-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 25 Dec 2025 19:03:31 +0100 Source: postgresql-17 Binary: libecpg-compat3 libecpg-compat3-dbgsym libecpg-dev libecpg-dev-dbgsym libecpg6 libecpg6-dbgsym libpgtypes3 libpgtypes3-dbgsym libpq-dev libpq5 libpq5-dbgsym postgresql-17 postgresql-17-dbgsym postgresql-client-17 postgresql-client-17-dbgsym postgresql-plperl-17 postgresql-plperl-17-dbgsym postgresql-plpython3-17 postgresql-plpython3-17-dbgsym postgresql-pltcl-17 postgresql-pltcl-17-dbgsym postgresql-server-dev-17 postgresql-server-dev-17-dbgsym Architecture: i386 Version: 17.7-0+deb13u1 Distribution: trixie Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-02) Changed-By: Christoph Berg Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 17 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql-17 - The World's Most Advanced Open Source Relational Database postgresql-client-17 - front-end programs for PostgreSQL 17 postgresql-plperl-17 - PL/Perl procedural language for PostgreSQL 17 postgresql-plpython3-17 - PL/Python 3 procedural language for PostgreSQL 17 postgresql-pltcl-17 - PL/Tcl procedural language for PostgreSQL 17 postgresql-server-dev-17 - development files for PostgreSQL 17 server-side programming Changes: postgresql-17 (17.7-0+deb13u1) trixie; urgency=medium . * New upstream version 17.7. . + Check for CREATE privileges on the schema in CREATE STATISTICS (Jelte Fennema-Nio) . This omission allowed table owners to create statistics in any schema, potentially leading to unexpected naming conflicts. . The PostgreSQL Project thanks Jelte Fennema-Nio for reporting this problem. (CVE-2025-12817) . + Avoid integer overflow in allocation-size calculations within libpq (Jacob Champion) . Several places in libpq were not sufficiently careful about computing the required size of a memory allocation. Sufficiently large inputs could cause integer overflow, resulting in an undersized buffer, which would then lead to writing past the end of the buffer. . The PostgreSQL Project thanks Aleksey Solovev of Positive Technologies for reporting this problem. (CVE-2025-12818) Checksums-Sha1: a25ff4a6c552be004403d2fdf94c0aeef7284982 14324 libecpg-compat3-dbgsym_17.7-0+deb13u1_i386.deb 0ddb9b244a4f74be89c5710c0d30c4632f0a7ef0 17460 libecpg-compat3_17.7-0+deb13u1_i386.deb cc656c699a8e03a3b04ce3bf21f28506a28a11dc 274116 libecpg-dev-dbgsym_17.7-0+deb13u1_i386.deb 4db2563028cbda89dab40ed083ca1575414557a3 311432 libecpg-dev_17.7-0+deb13u1_i386.deb f66ae7765e5acb55c2395503d2965036d6a58f71 102912 libecpg6-dbgsym_17.7-0+deb13u1_i386.deb 9366f3aa0e7de50d546de250f7dddca9694390be 66004 libecpg6_17.7-0+deb13u1_i386.deb 06a107b3143282ef4338f9a4434db5a39512a123 83412 libpgtypes3-dbgsym_17.7-0+deb13u1_i386.deb 932a165a463326f61cd438a7e1cd369fa5109328 47676 libpgtypes3_17.7-0+deb13u1_i386.deb 36b5d13ce397a4ad5b8cfc593977e37ce420bfda 160744 libpq-dev_17.7-0+deb13u1_i386.deb a134a7e6c84e2379144c1dcf030ea1703f6d28ba 260732 libpq5-dbgsym_17.7-0+deb13u1_i386.deb 47246431e6cf5597fc640180ad211dc6d9beb6db 237984 libpq5_17.7-0+deb13u1_i386.deb 74b5bb9ad4023d9661769db5ac09dc560f5afb4b 17688984 postgresql-17-dbgsym_17.7-0+deb13u1_i386.deb 02c6385bac0df2696a2257b2cbf24dcd25c223ee 17003 postgresql-17_17.7-0+deb13u1_i386-buildd.buildinfo 62dd86187e408be17db2f764c3b4572552bb9e39 16808472 postgresql-17_17.7-0+deb13u1_i386.deb 875347a9667faf15f27ad9ed25bd211ca74952c6 2579664 postgresql-client-17-dbgsym_17.7-0+deb13u1_i386.deb 32ac5a9fe91414c5c52a8ee56c15cbfcb9f683b3 2072128 postgresql-client-17_17.7-0+deb13u1_i386.deb f949a07e341b5ad6861f84ca35f2dc519302d1a0 190156 postgresql-plperl-17-dbgsym_17.7-0+deb13u1_i386.deb 829c56ff14ebbcecb9d30c7cf48a6bc5db2a9ea8 88652 postgresql-plperl-17_17.7-0+deb13u1_i386.deb 60cc39b97b7d3d7af072f16e376d7463361a1dfb 187712 postgresql-plpython3-17-dbgsym_17.7-0+deb13u1_i386.deb 8aecb854f01e53d55d4e6a528ecb43fc0961cb9b 112708 postgresql-plpython3-17_17.7-0+deb13u1_i386.deb d0af6359bafa62b9167562e32be28694f3c6fb09 78132 postgresql-pltcl-17-dbgsym_17.7-0+deb13u1_i386.deb bb330d75f7aafdbdf94da2fc9c5544feff8709b8 44376 postgresql-pltcl-17_17.7-0+deb13u1_i386.deb 9e5d179dc425ede1577aab56fadd2380e8087e31 53984 postgresql-server-dev-17-dbgsym_17.7-0+deb13u1_i386.deb 86e129c004ad447f918ad3e0f489416a8082bd2d 1337140 postgresql-server-dev-17_17.7-0+deb13u1_i386.deb Checksums-Sha256: b3cbd72e4a2ab7315f8416f2f236e606cb9ac04bbf4be6ec65cb59c76e6f2cf7 14324 libecpg-compat3-dbgsym_17.7-0+deb13u1_i386.deb 38d3e79a4716548278e818c545dcfa61db04db91db478de604444dd21470993c 17460 libecpg-compat3_17.7-0+deb13u1_i386.deb e9f46050dee693cda00051df46fc1dc89b4644e3d2ced96262934c14c7792123 274116 libecpg-dev-dbgsym_17.7-0+deb13u1_i386.deb 17b744fa892738900a2d59bd3b829c86ee9cf5912289d87a515e74d848f884c6 311432 libecpg-dev_17.7-0+deb13u1_i386.deb 2a1debd7bc7b84ac4b3315e7e0f6f561c03be97fb1af38e769114dbba1978139 102912 libecpg6-dbgsym_17.7-0+deb13u1_i386.deb 50402b2b425f01159498d79b40ceb7fcba4f079bb485b1d298443ecda896a57a 66004 libecpg6_17.7-0+deb13u1_i386.deb 44eb25de23352cf191f50b954283e51374368c659c1059af13982716c901b20f 83412 libpgtypes3-dbgsym_17.7-0+deb13u1_i386.deb 991ec6b5fdf18e08441e4fab800d5e7d58f3e8b414fcf609dec2ebda0c52f6f2 47676 libpgtypes3_17.7-0+deb13u1_i386.deb 482f1b873a3c8129bc23479f7e50f5433160be25c979caf8b67a61a9ef75dc88 160744 libpq-dev_17.7-0+deb13u1_i386.deb ce4032815eb473fd64771a4af58664125475d53698d0381985ca5071aa718670 260732 libpq5-dbgsym_17.7-0+deb13u1_i386.deb f2b50746645670c2f5d211b3345fd48ae190b1111ecd56f6a0b9af799a616515 237984 libpq5_17.7-0+deb13u1_i386.deb c51f4f6ad2a8567477c22b1853ef9ed466dbbbe17bcc7a6a08f82b2ebcf7d47e 17688984 postgresql-17-dbgsym_17.7-0+deb13u1_i386.deb 3f5446d7cbb45c6456da4d3ff0a8c83bfa0df8ab4c1d8695055379d067a08cf3 17003 postgresql-17_17.7-0+deb13u1_i386-buildd.buildinfo 2012c3bef3074e645ba63ba38b53c3bd318ba8fb77c6b0d93eb2c1e5894b654b 16808472 postgresql-17_17.7-0+deb13u1_i386.deb e328130ba649f52b3fa6e5448f87ac6c71bef12fc2a049103dd73466c5ddbcfe 2579664 postgresql-client-17-dbgsym_17.7-0+deb13u1_i386.deb 68ff514551cf8cdf9c35950c89bb6ef24bdf49e4d2fc68489731add313e16cee 2072128 postgresql-client-17_17.7-0+deb13u1_i386.deb 0ca11950bbbc00cc86ffb27252a9d70407dd8f332dac349e0292b982baf8b636 190156 postgresql-plperl-17-dbgsym_17.7-0+deb13u1_i386.deb d91ea57ff55cf6702698f32ef65c9b2d7db6dc2287f19dbeb8c52513d47ba01f 88652 postgresql-plperl-17_17.7-0+deb13u1_i386.deb 958ccc41e7516bf1e9eeab18ec4f6b993b2b38165b2f68acbbd461c82af85dc0 187712 postgresql-plpython3-17-dbgsym_17.7-0+deb13u1_i386.deb d833571f1573da106d4ec96a3eda08470aa47c24b19396f1e48afe09354cfb0e 112708 postgresql-plpython3-17_17.7-0+deb13u1_i386.deb 90acb34b1f509fef146580a23f271c2a546e2fd20f11deb9009da7a2a2f22014 78132 postgresql-pltcl-17-dbgsym_17.7-0+deb13u1_i386.deb 3e0205c290224acf5d35b054aa5256cdb2a9943455347156dca1476b4791c8ba 44376 postgresql-pltcl-17_17.7-0+deb13u1_i386.deb 92b71c9be47e9345e789ed8b4bc805acba12868333f91a315294ec4835eb1987 53984 postgresql-server-dev-17-dbgsym_17.7-0+deb13u1_i386.deb 30a99ab61f9ac955dc20d22671369f5051fb8c638fee06333f527294a24473c6 1337140 postgresql-server-dev-17_17.7-0+deb13u1_i386.deb Files: 1c9ecb1c7609781776851ebf5ff754ec 14324 debug optional libecpg-compat3-dbgsym_17.7-0+deb13u1_i386.deb 764a9f6236aad74a9f1525f4cbb3ae79 17460 libs optional libecpg-compat3_17.7-0+deb13u1_i386.deb ec2b3e2225f2b703a02a8cb1a17dbff9 274116 debug optional libecpg-dev-dbgsym_17.7-0+deb13u1_i386.deb 189ee782f29aa47f4c8d56205d00e2a0 311432 libdevel optional libecpg-dev_17.7-0+deb13u1_i386.deb c0df755a54bebe718b0906cb5307d3cc 102912 debug optional libecpg6-dbgsym_17.7-0+deb13u1_i386.deb 7960015c25ae36004ae75b6da3f45862 66004 libs optional libecpg6_17.7-0+deb13u1_i386.deb c7009156738ca06e47065027f14075a5 83412 debug optional libpgtypes3-dbgsym_17.7-0+deb13u1_i386.deb db41d97431a2281fe9bdeadea1093ccb 47676 libs optional libpgtypes3_17.7-0+deb13u1_i386.deb e621b755ff028fa225944d4f196d82ad 160744 libdevel optional libpq-dev_17.7-0+deb13u1_i386.deb 02706f4c4a49fb191afa0a2998c11d55 260732 debug optional libpq5-dbgsym_17.7-0+deb13u1_i386.deb 9b2fc9bc94ecdcad911b39ab581633b2 237984 libs optional libpq5_17.7-0+deb13u1_i386.deb 4c66c8c35b6ed29ebb52089424a86b55 17688984 debug optional postgresql-17-dbgsym_17.7-0+deb13u1_i386.deb 43d1c96d8e8dcbde8a70222c8eb1e665 17003 database optional postgresql-17_17.7-0+deb13u1_i386-buildd.buildinfo 8792cedee090c0999098c396d89a6790 16808472 database optional postgresql-17_17.7-0+deb13u1_i386.deb 17892058a4d1b524987d88b7aaf7d041 2579664 debug optional postgresql-client-17-dbgsym_17.7-0+deb13u1_i386.deb 135a3d5696da3890bc917ecbf6487a8e 2072128 database optional postgresql-client-17_17.7-0+deb13u1_i386.deb 10979caff65a5eb8bf0c54a35fc6b4b3 190156 debug optional postgresql-plperl-17-dbgsym_17.7-0+deb13u1_i386.deb 44821ccbb9a4d6cc75d7e2f612b9baef 88652 database optional postgresql-plperl-17_17.7-0+deb13u1_i386.deb d967dd15b457494c10da84daef7e5522 187712 debug optional postgresql-plpython3-17-dbgsym_17.7-0+deb13u1_i386.deb ebc42699b7fec4b732c89ae414704664 112708 database optional postgresql-plpython3-17_17.7-0+deb13u1_i386.deb 45b789d4758768f17253d82467df98c5 78132 debug optional postgresql-pltcl-17-dbgsym_17.7-0+deb13u1_i386.deb a9485a53087b8356351c529118c9f570 44376 database optional postgresql-pltcl-17_17.7-0+deb13u1_i386.deb 17cae1632975b49633c2edc6c6608b4a 53984 debug optional postgresql-server-dev-17-dbgsym_17.7-0+deb13u1_i386.deb ba23e1d38205a0808e402dde88ec4de8 1337140 libdevel optional postgresql-server-dev-17_17.7-0+deb13u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEErwLLVsiCiGZggzpHJuP6X4A0XeIFAmlUVYAACgkQJuP6X4A0 XeJGqxAAo5rjyJzjYWtPlraWMBC8WcjAPr2FyfEyl/jdEobVOPx24M3M9j4M1pYV Yj48DMJiAocUEPccokve7yAecINpe1MS2r+6iWHaLwgmTMfxDSOjJ+Ly2b009TQG F25pvHWy1wqGC7qPmzBgsnaizH8eSNU4sghor6MUvh0oopHBCDT2T/9AiemY4wQk kQoxAmUdMkiSVDaHdCh5iGBrwD5S7SJn2c13r5Ux+BnHDSo1RRsMdGVSxu2LjABU 71ZVeZbkSKufc4Czv0bsdUJsDiUWR/XbIwk4XhJ4uxPGE5rO1Um4XaWg71C1Li+t Iwi1+D9Pxi5unfAixntmFzozQuW2VosWzv3hruFMwMt77ak3VHqjiroRvzhXujeL sPnR+zoY6bXWNR126vJf5y5q5BvSWgjlONl+Q1Ovov9wfDM15km30p1cvTWEZWXj LTW39Vci5K2a8lThm7i8dMmwsqlN3PM9aMoOGQjo2S/EP7ODPD9Zr1Ka0kC6Ih9R ILhtuGFV8N5lhiqsRCj5DGReNXdTZtftlLQtqk5qR5GQQtX5SkVR8DzTBqHbrHQw WzteDfX7ridart10J8b4VdQXrTzLMHd1EvNbV+Lch0brFEyhXh7BOoOuy38ulV/6 71X1DQef43mLzvb19mlH7IRlOiwW4uMcwbjt6RMNDHiwIOuJsCs= =UZfa -----END PGP SIGNATURE-----