-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 17 Apr 2025 10:21:09 +0200 Source: pgbouncer Architecture: source Version: 1.24.1-1 Distribution: unstable Urgency: medium Maintainer: Debian PostgreSQL Maintainers <team+postgresql@tracker.debian.org> Changed-By: Christoph Berg <myon@debian.org> Closes: 1103394 Changes: pgbouncer (1.24.1-1) unstable; urgency=medium . [ Christoph Berg ] * B-D on libsystemd-dev on Linux only. . [ Bradford D. Boyle ] * New upstream version 1.24.1. - Security * Fix CVE-2025-2291: Account for VALID UNTIL in auth_query. (Closes: #1103394) - Fixes * Fix PAM support by reverting pam authentication support in HBA file. * Fix bug when decrementing user connection count. This was included in the tag of 1.24.0 on GitHub, but the release tarball did not contain this fix. * Add test_load_balance_hosts.py to the tarball. * Fix issues with tests to allow them to be run by Debian packagers. - Docs * Update auth_query example to set a safe search_path. Checksums-Sha1: 24253d2b3f8c4029efbf78e783be623eff1afea5 2504 pgbouncer_1.24.1-1.dsc e25d554d38c3dbacbfc33cc2f2e3c8faef06634f 717796 pgbouncer_1.24.1.orig.tar.gz d292d08418d4079f385db0e4bbbfb1333e552eb4 11460 pgbouncer_1.24.1-1.debian.tar.xz Checksums-Sha256: 0a0b923ad01462e52253ba9f79d8f9954f7d9d9f66fe30d18ec5781a0fda7dfe 2504 pgbouncer_1.24.1-1.dsc da72a3aba13072876d055a3e58dd4aba4a5de4ed6148e73033185245598fd3e0 717796 pgbouncer_1.24.1.orig.tar.gz b105e8ba570b8c1edee4ff333bb4565abff94b8c8ddae68f05f320a866c55e61 11460 pgbouncer_1.24.1-1.debian.tar.xz Files: 9949912e530d022b597836c5dd65eda7 2504 database optional pgbouncer_1.24.1-1.dsc 434cbb2db9034d358dddf525e0e5a3dd 717796 database optional pgbouncer_1.24.1.orig.tar.gz d27208af69dc492b3e238d508ca4956f 11460 database optional pgbouncer_1.24.1-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXEj+YVf0kXlZcIfGTFprqxLSp64FAmgAvVMACgkQTFprqxLS p65MtBAAj0HIFg3v+Bs2abu2gLmELGXJaKoJAqo/zBPptmz99HtJSFNbsP7gvfPU a+apJ10WLOoXFartGiMQxUoKQ1hdwwbAIC1aU3Cg0lmMDnDI+dhDCzQe0oFHLyH6 NFMmhFNlwGg1aPN+zJpWtWvmU4M31djbnnbAp4Ec8HNF7EndT/OdfUQTAl5JHgia qLrrrRX9KKgHPgYuJQJ/dxOdkPxWZFFRql5TndET0LEF0Syyj1n44rp9PegKRn8T ysqLtPv1LYETdW3tmexCfiv2jQgCFehAK4X0hiUlLZss+ALeALdhf6cBmbLJEABk ACXenVyCjmlAshrV0czkZO+LulKd4qmbU9cc0yAzMzy79KY9PL6ZMUh3+2GTeUyL gYZ6+mZOhXe4N4y6f62fLjQPNZSTbtmO8VAA5OkxmxBOI4AlBmGndZ061P06idpj gDeStB3KejlC5jt67zBpMMntIpKWCG4uKT7DvWvXHvCk6fR0nrxY0YLiUQ8tBORQ hsX8rb3jiMmjtShjAZFLzdcyuHosYTFeqSjZ5BFXPtFsTQcGCJoQiV/9qoh9zhEx rqbPQObNiLlA9BnLJx+liYlYMHes4k7y4A2i+RcOxTqS4islpwS1vVdEhGNZZx7x PfwHjVoL2UH+ouPQ9XIJoJ4nu1h+6qsL6SKTpQiw+jq+BsOrsRU= =KnQK -----END PGP SIGNATURE-----