-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 25 Dec 2025 19:03:31 +0100 Source: postgresql-17 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-17 postgresql-17-dbgsym postgresql-client-17 postgresql-client-17-dbgsym postgresql-plperl-17 postgresql-plperl-17-dbgsym postgresql-plpython3-17 postgresql-plpython3-17-dbgsym postgresql-pltcl-17 postgresql-pltcl-17-dbgsym postgresql-server-dev-17 postgresql-server-dev-17-dbgsym Architecture: arm64 Version: 17.7-0+deb13u1 Distribution: trixie Urgency: medium Maintainer: arm Build Daemon (arm-ubc-02) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 17 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-17 - The World's Most Advanced Open Source Relational Database postgresql-client-17 - front-end programs for PostgreSQL 17 postgresql-plperl-17 - PL/Perl procedural language for PostgreSQL 17 postgresql-plpython3-17 - PL/Python 3 procedural language for PostgreSQL 17 postgresql-pltcl-17 - PL/Tcl procedural language for PostgreSQL 17 postgresql-server-dev-17 - development files for PostgreSQL 17 server-side programming Changes: postgresql-17 (17.7-0+deb13u1) trixie; urgency=medium . * New upstream version 17.7. . + Check for CREATE privileges on the schema in CREATE STATISTICS (Jelte Fennema-Nio) . This omission allowed table owners to create statistics in any schema, potentially leading to unexpected naming conflicts. . The PostgreSQL Project thanks Jelte Fennema-Nio for reporting this problem. (CVE-2025-12817) . + Avoid integer overflow in allocation-size calculations within libpq (Jacob Champion) . Several places in libpq were not sufficiently careful about computing the required size of a memory allocation. Sufficiently large inputs could cause integer overflow, resulting in an undersized buffer, which would then lead to writing past the end of the buffer. . The PostgreSQL Project thanks Aleksey Solovev of Positive Technologies for reporting this problem. (CVE-2025-12818) Checksums-Sha1: 1094081bbea2acd68723dffdf0dd3c8f8ff8cb04 16980 libecpg-compat3-dbgsym_17.7-0+deb13u1_arm64.deb f8ce5be7c727ed1fd9490dea92b7802d501331af 16896 libecpg-compat3_17.7-0+deb13u1_arm64.deb 157d043a13c5273592bc00e887aab1b8200b6682 268656 libecpg-dev-dbgsym_17.7-0+deb13u1_arm64.deb f6e9f7ddfd5704eb3fcf4a217134d71c82667d2e 285460 libecpg-dev_17.7-0+deb13u1_arm64.deb ca83939b5d06a74329064db8ee0da5db10af95e6 114872 libecpg6-dbgsym_17.7-0+deb13u1_arm64.deb b8619ae717a9a44360d59f4e84088e70e448dd60 59720 libecpg6_17.7-0+deb13u1_arm64.deb 6ec909a0b6c83d9a00da6b2e18686291b079feb6 89324 libpgtypes3-dbgsym_17.7-0+deb13u1_arm64.deb 93b4d9351533af0782099d0129fa106b8222f620 43260 libpgtypes3_17.7-0+deb13u1_arm64.deb 0d4c4c5523abd6dd59ce37067c7f794d740ed310 148024 libpq-dev_17.7-0+deb13u1_arm64.deb 139204b8cb6b5eb175f3f8242c6290331bcb55d0 296980 libpq5-dbgsym_17.7-0+deb13u1_arm64.deb bb6a96f7fcbf5b49513218e394e26a6e9c255839 220920 libpq5_17.7-0+deb13u1_arm64.deb 552b90f2991eaa7c7ebd49038abdd644382db70c 19547612 postgresql-17-dbgsym_17.7-0+deb13u1_arm64.deb 542dfafc9893fef5bcadd8a2616526cca3263ced 17133 postgresql-17_17.7-0+deb13u1_arm64-buildd.buildinfo e1992f06893e718aac3d6062d0068f4df09ae067 16069860 postgresql-17_17.7-0+deb13u1_arm64.deb b789b56b57b7c4bcefa8910ee06d49d20691f001 3016364 postgresql-client-17-dbgsym_17.7-0+deb13u1_arm64.deb 0ade0cd975234634c36f75bba8c9cb20b9b7fc57 1991576 postgresql-client-17_17.7-0+deb13u1_arm64.deb 934e5afbdc3afc9a1ecfcb1f37a4ffb824303a7d 198200 postgresql-plperl-17-dbgsym_17.7-0+deb13u1_arm64.deb e7b73654f39ed32bb90e4c8494c99e47c1f6f4be 82100 postgresql-plperl-17_17.7-0+deb13u1_arm64.deb 86cf991541320cb1f28335a3da32116e1e8775ef 200760 postgresql-plpython3-17-dbgsym_17.7-0+deb13u1_arm64.deb 064e88ea453f368a902c4fe3cb69f04988ec1d5b 106096 postgresql-plpython3-17_17.7-0+deb13u1_arm64.deb 352a1b7d40ea0f2e97d0ca12602dba1780090a0c 84540 postgresql-pltcl-17-dbgsym_17.7-0+deb13u1_arm64.deb d9776ca3b5330f28063cd297bb933e4e576f7570 41352 postgresql-pltcl-17_17.7-0+deb13u1_arm64.deb 5632948159d97a8dd129320e68291fb13844b31e 56548 postgresql-server-dev-17-dbgsym_17.7-0+deb13u1_arm64.deb b24096931b2bd06f1e6239fbe3fc63017997920e 1310668 postgresql-server-dev-17_17.7-0+deb13u1_arm64.deb Checksums-Sha256: cb7074a56045634c782a30d76159ba823b96689ee10ca3232f1ae9429c8a82bb 16980 libecpg-compat3-dbgsym_17.7-0+deb13u1_arm64.deb d8ffd8a11fa4e21a6ce2020b1308b7a40fe0ead8ae9aafaca7df9b9323bce550 16896 libecpg-compat3_17.7-0+deb13u1_arm64.deb ee9eb774c69d1b7f0e3e8de0e6f2d0b42ec493cc169371d653d0e82be6814b57 268656 libecpg-dev-dbgsym_17.7-0+deb13u1_arm64.deb 86d47e4dfe3b2eb6f622f0c8ecd4484a7bc87bf76a40bc54b625129774924435 285460 libecpg-dev_17.7-0+deb13u1_arm64.deb 83293a97a33a887e5eb3e4e786fdacee528777ea1c458ab422598b2e01cad307 114872 libecpg6-dbgsym_17.7-0+deb13u1_arm64.deb a58519b2058b21bbc6b38376d90e0e1924e5e116d8c37bdd406533451cab5a2c 59720 libecpg6_17.7-0+deb13u1_arm64.deb e5f72b593a61861bdfb4076a04b5c4c62999727fde59c5a35cbe8490df6c05e6 89324 libpgtypes3-dbgsym_17.7-0+deb13u1_arm64.deb e66693be8051ccf8076ceb3c3f83631f47096f440f2a546aa0d136338e1affe9 43260 libpgtypes3_17.7-0+deb13u1_arm64.deb 6fd437a7aad11ed1a17415f6aa11f6aa0b0f5b4269c111f27a8e591206780f9d 148024 libpq-dev_17.7-0+deb13u1_arm64.deb 0d9f1a97bdf744b102fdaa7ad6a964b0d5f6c04bbf0e8742f9819f12c09ef7b2 296980 libpq5-dbgsym_17.7-0+deb13u1_arm64.deb 5d0ebdd9003dea3a0a628badf1c45df23d9cadb4becf99e2af325ad183c22bac 220920 libpq5_17.7-0+deb13u1_arm64.deb 7f12a046ad961446c68ad64c1c9e8cae9176e06cdfc903e11c82c20d300e842f 19547612 postgresql-17-dbgsym_17.7-0+deb13u1_arm64.deb 8d3ea48857fe28d8d261956c0a4538f0dec187c084825d587f0029af9d5d9a7c 17133 postgresql-17_17.7-0+deb13u1_arm64-buildd.buildinfo 5026b4ca63f54300d52c38539f6a0f52615ec561bee1add8816f00f44abdb9e0 16069860 postgresql-17_17.7-0+deb13u1_arm64.deb f1c7cf44884c85659207f406f5d12b445265ce3a1ef3eb402017f7482c6e7108 3016364 postgresql-client-17-dbgsym_17.7-0+deb13u1_arm64.deb 224ea5eae7499dac81016b3257ac67df9ccbc3e58eaf10728eecc94d1ec15d46 1991576 postgresql-client-17_17.7-0+deb13u1_arm64.deb fbb1186d616df3e742044e5b8a721e8a65eddc5e21b135d74d579409edac5023 198200 postgresql-plperl-17-dbgsym_17.7-0+deb13u1_arm64.deb 21ad3ad075ade055d96f5b5609a0cc0223180edcfc8640522d9a0f2f90be727e 82100 postgresql-plperl-17_17.7-0+deb13u1_arm64.deb a37b3be08b0b7328e07ae8f995a6c4432a4b9462dd256ffcafc6dcf89ee74188 200760 postgresql-plpython3-17-dbgsym_17.7-0+deb13u1_arm64.deb 996623cebcb0b65475a6b2c72d0467d661e32edc5658515deb29d383766b5b74 106096 postgresql-plpython3-17_17.7-0+deb13u1_arm64.deb c2fdd0b69a5e23d11ce80b09e9e7eaa6c08959e5ab9cf382c3838a5f20bc2bfd 84540 postgresql-pltcl-17-dbgsym_17.7-0+deb13u1_arm64.deb 6ac4db88f85c8dc2c523b01812251b05fccd78c5bf6b3b9b1861a708739bc3ed 41352 postgresql-pltcl-17_17.7-0+deb13u1_arm64.deb f0298c230169ddc3d520954a851fdbd012788277c361528efeb5e63dbad524cf 56548 postgresql-server-dev-17-dbgsym_17.7-0+deb13u1_arm64.deb 3503a19c0526c5b071a30946a0d98f108b712e00c11a71d3fff878cb31e22f2f 1310668 postgresql-server-dev-17_17.7-0+deb13u1_arm64.deb Files: 3f044a2a8a798862b067c61d429ae82f 16980 debug optional libecpg-compat3-dbgsym_17.7-0+deb13u1_arm64.deb 30385b3d8d1ee0214fa49fd635b30d24 16896 libs optional libecpg-compat3_17.7-0+deb13u1_arm64.deb f549ea5a26a7d259402d40f8c6cadacf 268656 debug optional libecpg-dev-dbgsym_17.7-0+deb13u1_arm64.deb e362a5123b8a188b66a57f3b9c2e45d7 285460 libdevel optional libecpg-dev_17.7-0+deb13u1_arm64.deb bd48fe6844a5f7601ab5704905f314b5 114872 debug optional libecpg6-dbgsym_17.7-0+deb13u1_arm64.deb adb0641cff4f826e679f21b8fb723860 59720 libs optional libecpg6_17.7-0+deb13u1_arm64.deb 88fc78e3ea0e30cba859d653fdbea375 89324 debug optional libpgtypes3-dbgsym_17.7-0+deb13u1_arm64.deb a2e011a5e1101f14845842e0a1207d51 43260 libs optional libpgtypes3_17.7-0+deb13u1_arm64.deb 2076534ce1116e8b7c9501e089bd86fa 148024 libdevel optional libpq-dev_17.7-0+deb13u1_arm64.deb 0b1949248eae9c4849fe538d1ffb009a 296980 debug optional libpq5-dbgsym_17.7-0+deb13u1_arm64.deb b6492d6db054a4fcf97b98224c715732 220920 libs optional libpq5_17.7-0+deb13u1_arm64.deb 64b98fe2db64a547190741ddb18a94ff 19547612 debug optional postgresql-17-dbgsym_17.7-0+deb13u1_arm64.deb ee7c4f3fdb8bab1ef4c630140ac5b11c 17133 database optional postgresql-17_17.7-0+deb13u1_arm64-buildd.buildinfo 7b2481be4239df92cdfb22bf65a7e69d 16069860 database optional postgresql-17_17.7-0+deb13u1_arm64.deb 07136caf75fe5ca2203ab50c0a378355 3016364 debug optional postgresql-client-17-dbgsym_17.7-0+deb13u1_arm64.deb ef0b24404c3e5deded76ea566b653406 1991576 database optional postgresql-client-17_17.7-0+deb13u1_arm64.deb f48506ee1c21b7f6aaf5a979d62fd692 198200 debug optional postgresql-plperl-17-dbgsym_17.7-0+deb13u1_arm64.deb d0cfa2310b815612e60c1d187730d339 82100 database optional postgresql-plperl-17_17.7-0+deb13u1_arm64.deb baf48f5bed2fdde5f784984d20f6b5ec 200760 debug optional postgresql-plpython3-17-dbgsym_17.7-0+deb13u1_arm64.deb fb047fabb339500e747086534858e09a 106096 database optional postgresql-plpython3-17_17.7-0+deb13u1_arm64.deb 2b1e0aa1a5becdfbf6f2357fdafb6dae 84540 debug optional postgresql-pltcl-17-dbgsym_17.7-0+deb13u1_arm64.deb 29642b1954f1e4781364ca2dbc3a16b8 41352 database optional postgresql-pltcl-17_17.7-0+deb13u1_arm64.deb a1d1761352f5dbfaf66b6b6df563de39 56548 debug optional postgresql-server-dev-17-dbgsym_17.7-0+deb13u1_arm64.deb ef02ef076f3adfc530dcd441037d4095 1310668 libdevel optional postgresql-server-dev-17_17.7-0+deb13u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEbIns2iWsAAdAqh2MS/ZIXkV8oLAFAmlUU/AACgkQS/ZIXkV8 oLCf7A//UKJYpG9K1F0jUci5g4M5G6wdKWEAk0HjQFVi2t4sj8DG+xHZpzg1ZkpZ tPGRyGZ9H39vtzBNAQjnJdh/SNt5qbMSOWdJdGQTjrllexayCQwp76zQJ6L4iiRc rb1+WwJxHEKNzlZxik3ME/eyOCWpxjsZNHxQKtR84UEZTaQVJwkzrQtCG/KMgXac NE2nBbZZokPwOq66/CLhH34gKN8ksZBnH+UO3lQdwgWd3FtfQPItnMxgbbpIA4In 5eK1Yg7VF6Godb1nidEX6y3tzClkS1xMeQP8mWMl1UVe1VlxGIX9GlNyEUGSo0ys ujMuHVp6ap8q8mDaazQmTmb7DU362rij828BAx/3OEnzTvfDogwKAC/ERaKRt60H uhefSiYqxDFv7bI6ACqlQm8xYiERtLYgATZCMT3uQX+zKXG9qwxlxH6gkS7Fmvaf Us6hccw1j8H7ahqhxOlDu2syyO5z+JjUQ7Mi98oJIyv97M7VkoaDu9/8j6uSJTv4 tioOknAQOCyQuYM5QSmSe8CPkwyvjW6DlaLswQhswasGnm3J+lmZtBLSHAUFVm0v 1DBsMgDF9uRljcxK9Glm9tUiV8Esw9IA+7OKJOB8JmORXmhC4cnyw2ACyMMXIqx6 ATTk29zVVonUxTGsmJFjbVJQhGtLwuow55Qj9m2eauSObzFLYT8= =t68Q -----END PGP SIGNATURE-----