-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Tue, 15 Dec 2009 12:38:18 +0100 Source: postgresql-8.1 Binary: postgresql-8.1 postgresql-pltcl-8.1 postgresql-plperl-8.1 libpgtypes2 libpq-dev libpq4 postgresql-doc-8.1 postgresql-plpython-8.1 libecpg5 libecpg-compat2 libecpg-dev postgresql-client-8.1 postgresql-contrib-8.1 postgresql-server-dev-8.1 Architecture: source i386 all Version: 8.1.19-0etch1 Distribution: oldstable-security Urgency: high Maintainer: Martin Pitt <mpitt@debian.org> Changed-By: Martin Pitt <mpitt@debian.org> Description: libecpg-compat2 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg5 - run-time library for ECPG programs libpgtypes2 - shared library libpgtypes for PostgreSQL 8.1 libpq-dev - header files for libpq4 (PostgreSQL library) libpq4 - PostgreSQL C client library postgresql-8.1 - object-relational SQL database, version 8.1 server postgresql-client-8.1 - front-end programs for PostgreSQL 8.1 postgresql-contrib-8.1 - additional facilities for PostgreSQL postgresql-doc-8.1 - documentation for the PostgreSQL database management system postgresql-plperl-8.1 - PL/Perl procedural language for PostgreSQL 8.1 postgresql-plpython-8.1 - PL/Python procedural language for PostgreSQL 8.1 postgresql-pltcl-8.1 - PL/Tcl procedural language for PostgreSQL 8.1 postgresql-server-dev-8.1 - development files for PostgreSQL 8.1 server-side programming Changes: postgresql-8.1 (8.1.19-0etch1) oldstable-security; urgency=high . * New upstream bug fix/security release: - Protect against indirect security threats caused by index functions changing session-local state. This change prevents allegedly-immutable index functions from possibly subverting a superuser's session (CVE-2009-4136). - Reject SSL certificates containing an embedded null byte in the common name (CN) field. This prevents unintended matching of a certificate to a server or client name during SSL validation (CVE-2009-4034). - Fix possible crash during backend-startup-time cache initialization. - Prevent signals from interrupting VACUUM at unsafe times. - Fix possible crash due to integer overflow in hash table size calculation. - Fix very rare crash in inet/cidr comparisons. - Ensure that shared tuple-level locks held by prepared transactions are not ignored. - Fix premature drop of temporary files used for a cursor that is accessed within a subtransaction. - Fix PAM password processing to be more robust. The previous code is known to fail with the combination of the Linux pam_krb5 PAM module with Microsoft Active Directory as the domain controller. It might have problems elsewhere too, since it was making unjustified assumptions about what arguments the PAM stack would pass to it. - Fix processing of ownership dependencies during CREATE OR REPLACE FUNCTION. - Ensure that Perl arrays are properly converted to PostgreSQL arrays when returned by a set-returning PL/Perl function. This worked correctly already for non-set-returning functions. - Fix rare crash in exception processing in PL/Python. - Make the postmaster ignore any application_name parameter in connection request packets, to improve compatibility with future libpq versions. Files: 9a2edb5a2dfe632748f7ad720c7c9ea2 1179 misc optional postgresql-8.1_8.1.19-0etch1.dsc 64185bcc279f0787017d89596ad519a0 11535709 misc optional postgresql-8.1_8.1.19.orig.tar.gz 7e87c7dba806e8f17527ecd44f3b21ad 40781 misc optional postgresql-8.1_8.1.19-0etch1.diff.gz 29989a9668481d64a22906e8a8cb39e6 1521982 doc optional postgresql-doc-8.1_8.1.19-0etch1_all.deb 64dd0ab7b06d4e3bc370e29ad54e6682 358058 libdevel optional libpq-dev_8.1.19-0etch1_i386.deb cf367d99c98cf398918b3cbf1a0a2e15 298842 libs optional libpq4_8.1.19-0etch1_i386.deb cebfcc612b77a9cf896ff649b3053346 209634 libs optional libecpg5_8.1.19-0etch1_i386.deb 521dc1be7a37201d6621043854c359d6 377030 libdevel optional libecpg-dev_8.1.19-0etch1_i386.deb 8d7be7bd4b8958d2d28f2cead71faffa 189288 libs optional libecpg-compat2_8.1.19-0etch1_i386.deb cf69ce66e565a882a8d4e657a49f2d67 211304 libs optional libpgtypes2_8.1.19-0etch1_i386.deb 35090ac594866140b8327bb8a635d77b 4301750 misc optional postgresql-8.1_8.1.19-0etch1_i386.deb df71d62f53e21de14be9387903954bfc 1461532 misc optional postgresql-client-8.1_8.1.19-0etch1_i386.deb 5bde112ff217639b066968ea1d88fe11 636052 libdevel optional postgresql-server-dev-8.1_8.1.19-0etch1_i386.deb e628b01b30342c27dd526a7aa199fe81 623632 misc optional postgresql-contrib-8.1_8.1.19-0etch1_i386.deb cc5e76b3011c151b07c3a6419f1863f0 205886 misc optional postgresql-plperl-8.1_8.1.19-0etch1_i386.deb 916c993c5ec43323fb29c21b93d65676 198820 misc optional postgresql-plpython-8.1_8.1.19-0etch1_i386.deb 984a18ace8b12e0fd783fd579e58d357 200274 misc optional postgresql-pltcl-8.1_8.1.19-0etch1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAksnkJMACgkQDecnbV4Fd/LRFgCfcNlXmBOuo7Vrf2pm6awTZ8Zd /oMAoNHpmXFqDbfV5tUQyscXYhgU2BEu =J8oS -----END PGP SIGNATURE----- Accepted: libecpg-compat2_8.1.19-0etch1_i386.deb to main/p/postgresql-8.1/libecpg-compat2_8.1.19-0etch1_i386.deb libecpg-dev_8.1.19-0etch1_i386.deb to main/p/postgresql-8.1/libecpg-dev_8.1.19-0etch1_i386.deb libecpg5_8.1.19-0etch1_i386.deb to main/p/postgresql-8.1/libecpg5_8.1.19-0etch1_i386.deb libpgtypes2_8.1.19-0etch1_i386.deb to main/p/postgresql-8.1/libpgtypes2_8.1.19-0etch1_i386.deb libpq-dev_8.1.19-0etch1_i386.deb to main/p/postgresql-8.1/libpq-dev_8.1.19-0etch1_i386.deb libpq4_8.1.19-0etch1_i386.deb to main/p/postgresql-8.1/libpq4_8.1.19-0etch1_i386.deb postgresql-8.1_8.1.19-0etch1.diff.gz to main/p/postgresql-8.1/postgresql-8.1_8.1.19-0etch1.diff.gz postgresql-8.1_8.1.19-0etch1.dsc to main/p/postgresql-8.1/postgresql-8.1_8.1.19-0etch1.dsc postgresql-8.1_8.1.19-0etch1_i386.deb to main/p/postgresql-8.1/postgresql-8.1_8.1.19-0etch1_i386.deb postgresql-8.1_8.1.19.orig.tar.gz to main/p/postgresql-8.1/postgresql-8.1_8.1.19.orig.tar.gz postgresql-client-8.1_8.1.19-0etch1_i386.deb to main/p/postgresql-8.1/postgresql-client-8.1_8.1.19-0etch1_i386.deb postgresql-contrib-8.1_8.1.19-0etch1_i386.deb to main/p/postgresql-8.1/postgresql-contrib-8.1_8.1.19-0etch1_i386.deb postgresql-doc-8.1_8.1.19-0etch1_all.deb to main/p/postgresql-8.1/postgresql-doc-8.1_8.1.19-0etch1_all.deb postgresql-plperl-8.1_8.1.19-0etch1_i386.deb to main/p/postgresql-8.1/postgresql-plperl-8.1_8.1.19-0etch1_i386.deb postgresql-plpython-8.1_8.1.19-0etch1_i386.deb to main/p/postgresql-8.1/postgresql-plpython-8.1_8.1.19-0etch1_i386.deb postgresql-pltcl-8.1_8.1.19-0etch1_i386.deb to main/p/postgresql-8.1/postgresql-pltcl-8.1_8.1.19-0etch1_i386.deb postgresql-server-dev-8.1_8.1.19-0etch1_i386.deb to main/p/postgresql-8.1/postgresql-server-dev-8.1_8.1.19-0etch1_i386.deb