Format: 1.8 Date: Tue, 02 Apr 2013 11:52:28 +0200 Source: postgresql-9.1 Binary: libpq-dev libpq5 libecpg6 libecpg-dev libecpg-compat3 libpgtypes3 postgresql-9.1 postgresql-9.1-dbg postgresql-client-9.1 postgresql-server-dev-9.1 postgresql-doc-9.1 postgresql-contrib-9.1 postgresql-plperl-9.1 postgresql-plpython-9.1 postgresql-plpython3-9.1 postgresql-pltcl-9.1 Architecture: amd64 amd64_translations Version: 9.1.9-0ubuntu12.10 Distribution: quantal Urgency: low Maintainer: Ubuntu/amd64 Build Daemon Changed-By: Martin Pitt Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 9.1 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-9.1 - object-relational SQL database, version 9.1 server postgresql-9.1-dbg - debug symbols for postgresql-9.1 postgresql-client-9.1 - front-end programs for PostgreSQL 9.1 postgresql-contrib-9.1 - additional facilities for PostgreSQL postgresql-doc-9.1 - documentation for the PostgreSQL database management system postgresql-plperl-9.1 - PL/Perl procedural language for PostgreSQL 9.1 postgresql-plpython-9.1 - PL/Python procedural language for PostgreSQL 9.1 postgresql-plpython3-9.1 - PL/Python 3 procedural language for PostgreSQL 9.1 postgresql-pltcl-9.1 - PL/Tcl procedural language for PostgreSQL 9.1 postgresql-server-dev-9.1 - development files for PostgreSQL 9.1 server-side programming Launchpad-Bugs-Fixed: 1163184 Changes: postgresql-9.1 (9.1.9-0ubuntu12.10) quantal-security; urgency=low . * New upstream security/bug fix release: (LP: #1163184) - Fix insecure parsing of server command-line switches. A connection request containing a database name that begins with "-" could be crafted to damage or destroy files within the server's data directory, even if the request is eventually rejected. [CVE-2013-1899] - Reset OpenSSL randomness state in each postmaster child process. This avoids a scenario wherein random numbers generated by "contrib/pgcrypto" functions might be relatively easy for another database user to guess. The risk is only significant when the postmaster is configured with ssl = on but most connections don't use SSL encryption. [CVE-2013-1900] - Make REPLICATION privilege checks test current user not authenticated user. An unprivileged database user could exploit this mistake to call pg_start_backup() or pg_stop_backup(), thus possibly interfering with creation of routine backups. [CVE-2013-1901] - Fix GiST indexes to not use "fuzzy" geometric comparisons when it's not appropriate to do so. The core geometric types perform comparisons using "fuzzy" equality, but gist_box_same must do exact comparisons, else GiST indexes using it might become inconsistent. After installing this update, users should "REINDEX" any GiST indexes on box, polygon, circle, or point columns, since all of these use gist_box_same. - Fix erroneous range-union and penalty logic in GiST indexes that use "contrib/btree_gist" for variable-width data types, that is text, bytea, bit, and numeric columns. These errors could result in inconsistent indexes in which some keys that are present would not be found by searches, and also in useless index bloat. Users are advised to "REINDEX" such indexes after installing this update. - Fix bugs in GiST page splitting code for multi-column indexes. These errors could result in inconsistent indexes in which some keys that are present would not be found by searches, and also in indexes that are unnecessarily inefficient to search. Users are advised to "REINDEX" multi-column GiST indexes after installing this update. - See HISTORY/changelog.gz for details about the other bug fixes. Checksums-Sha1: eacf53bfe6c154a9a6a27497ba92f8fa9bc7a94c 153666 libpq-dev_9.1.9-0ubuntu12.10_amd64.deb a1d7d0126024cf52f11f4872d4dd4b2d460203fe 77970 libpq5_9.1.9-0ubuntu12.10_amd64.deb 7386b8721865f6c5c06ada7d5d8db272d3e94fd6 34416 libecpg6_9.1.9-0ubuntu12.10_amd64.deb 3a805895d49c4f60da196a5c99f1dbfed37e7502 203340 libecpg-dev_9.1.9-0ubuntu12.10_amd64.deb c090c2484634203d627385eecb7c459850112d33 11004 libecpg-compat3_9.1.9-0ubuntu12.10_amd64.deb b13a29f8c0260c052eaa6f1905eaf84207f03afe 40162 libpgtypes3_9.1.9-0ubuntu12.10_amd64.deb 5ab44185a94382e82dc8719ba8bebf794bc4997f 2478294 postgresql-9.1_9.1.9-0ubuntu12.10_amd64.deb de41e59799dca157eb364dbddaa2fae4d7069092 6652544 postgresql-9.1-dbg_9.1.9-0ubuntu12.10_amd64.deb 30db13d0ce54f98890abb126a17f4e9251a97130 711404 postgresql-client-9.1_9.1.9-0ubuntu12.10_amd64.deb 08dd4fcafc95e265ea17dea4e84e20316e570676 529704 postgresql-server-dev-9.1_9.1.9-0ubuntu12.10_amd64.deb d7038270dc332d45a185d9fa5a300d2cfb27e799 334222 postgresql-contrib-9.1_9.1.9-0ubuntu12.10_amd64.deb 6abce6ccfeb0c33f05999d0ac86dbfa966c2751d 38974 postgresql-plperl-9.1_9.1.9-0ubuntu12.10_amd64.deb 064632673ba07f9a799c19984f00b323a2b8c9f5 35234 postgresql-plpython-9.1_9.1.9-0ubuntu12.10_amd64.deb 27a2402b5ecf2e9f11e8e624705194b3cb10b019 35024 postgresql-plpython3-9.1_9.1.9-0ubuntu12.10_amd64.deb 145f4166a54fdc6824fde29993eec15254416346 21718 postgresql-pltcl-9.1_9.1.9-0ubuntu12.10_amd64.deb 922028a45e0f781c525e58e986c2211b3a92f654 5002444 postgresql-9.1_9.1.9-0ubuntu12.10_amd64_translations.tar.gz Checksums-Sha256: 8ab525edb381b0339594850ae65b50a4543c29707bb88270c8125506d78d9a8f 153666 libpq-dev_9.1.9-0ubuntu12.10_amd64.deb 3c59d1aeebc262a8c12ab8183832091ca1bf37d44aaa4def963e1c5948e396f4 77970 libpq5_9.1.9-0ubuntu12.10_amd64.deb ed1da7e5270140213b5c04a2231e078f08322a3db3a2a45654520b2006de8193 34416 libecpg6_9.1.9-0ubuntu12.10_amd64.deb 0cc9c44af0e48f9df304f232897d707d13614fbcc5c12a4f68181531ec0f1d6a 203340 libecpg-dev_9.1.9-0ubuntu12.10_amd64.deb fdb779dc760d75bd1ef697bddab2ef637310ea5bb9ac2bced13f9144e5ff6945 11004 libecpg-compat3_9.1.9-0ubuntu12.10_amd64.deb b6c9661e54208917edec4af462cd70f57660896849e5281ed9debb02d36f2d8f 40162 libpgtypes3_9.1.9-0ubuntu12.10_amd64.deb d893dfd711d55f1c9ea3c98bb38935a2d24b2b055384b7b7ea32cc3822a2d088 2478294 postgresql-9.1_9.1.9-0ubuntu12.10_amd64.deb 742249df1ded27907da5dcba7c9e46a6c62696f1d86a452b65534f230b85cdb4 6652544 postgresql-9.1-dbg_9.1.9-0ubuntu12.10_amd64.deb 22c82a334a5a748ec7ea1dc304675ae4bca410e2a9e1f30be2a066d4a64a1fde 711404 postgresql-client-9.1_9.1.9-0ubuntu12.10_amd64.deb 0b05e1a53b4a698aa8c2e9ee92089c109d752018b116891269846dd1937ba0e3 529704 postgresql-server-dev-9.1_9.1.9-0ubuntu12.10_amd64.deb 950823ceb0c4abd65b95c43ae443af189c1bfa92f8430edf00819c410c3a0283 334222 postgresql-contrib-9.1_9.1.9-0ubuntu12.10_amd64.deb a8bc822af010f92230199609d6e3f157837a31d248ce94f04899d6fae9306c86 38974 postgresql-plperl-9.1_9.1.9-0ubuntu12.10_amd64.deb 0dfcaa3366a7d5621e5688d84c37522320d13f92c0e4661f5cf7fa6db4641081 35234 postgresql-plpython-9.1_9.1.9-0ubuntu12.10_amd64.deb d6597dbf196098f7e33ba041118c572dd6a0b42c047b0003f3163026e4795f59 35024 postgresql-plpython3-9.1_9.1.9-0ubuntu12.10_amd64.deb 0eb0a5f71ec10eabb662a4628046d6c130a54e561a088b03ee7f94984dd500b3 21718 postgresql-pltcl-9.1_9.1.9-0ubuntu12.10_amd64.deb 1c5108fbbb42b5decdb968a4443b64eaed998b4324d690485e54c680b8b52b48 5002444 postgresql-9.1_9.1.9-0ubuntu12.10_amd64_translations.tar.gz Files: bb94521bd2b3697a686db59276b8aef3 153666 libdevel optional libpq-dev_9.1.9-0ubuntu12.10_amd64.deb a82a80cbf1aebd69afade141bd1786f3 77970 libs optional libpq5_9.1.9-0ubuntu12.10_amd64.deb bbe0e5a64728df2f3891c1b560e9db48 34416 libs optional libecpg6_9.1.9-0ubuntu12.10_amd64.deb 28cd5c5108f3cfd69e21c1097857e480 203340 libdevel optional libecpg-dev_9.1.9-0ubuntu12.10_amd64.deb b2dbcb6be4310093ca917130d84bc003 11004 libs optional libecpg-compat3_9.1.9-0ubuntu12.10_amd64.deb bc2033a64f47c5ff4f6bb9b44eb288e5 40162 libs optional libpgtypes3_9.1.9-0ubuntu12.10_amd64.deb 600691676a13002c407421a36635a71c 2478294 database optional postgresql-9.1_9.1.9-0ubuntu12.10_amd64.deb 44c88abfbd708bb3fba3617b2b6546ad 6652544 debug extra postgresql-9.1-dbg_9.1.9-0ubuntu12.10_amd64.deb 243a1708a276a6efd2f81c4bf08597f0 711404 database optional postgresql-client-9.1_9.1.9-0ubuntu12.10_amd64.deb 63f89b6c0c61aebfe16909319178e976 529704 libdevel optional postgresql-server-dev-9.1_9.1.9-0ubuntu12.10_amd64.deb c21eea7239dafd5876dddb94316d7088 334222 database optional postgresql-contrib-9.1_9.1.9-0ubuntu12.10_amd64.deb 51931258c5e8da1a4d8b1a8a79d223c6 38974 database optional postgresql-plperl-9.1_9.1.9-0ubuntu12.10_amd64.deb 47b009698186182dc99fd39a3e2bbb40 35234 database optional postgresql-plpython-9.1_9.1.9-0ubuntu12.10_amd64.deb 53510ceb1b9c83a7f712e9c02ee979b7 35024 database optional postgresql-plpython3-9.1_9.1.9-0ubuntu12.10_amd64.deb d9bf34960625f11926750848ae134ab3 21718 database optional postgresql-pltcl-9.1_9.1.9-0ubuntu12.10_amd64.deb 4f7e2efc1c5a54838766ef9d62545dc1 5002444 raw-translations - postgresql-9.1_9.1.9-0ubuntu12.10_amd64_translations.tar.gz Original-Maintainer: Debian PostgreSQL Maintainers