6d20caccfb0a9023b8790aae502fe48857c3dbb1034c1378576f 964 postgresql-plpython-9.4-dbgsym_9.4.2-1_ppc64el.ddeb 78b6da9babad7f04624917f084dca06a17eb647a02a65eff9de97a9be58e74bd 964 postgresql-plpython3-9.4-dbgsym_9.4.2-1_ppc64el.ddeb 3e03f6e3c08638f7703d4e929c373b831372b99701a2998cbc276696f26d867e 960 postgresql-pltcl-9.4-dbgsym_9.4.2-1_ppc64el.ddeb 6f3b7e148928d3c94f29b99ea530d76eef19293e48ed707ff2957f097c8729d1 5366830 postgresql-9.4_9.4.2-1_ppc64el_translations.tar.gz Files: b9d0128fd01980181575e5ae97b8e5a1 147666 libdevel optional libpq-dev_9.4.2-1_ppc64el.deb a0d35e1f2d53ec8f202ea3f781938e7f 77710 libs optional libpq5_9.4.2-1_ppc64el.deb 12ad87797cf8cc661785794de45305c0 33420 libs optional libecpg6_9.4.2-1_ppc64el.deb 69adc0e849aa78c7688ee0163cd9d773 202884 libdevel optional libecpg-dev_9.4.2-1_ppc64el.deb e8342cfe328e4c8e8585dd57ca0f352b 10328 libs optional libecpg-compat3_9.4.2-1_ppc64el.deb 9ac93aeb6d76c84aeae075dae2f2f25e 36990 libs optional libpgtypes3_9.4.2-1_ppc64el.deb 026668c64ccdf1bb8008a44d628fdf4c 2779940 database optional postgresql-9.4_9.4.2-1_ppc64el.deb e3c1be86c9db38a1c9abb2af2026a203 13431310 debug extra postgresql-9.4-dbg_9.4.2-1_ppc64el.deb 8969b6386a33cf8df3f8d07c29668870 796860 database optional postgresql-client-9.4_9.4.2-1_ppc64el.deb 116b2c7cd6287188a63bc94d660bdcdd 630584 libdevel optional postgresql-server-dev-9.4_9.4.2-1_ppc64el.deb a22806c7faa75fab9c0006248335fdb9 446236 database optional postgresql-contrib-9.4_9.4.2-1_ppc64el.deb 8105dc2587b55af044055f2069ebfb62 37888 database optional postgresql-plperl-9.4_9.4.2-1_ppc64el.deb c9dcbbdfeb3bf84d3270357388e3e2ea 36170 database optional postgresql-plpython-9.4_9.4.2-1_ppc64el.deb 7f32c5590cd92d02d7a5640362adf15c 35816 database optional postgresql-plpython3-9.4_9.4.2-1_ppc64el.deb 941d402d78b0cb4976d829a2d27c7563 20380 database optional postgresql-pltcl-9.4_9.4.2-1_ppc64el.deb 73dc6ffe119a4e6109cc941a14d0ef26 934 libdevel extra libpq-dev-dbgsym_9.4.2-1_ppc64el.ddeb c60c04e8cbd860b995d5ab1db0d12597 1020 libs extra libpq5-dbgsym_9.4.2-1_ppc64el.ddeb 0da5f63c0e7847f58a62e697aa504c0e 908 libs extra libecpg6-dbgsym_9.4.2-1_ppc64el.ddeb bc0abba36d5ae8237e97a00892f91177 1016 libdevel extra libecpg-dev-dbgsym_9.4.2-1_ppc64el.ddeb f1b5698568de18cf9bcbc2488d6dc3df 914 libs extra libecpg-compat3-dbgsym_9.4.2-1_ppc64el.ddeb 497e366c1fe9b486cf0460321e0db73e 908 libs extra libpgtypes3-dbgsym_9.4.2-1_ppc64el.ddeb 67c078b9685748aa4345a800c01d739f 1224 database extra postgresql-9.4-dbgsym_9.4.2-1_ppc64el.ddeb 718cbb6900c8b63b13435005e45c4d10 1074 database extra postgresql-client-9.4-dbgsym_9.4.2-1_ppc64el.ddeb ff4b45ba919fbc9214544da9248beae7 1022 libdevel extra postgresql-server-dev-9.4-dbgsym_9.4.2-1_ppc64el.ddeb f536b6488fd016f2efd5ae0108483645 2214 database extra postgresql-contrib-9.4-dbgsym_9.4.2-1_ppc64el.ddeb b9aa9bd55b7f273a12e10a6d0f238d73 960 database extra postgresql-plperl-9.4-dbgsym_9.4.2-1_ppc64el.ddeb c5ba25656fc862b116b9d27ad12e6e56 964 database extra postgresql-plpython-9.4-dbgsym_9.4.2-1_ppc64el.ddeb a2f50ac08bc218943fb57873d830b1b2 964 database extra postgresql-plpython3-9.4-dbgsym_9.4.2-1_ppc64el.ddeb 2085d7a2d600cac887d33f6cc6db3cb6 960 database extra postgresql-pltcl-9.4-dbgsym_9.4.2-1_ppc64el.ddeb 30de0171646581c5e0a75d0cd99c7bac 5366830 raw-translations - postgresql-9.4_9.4.2-1_ppc64el_translations.tar.gz