Format: 1.8 Date: Tue, 02 Apr 2013 12:24:32 +0200 Source: postgresql-9.1 Binary: libpq-dev libpq5 libecpg6 libecpg-dev libecpg-compat3 libpgtypes3 postgresql-9.1 postgresql-9.1-dbg postgresql-client-9.1 postgresql-server-dev-9.1 postgresql-doc-9.1 postgresql-contrib-9.1 postgresql-plperl-9.1 postgresql-plpython-9.1 postgresql-pltcl-9.1 Architecture: i386 all i386_translations Version: 9.1.9-0ubuntu11.10 Distribution: oneiric Urgency: low Maintainer: Ubuntu/amd64 Build Daemon Changed-By: Martin Pitt Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 9.1 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-9.1 - object-relational SQL database, version 9.1 server postgresql-9.1-dbg - debug symbols for postgresql-9.1 postgresql-client-9.1 - front-end programs for PostgreSQL 9.1 postgresql-contrib-9.1 - additional facilities for PostgreSQL postgresql-doc-9.1 - documentation for the PostgreSQL database management system postgresql-plperl-9.1 - PL/Perl procedural language for PostgreSQL 9.1 postgresql-plpython-9.1 - PL/Python procedural language for PostgreSQL 9.1 postgresql-pltcl-9.1 - PL/Tcl procedural language for PostgreSQL 9.1 postgresql-server-dev-9.1 - development files for PostgreSQL 9.1 server-side programming Launchpad-Bugs-Fixed: 1163184 Changes: postgresql-9.1 (9.1.9-0ubuntu11.10) oneiric-security; urgency=low . * New upstream security/bug fix release: (LP: #1163184) - Fix insecure parsing of server command-line switches. A connection request containing a database name that begins with "-" could be crafted to damage or destroy files within the server's data directory, even if the request is eventually rejected. [CVE-2013-1899] - Reset OpenSSL randomness state in each postmaster child process. This avoids a scenario wherein random numbers generated by "contrib/pgcrypto" functions might be relatively easy for another database user to guess. The risk is only significant when the postmaster is configured with ssl = on but most connections don't use SSL encryption. [CVE-2013-1900] - Make REPLICATION privilege checks test current user not authenticated user. An unprivileged database user could exploit this mistake to call pg_start_backup() or pg_stop_backup(), thus possibly interfering with creation of routine backups. [CVE-2013-1901] - Fix GiST indexes to not use "fuzzy" geometric comparisons when it's not appropriate to do so. The core geometric types perform comparisons using "fuzzy" equality, but gist_box_same must do exact comparisons, else GiST indexes using it might become inconsistent. After installing this update, users should "REINDEX" any GiST indexes on box, polygon, circle, or point columns, since all of these use gist_box_same. - Fix erroneous range-union and penalty logic in GiST indexes that use "contrib/btree_gist" for variable-width data types, that is text, bytea, bit, and numeric columns. These errors could result in inconsistent indexes in which some keys that are present would not be found by searches, and also in useless index bloat. Users are advised to "REINDEX" such indexes after installing this update. - Fix bugs in GiST page splitting code for multi-column indexes. These errors could result in inconsistent indexes in which some keys that are present would not be found by searches, and also in indexes that are unnecessarily inefficient to search. Users are advised to "REINDEX" multi-column GiST indexes after installing this update. - See HISTORY/changelog.gz for details about the other bug fixes. Checksums-Sha1: 8a0b64f7a4695075e7e0bf9eb88ce3e8b967640c 215376 libpq-dev_9.1.9-0ubuntu11.10_i386.deb ed3629cc690bf3fc7083e371b2a4e44c592328f2 101328 libpq5_9.1.9-0ubuntu11.10_i386.deb 896dad76433c1089d13a6be25f8137a94e78519a 40432 libecpg6_9.1.9-0ubuntu11.10_i386.deb da1fc9a6cec001dee4475e783f91c7b2300a67a8 259852 libecpg-dev_9.1.9-0ubuntu11.10_i386.deb 6228a8c41e607f6db988d2f32d43dd04e26cb981 12610 libecpg-compat3_9.1.9-0ubuntu11.10_i386.deb a668d52fcf02e88bbc699462178b7847120567af 55236 libpgtypes3_9.1.9-0ubuntu11.10_i386.deb 99a6b3e6661c597380faf04818aa8769b1d65f48 4338452 postgresql-9.1_9.1.9-0ubuntu11.10_i386.deb 432d7506d06943fc3f7b544ee49564e56e14e3f9 8246676 postgresql-9.1-dbg_9.1.9-0ubuntu11.10_i386.deb 23bd882cf29f8d731242a03f60eb9f48d43663be 960018 postgresql-client-9.1_9.1.9-0ubuntu11.10_i386.deb 54725bda235a658a3bdefbb5be231742fc721e42 700316 postgresql-server-dev-9.1_9.1.9-0ubuntu11.10_i386.deb a6e454bd02d60765778287c1bef610e3aae336cf 2568932 postgresql-doc-9.1_9.1.9-0ubuntu11.10_all.deb 6ef845151ea7556aa0a163e7aa57d272e54575bc 453696 postgresql-contrib-9.1_9.1.9-0ubuntu11.10_i386.deb 4c7f7503ae3f97655fb73db4e2b537cf0f94fc57 67452 postgresql-plperl-9.1_9.1.9-0ubuntu11.10_i386.deb 81eb73303ac99ddae098f416f2252ce01b8501bb 58074 postgresql-plpython-9.1_9.1.9-0ubuntu11.10_i386.deb 458434584650d925b3c9aa8800e474397338f0d9 42190 postgresql-pltcl-9.1_9.1.9-0ubuntu11.10_i386.deb 0a6a511223ac7a24ef2142b5acdc38504be82411 5105682 postgresql-9.1_9.1.9-0ubuntu11.10_i386_translations.tar.gz Checksums-Sha256: dae1fe6347519571932fea0a908b1950d811bc12e0807d47dddc2c6d918c14ac 215376 libpq-dev_9.1.9-0ubuntu11.10_i386.deb 4926e5e20ebeaa65a58f38484e236af03d3cab5c255b3fdaa90372812b8cde98 101328 libpq5_9.1.9-0ubuntu11.10_i386.deb b87dc34bc6101ecaace336776cfad2f19fb7fe54036ce20db71aa6e8dae3e1ab 40432 libecpg6_9.1.9-0ubuntu11.10_i386.deb c0c2a99a5bf1e8af3a77470035eb8269f352c2d2692c9546776098d5bf34a75f 259852 libecpg-dev_9.1.9-0ubuntu11.10_i386.deb 2fa15cc9cd191e2b85c6fbf320bc49ab061095eb2bf29421a0d5a6823b75f2d4 12610 libecpg-compat3_9.1.9-0ubuntu11.10_i386.deb b909c22228a89a68c89cbbc5dfb4f733446fb39d747095efbb6da9ec428b731c 55236 libpgtypes3_9.1.9-0ubuntu11.10_i386.deb 1ad2d3d950b6dcace252f9a8994ff89f329c57142fb6a14e2f5fb199979bec9c 4338452 postgresql-9.1_9.1.9-0ubuntu11.10_i386.deb 80b7d056e3ead3f1f1e7c0fbc5ccc94717e137b88bae574edf18047fd579883f 8246676 postgresql-9.1-dbg_9.1.9-0ubuntu11.10_i386.deb 5534247dda912840d8f82463e88c3854d5dd54f0d0abbe16266b0a4a95e66802 960018 postgresql-client-9.1_9.1.9-0ubuntu11.10_i386.deb e2fd81977f274471fc359aae2ece74b003f5f87417155055c05982ceb66f2221 700316 postgresql-server-dev-9.1_9.1.9-0ubuntu11.10_i386.deb d5a4efe3fcb83c05335afe27b57299d45456117140fef52d2de02204efe6ff50 2568932 postgresql-doc-9.1_9.1.9-0ubuntu11.10_all.deb 059dd0acb0dfed8b705e4cd967477b78962199d849503e4e9d52aa18c9e535bc 453696 postgresql-contrib-9.1_9.1.9-0ubuntu11.10_i386.deb 6aa5fca3cf2d83f76714425cb6b0f21b971645012e0de5db51862556933e3b28 67452 postgresql-plperl-9.1_9.1.9-0ubuntu11.10_i386.deb 4d7a14e97cc08fd6d78e9248a1d38fb7f3f9d7141149c6f30a230f4cd6633e09 58074 postgresql-plpython-9.1_9.1.9-0ubuntu11.10_i386.deb c2cf72e07f6d2f999c947aafc44570022ed33465d698d8498f4b6c752f3172ef 42190 postgresql-pltcl-9.1_9.1.9-0ubuntu11.10_i386.deb 52d6cf071a905ba494c58a78d9ae515a75cb1e8a0ce16e5dcafb107dce31626e 5105682 postgresql-9.1_9.1.9-0ubuntu11.10_i386_translations.tar.gz Files: c4b4098a4de4e038d24481e941033217 215376 libdevel optional libpq-dev_9.1.9-0ubuntu11.10_i386.deb 1cae24e71d086567d8b005045b1003f4 101328 libs optional libpq5_9.1.9-0ubuntu11.10_i386.deb 80e885f9d012aa6ba1f954c4a3fd6e99 40432 libs optional libecpg6_9.1.9-0ubuntu11.10_i386.deb 7b36ce0d1cb0d9e2437abb8eaaa36465 259852 libdevel optional libecpg-dev_9.1.9-0ubuntu11.10_i386.deb f907e5e1389e9e8d313fe2583665d206 12610 libs optional libecpg-compat3_9.1.9-0ubuntu11.10_i386.deb a8a72b95ce612fde27674af6123f70a3 55236 libs optional libpgtypes3_9.1.9-0ubuntu11.10_i386.deb d032ad91cad21e97fbd27513f033cb37 4338452 database optional postgresql-9.1_9.1.9-0ubuntu11.10_i386.deb 92e82f13d80fad3ea003f2dcf77e845c 8246676 debug extra postgresql-9.1-dbg_9.1.9-0ubuntu11.10_i386.deb bad7d64235871b0d0e725d736cb49146 960018 database optional postgresql-client-9.1_9.1.9-0ubuntu11.10_i386.deb b97d1f836e80ccd7709afc1413da84d2 700316 libdevel optional postgresql-server-dev-9.1_9.1.9-0ubuntu11.10_i386.deb dc49d16b119d9fa83af67708161bf059 2568932 doc optional postgresql-doc-9.1_9.1.9-0ubuntu11.10_all.deb c52ef99d3a6d36ee392d25f25c1737c5 453696 database optional postgresql-contrib-9.1_9.1.9-0ubuntu11.10_i386.deb 4c993f5664b1fc47cfe00ed6375d26ff 67452 database optional postgresql-plperl-9.1_9.1.9-0ubuntu11.10_i386.deb 4f9cb23cb04f288439a01c18c946e4db 58074 database optional postgresql-plpython-9.1_9.1.9-0ubuntu11.10_i386.deb 8409bb6a1e80e37b0b6a7b46bf504625 42190 database optional postgresql-pltcl-9.1_9.1.9-0ubuntu11.10_i386.deb 13111a7d45651e7fc6bc536a53b52a34 5105682 raw-translations - postgresql-9.1_9.1.9-0ubuntu11.10_i386_translations.tar.gz Original-Maintainer: Martin Pitt