-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 12 Nov 2019 15:00:36 +0100 Source: postgresql-common Binary: postgresql-common postgresql-client-common postgresql-server-dev-all postgresql postgresql-client postgresql-doc postgresql-contrib postgresql-all Architecture: source Version: 181+deb9u3 Distribution: stretch-security Urgency: medium Maintainer: Debian PostgreSQL Maintainers <pkg-postgresql-public@lists.alioth.debian.org> Changed-By: Christoph Berg <myon@debian.org> Description: postgresql - object-relational SQL database (supported version) postgresql-all - metapackage depending on all PostgreSQL server packages postgresql-client - front-end programs for PostgreSQL (supported version) postgresql-client-common - manager for multiple PostgreSQL client versions postgresql-common - PostgreSQL database-cluster manager postgresql-contrib - additional facilities for PostgreSQL (supported version) postgresql-doc - documentation for the PostgreSQL database management system postgresql-server-dev-all - extension build tool for multiple PostgreSQL versions Changes: postgresql-common (181+deb9u3) stretch-security; urgency=medium . * pg_ctlcluster: Drop privileges before creating socket and stats temp directories outside /var/run/postgresql. The default configuration is not affected by this change. Users with directories on volatile storage (tmpfs) in other locations have to make sure the parent directory is writable for the cluster owner. (CVE-2019-3466, discovered by Rich Mirch) Checksums-Sha1: e68c3f97d483c1a21547ff0d109867e1c79f1da1 2353 postgresql-common_181+deb9u3.dsc f83a995ceddbc5f5118acd728a7062886b1e53c1 202296 postgresql-common_181+deb9u3.tar.xz Checksums-Sha256: d28b756107e6dfad8e980ac569d6e660bfee0ef28af55e9cfbb8aedcbe77bb7c 2353 postgresql-common_181+deb9u3.dsc cc7912aa71a3e0301e3f6e966b885e7fd045d90022f2357ed51eceed36472bbb 202296 postgresql-common_181+deb9u3.tar.xz Files: 6659ec753694d8a5867ac8c225615b5e 2353 database optional postgresql-common_181+deb9u3.dsc fc422d3745952ad8bff9fdf8c6fd9806 202296 database optional postgresql-common_181+deb9u3.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEXEj+YVf0kXlZcIfGTFprqxLSp64FAl3Mc38ACgkQTFprqxLS p66hUw//bN9gWrwKNdX4NadKrkgfXS6SZxmH+SfYanBcm7mI6yHSRvqfDGOzZzO2 wcJRTidQ8S5jBese+51bahfxEyhVx9bmoW0LCfQ2tcUCP8EpSi+Ve3DRKGdCSpsF iQd3x21BWVxzAXV/TReFRFrHZTFwPTPmoV7iFxXEk/Ic0UrWtBrx59pMbZC+N4pW nRa3P73j9aJs6X9Ldd2L/BDHAqOP8iUGzrG2IpZY7pwPlpWiYFlStZoZa+Z7/fXr oZjYjJOYqiggEoCjhMZHPA1+KgprE9LqYWTn55I4isz+8tSzQip6M2WzFRz1reAM EtuI5g4xPwjdMCQ4J3MX+1ItmQodRg1+hksaB+r6hHKXIkFc/fPuYZcFk4NPUs3R dvfLo7tHgrYRW6/9GYA0nlIkx/UdblpDvVA6tV76rSQCLfghKoOidgxBvzPbSVUH BpMLvgWZsI/5+yg7O90WgJdwePs5C0rk1TlvJMiGjc22g2i4cMLtpL04mrjmldnr aKhAd9vlFxIcoF486nLoRZcirVi83PaB3jCSmxTGh5elPRuhTbKQDci7Q6z79IBD odoX6vcVQ6xs0Dt7fgCEgduy535sKaPubRwqOHJqnJWUU17qjV/f669QmR58MmEN cNboxpNPuexs7lWVYnGIfDrpYTLkkhZkNkLG3oKdZoxy/TzWbwI= =ky6B -----END PGP SIGNATURE-----