-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 08 Nov 2017 16:03:19 +0100 Source: postgresql-common Binary: postgresql-common postgresql-client-common postgresql-server-dev-all postgresql postgresql-client postgresql-doc postgresql-contrib postgresql-all Architecture: source Version: 188 Distribution: unstable Urgency: medium Maintainer: Debian PostgreSQL Maintainers <pkg-postgresql-public@lists.alioth.debian.org> Changed-By: Christoph Berg <christoph.berg@credativ.de> Description: postgresql - object-relational SQL database (supported version) postgresql-all - metapackage depending on all PostgreSQL server packages postgresql-client - front-end programs for PostgreSQL (supported version) postgresql-client-common - manager for multiple PostgreSQL client versions postgresql-common - PostgreSQL database-cluster manager postgresql-contrib - additional facilities for PostgreSQL (supported version) postgresql-doc - documentation for the PostgreSQL database management system postgresql-server-dev-all - extension build tool for multiple PostgreSQL versions Changes: postgresql-common (188) unstable; urgency=medium . * pg_ctlcluster, pg_createcluster, pg_upgradecluster: Use lchown instead of chown to mitigate privilege escalation via symlinks. (CVE-2017-8806. Related to CVE-2017-12172 in PostgreSQL; extends our earlier fix for CVE-2016-1255.) * dh_make_pgxs: Add options to set package name and version. * pg_lsclusters: Raise error when called on a specific cluster that does not exist. This was the behavior before the "accept dead postgresql.conf symlinks" change, but not coded explicitly. Checksums-Sha1: 01df7c12593a1f1c733e2d1b8b434db53de0e49b 2339 postgresql-common_188.dsc 8b023a518be6cebcd8006f78b8b1556becee1ec6 205532 postgresql-common_188.tar.xz 6907890903908fe302a2f885fab7be5413676949 5771 postgresql-common_188_source.buildinfo Checksums-Sha256: fd0e24207bd8f928a06513f8ae80159b1a1dcb0adf9c829dd813c7c001af3c26 2339 postgresql-common_188.dsc 1d8d69188862a1ca4831a7ab6e63a46aae0fe3b6322461a94efc9f8b9f2759e1 205532 postgresql-common_188.tar.xz d0a5a954d381b8a22e7b627c29a57516c6b10527fcfe855035a693ac18521b1f 5771 postgresql-common_188_source.buildinfo Files: e4b2bf4dd565093b7759f79689cb8de6 2339 database optional postgresql-common_188.dsc 31700e314c82c3ed53576fbca4728a9d 205532 database optional postgresql-common_188.tar.xz 1a26897e18a46a00ab28c9865627551e 5771 database optional postgresql-common_188_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEXEj+YVf0kXlZcIfGTFprqxLSp64FAloDHPMACgkQTFprqxLS p65QKw//Z0d0SmFU+zPrf1TLvXf01kCSBxApp5nOdYnANeUFTzoe2AgTg5xSR93/ TSjAv7wLoKZtHxOrqPGSaeRBvHK0id0L5Tf6831niCGgvSywQmNgeO4xxtIll6R3 YB8NbUSNw9vmQZBoAiW+dQsKaoH43xyWIp3EulnGWPhXMlY/w56KDnjoxI1bmC51 j6oz5yh5Wf4jjRcMeyYl1fDKx09FjM4zhAnADLm9/zm7YGjmh05/mw/9EEelfe8w nmVq7hVpyzuYlNIPzyLr8WyUWU2coP3Qm7tCEfDZmJSBbIQb2WPnZUsFt14r53Dc w3q1g3DkZJfaEKIR5Gio2x2Ar06+TE9sWR+YyhVA7QKKlZb8lLlugy8Wo/zRm8WK M9bnleCR2UTubJjudQGiPhqRwGqyeA2Zs3JhgdvLbdgxYzEL4cPx2iiHlah7HmZt Ry7q1n+2njFR+sWoz8KlJ4wqtwmHURH/z3OOzeYdWQGw3UjTAQwCucZm9ZxzXZ0N imozIlELmnCkFEKMCO62CdyBSxxM9GpbfJZYQpxoKPHLPZhKzs8dcb/WcLPz/vIa C0pAQti/Qatjsa69h9+shzFkJVyp4LFwZyxRbNfPftUq64oW/RlveIxMibsAYriV YAgdbAUxtqKavQ4H6k+Y3r31xUvzyqatvihk5c4AYB5sTJclUtM= =uvQQ -----END PGP SIGNATURE-----