-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 25 Dec 2025 19:03:31 +0100 Source: postgresql-17 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-17 postgresql-17-dbgsym postgresql-client-17 postgresql-client-17-dbgsym postgresql-plperl-17 postgresql-plperl-17-dbgsym postgresql-plpython3-17 postgresql-plpython3-17-dbgsym postgresql-pltcl-17 postgresql-pltcl-17-dbgsym postgresql-server-dev-17 postgresql-server-dev-17-dbgsym Architecture: amd64 Version: 17.7-0+deb13u1 Distribution: trixie Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 17 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-17 - The World's Most Advanced Open Source Relational Database postgresql-client-17 - front-end programs for PostgreSQL 17 postgresql-plperl-17 - PL/Perl procedural language for PostgreSQL 17 postgresql-plpython3-17 - PL/Python 3 procedural language for PostgreSQL 17 postgresql-pltcl-17 - PL/Tcl procedural language for PostgreSQL 17 postgresql-server-dev-17 - development files for PostgreSQL 17 server-side programming Changes: postgresql-17 (17.7-0+deb13u1) trixie; urgency=medium . * New upstream version 17.7. . + Check for CREATE privileges on the schema in CREATE STATISTICS (Jelte Fennema-Nio) . This omission allowed table owners to create statistics in any schema, potentially leading to unexpected naming conflicts. . The PostgreSQL Project thanks Jelte Fennema-Nio for reporting this problem. (CVE-2025-12817) . + Avoid integer overflow in allocation-size calculations within libpq (Jacob Champion) . Several places in libpq were not sufficiently careful about computing the required size of a memory allocation. Sufficiently large inputs could cause integer overflow, resulting in an undersized buffer, which would then lead to writing past the end of the buffer. . The PostgreSQL Project thanks Aleksey Solovev of Positive Technologies for reporting this problem. (CVE-2025-12818) Checksums-Sha1: 622a1956a1b3324c773466cc1cf3af19b2a33625 16500 libecpg-compat3-dbgsym_17.7-0+deb13u1_amd64.deb dcd0d9715e70364e22dfadabae02d0851759d4bd 16844 libecpg-compat3_17.7-0+deb13u1_amd64.deb 6ed7b2f4faba9b0443888035421efe5377faa906 276284 libecpg-dev-dbgsym_17.7-0+deb13u1_amd64.deb 3519658015fc3ecd726aba1e4271ae3a6a73dead 303460 libecpg-dev_17.7-0+deb13u1_amd64.deb 880e5585422cb1bb1f9f44f31e4cd8f63ac427e2 114796 libecpg6-dbgsym_17.7-0+deb13u1_amd64.deb 8a795f17bad227a7e320b588fabc53fe033cda1c 62160 libecpg6_17.7-0+deb13u1_amd64.deb 187f6443b9688fb37e55a3a32db21b688e1993e0 90652 libpgtypes3-dbgsym_17.7-0+deb13u1_amd64.deb 4047afe3373c16e50bf7baa82875e3f8ce824aae 45428 libpgtypes3_17.7-0+deb13u1_amd64.deb a22a91a96cdcab153df8374b57890c3074ad8607 150564 libpq-dev_17.7-0+deb13u1_amd64.deb 9e99489b12b3b1a8972bddf3a0daed70a6c19d57 298128 libpq5-dbgsym_17.7-0+deb13u1_amd64.deb a22986e479cabc60e39bda6a708abab8ce3ddb6d 227868 libpq5_17.7-0+deb13u1_amd64.deb b61c880ad16f060250436c91f05906fa42c02325 19632368 postgresql-17-dbgsym_17.7-0+deb13u1_amd64.deb ee6ebe1151c35b784e55f2aef4077ef7e1990ddd 17165 postgresql-17_17.7-0+deb13u1_amd64-buildd.buildinfo 63b7b75952f06b09a18985c44f458cad7245c0cf 16555828 postgresql-17_17.7-0+deb13u1_amd64.deb 9a2e7e7cec87b3fe056dd9fd9853c224abf33808 3000252 postgresql-client-17-dbgsym_17.7-0+deb13u1_amd64.deb e221a61196125d61c49cf8b08dc20f5c2cfd9702 2044672 postgresql-client-17_17.7-0+deb13u1_amd64.deb f92530fa985431814ec9a88d99d6c22db7cf119e 203376 postgresql-plperl-17-dbgsym_17.7-0+deb13u1_amd64.deb d1672a41f1d36a85e8cd0684b5b9745f75a8c9a6 85584 postgresql-plperl-17_17.7-0+deb13u1_amd64.deb 08a164bacee1b5d77c776f42c36ed7915c3613c4 204888 postgresql-plpython3-17-dbgsym_17.7-0+deb13u1_amd64.deb d62a056dc5ea87dfe7dce49fa9f63ac86d9acd5f 109792 postgresql-plpython3-17_17.7-0+deb13u1_amd64.deb 9a44dc3d50157d3970e2f80d353c895ad86573c1 85104 postgresql-pltcl-17-dbgsym_17.7-0+deb13u1_amd64.deb 109cbf3ec9154eeb9d60ca33cb650a99123f9957 42824 postgresql-pltcl-17_17.7-0+deb13u1_amd64.deb a5ea70fd2adc79f8da32b7ecb033078141b7ccbc 56064 postgresql-server-dev-17-dbgsym_17.7-0+deb13u1_amd64.deb c2d3142a0e17f97d12ff94f351bb7f5665480556 1320696 postgresql-server-dev-17_17.7-0+deb13u1_amd64.deb Checksums-Sha256: 73f412f8f427c9170268db0737da147171a9fbba5edcf6c22aef3e0682e01833 16500 libecpg-compat3-dbgsym_17.7-0+deb13u1_amd64.deb fe3aa4392bc39b308e3cd3ece47da90405e7ddc0b077bbb4ea58dc7b7f658108 16844 libecpg-compat3_17.7-0+deb13u1_amd64.deb f75ea2e0698248d02cf3ae656beb7a26843d1234a0fd4f0810487902e1762a1f 276284 libecpg-dev-dbgsym_17.7-0+deb13u1_amd64.deb ef9e35e1eaef3bc1118d4d50e2b4409015b71740d883abcaa365ae73e391a7c3 303460 libecpg-dev_17.7-0+deb13u1_amd64.deb d396322abc370792f2e1df1979d29c3e1196b1292b96e9e44f11fe852e3f71bd 114796 libecpg6-dbgsym_17.7-0+deb13u1_amd64.deb 7525390f78873ea2a415b43c679bb0ca01542408ccbe23ab286a5dfc104300df 62160 libecpg6_17.7-0+deb13u1_amd64.deb c14411d8a419ba33fa536a36aa74a20e678f23b8d91e845628b257d047187a2c 90652 libpgtypes3-dbgsym_17.7-0+deb13u1_amd64.deb 4a0a819d36a25b173b04b0673a2dff433a8b711ba275cfab12ed4c989921191f 45428 libpgtypes3_17.7-0+deb13u1_amd64.deb c0c28c03ca2fc5d0ca83bc830f6ea55514efdf5fe82847811786a78d477d24d8 150564 libpq-dev_17.7-0+deb13u1_amd64.deb 878e6504dfc1fd21d88a9f7cc1f847c0cae024906a1c11d4129ec9c0a4b66c07 298128 libpq5-dbgsym_17.7-0+deb13u1_amd64.deb c87472bef6421c9232942a1e06de942f72ce759d2dce3ab9af2d9021602839db 227868 libpq5_17.7-0+deb13u1_amd64.deb e42a1f551e87bae9b6b3176348312ccad1e2ef2ee7f44dd4b2b01414d38b1a5b 19632368 postgresql-17-dbgsym_17.7-0+deb13u1_amd64.deb da04c8badaf776a343c122952b379599fad4e85119dce3632be56b964408e818 17165 postgresql-17_17.7-0+deb13u1_amd64-buildd.buildinfo 568672a2ec694d0139bc8f8eb3c21ea15aae28688366db8eb0d5c99156891a03 16555828 postgresql-17_17.7-0+deb13u1_amd64.deb f4f524c40f7628f093cce10b0e2312aeeaa37e9ebd2e925b73d0871c3d965813 3000252 postgresql-client-17-dbgsym_17.7-0+deb13u1_amd64.deb 18a36be98cc1fb4355201ebcf6f837c540134220c6b312008774eba9767886e5 2044672 postgresql-client-17_17.7-0+deb13u1_amd64.deb b467ffeaff62445c0b88c717126c1bb5da3e8af1f31f7181b72ed11bbcbf9dc4 203376 postgresql-plperl-17-dbgsym_17.7-0+deb13u1_amd64.deb abb001482e8dbfa4a2b2c11bb1fea7ccfee20b5b4e41a67d5e2e242ab16e3935 85584 postgresql-plperl-17_17.7-0+deb13u1_amd64.deb 53c883c314b75f09ee811899f60ec9ab52a8236c5a3ac150891c3356716b532f 204888 postgresql-plpython3-17-dbgsym_17.7-0+deb13u1_amd64.deb d16aeeabb9e5a0e2c4f94a45fd027d7e855509ffd8b91a49fce36add9d832bda 109792 postgresql-plpython3-17_17.7-0+deb13u1_amd64.deb 96dbe9a7e8ba96cd23a48f5c167a719c5bdec77dd0866f6155c885025ac72417 85104 postgresql-pltcl-17-dbgsym_17.7-0+deb13u1_amd64.deb 71c4bfe1595345cb8946fdf7fa648579f283964d861d4a6dd84770877c448a60 42824 postgresql-pltcl-17_17.7-0+deb13u1_amd64.deb 0395af17d7b8fa0b9bed9f5f619b115cb67f9744fb05db2e4ae27068fa3fa22f 56064 postgresql-server-dev-17-dbgsym_17.7-0+deb13u1_amd64.deb 8ad420e5fe8df1a9b86c81b38cfb1892fea2758da8248fd97f8991f614acdd3e 1320696 postgresql-server-dev-17_17.7-0+deb13u1_amd64.deb Files: b5ec9775c24a945e0658b580e7be81ff 16500 debug optional libecpg-compat3-dbgsym_17.7-0+deb13u1_amd64.deb 7cb7d4d346b6630b96711d6edf8a90df 16844 libs optional libecpg-compat3_17.7-0+deb13u1_amd64.deb b94661bce4b57f7b7c7230ff5dca309f 276284 debug optional libecpg-dev-dbgsym_17.7-0+deb13u1_amd64.deb 7592e602d8a2893296684d3b50475eef 303460 libdevel optional libecpg-dev_17.7-0+deb13u1_amd64.deb 4341d49c8187b93bc6d881e801a1f534 114796 debug optional libecpg6-dbgsym_17.7-0+deb13u1_amd64.deb 09f4d75b3447030761162818e5c34255 62160 libs optional libecpg6_17.7-0+deb13u1_amd64.deb 60801e606eb17c8323de11553add6d96 90652 debug optional libpgtypes3-dbgsym_17.7-0+deb13u1_amd64.deb 505794cfb67f5c4fa2326f1691a4bc6a 45428 libs optional libpgtypes3_17.7-0+deb13u1_amd64.deb 8b9a67ec649fc75d40bff5fa7abf4a67 150564 libdevel optional libpq-dev_17.7-0+deb13u1_amd64.deb 82b5c6114692321e5925bb6a634ac86f 298128 debug optional libpq5-dbgsym_17.7-0+deb13u1_amd64.deb 3cd57418de0d9a3a1d7915e25f672572 227868 libs optional libpq5_17.7-0+deb13u1_amd64.deb 0aea5b892d6cd622e3fd63e8d9b54c41 19632368 debug optional postgresql-17-dbgsym_17.7-0+deb13u1_amd64.deb 5fca13d9168b00103a9d3e47a9790bd6 17165 database optional postgresql-17_17.7-0+deb13u1_amd64-buildd.buildinfo b944edb552a3cfe27f8bbe4f1c955a2f 16555828 database optional postgresql-17_17.7-0+deb13u1_amd64.deb fba540f2d155429737c9b4a34823d2ba 3000252 debug optional postgresql-client-17-dbgsym_17.7-0+deb13u1_amd64.deb 665971e2a30b3bee73c95b60e7336096 2044672 database optional postgresql-client-17_17.7-0+deb13u1_amd64.deb 0eef38ad6a1b3e45746d8a2b70d88397 203376 debug optional postgresql-plperl-17-dbgsym_17.7-0+deb13u1_amd64.deb d5d9c6f5c1029768d10904250cef85e1 85584 database optional postgresql-plperl-17_17.7-0+deb13u1_amd64.deb 6484b969559cd35c47728cbe6e74397f 204888 debug optional postgresql-plpython3-17-dbgsym_17.7-0+deb13u1_amd64.deb 63533c33e4b4da5982da3b65b115d935 109792 database optional postgresql-plpython3-17_17.7-0+deb13u1_amd64.deb 68324f594d7649a5ca8402a1936c58cf 85104 debug optional postgresql-pltcl-17-dbgsym_17.7-0+deb13u1_amd64.deb 7308696ef6376c51042eaeda21d176b6 42824 database optional postgresql-pltcl-17_17.7-0+deb13u1_amd64.deb 41057be5c381ad4558c8e9a89287aef5 56064 debug optional postgresql-server-dev-17-dbgsym_17.7-0+deb13u1_amd64.deb e3f604f310c79b1e8cfbb3e25d287444 1320696 libdevel optional postgresql-server-dev-17_17.7-0+deb13u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEnw0rdzqckKx6dwRTEbCLukZn24oFAmlUUPwACgkQEbCLukZn 24ohng/8Dx+9gSBMmGL6XCMT6Q6kn5oRotgDgldWSLr4hBRmfnHftJPX5/BUTYU7 PJzpkRBHZ4VXSYZKljyi8/aqUcq/X+vY1/72TRZnjFiXodH/yur9VEe1WEYCLQWL GENpxrv8HB5QcBbKe7vNqBerv1ri6lfPCDDgPGaIhe5z9heaOj8sKJkn+7NP+K5j eazFMkmaILIXipZYbpVYgzbwhd+NMJiK8ZEm4TS4E2GTiAE713FPncywLbrFXBUD 3TdRcbZP8wOFznT7dl0kUhkeVuMYMxluoLaVkL5y/OBvE8zA9Y0T3JBeB266p9xw 3WQlDnyt5oAIChhd7Tt7t1ZBru4zNwB1U7eDYvjDbEsD0JWMP9oSzxyKyr2HlUug y9wI3vQI0P6bQjpVHkErPF8KDSCqyeAij8dwaKDiDq2Fzo5WbZY4PzjlvlGekVj4 S8Xh4TBW/w+ZdlybJfL+5BixtLvCljd5yYIznbvos0QakkDOfTdod0iaPyFF/gqL x8omFPAUilTZLEjMwdtE5nAujQwIl2ka7oeBR9f3DS1pYruyPWs4u0R5qVnBMKP1 gcx2ZcUAFXegdAnaqFCLW7p5eL8soZx0/wJsjpEahxjJOiLjK7ekw3QFXg+b/7tu N/NkHarGNcH69VIe5MPfgP9e7ZpmTDVgAklE6uUZtP01Nk+J7dw= =BMa5 -----END PGP SIGNATURE-----