-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 07 Nov 2017 20:54:52 +0100 Source: postgresql-common Binary: postgresql-common postgresql-client-common postgresql-server-dev-all postgresql postgresql-client postgresql-doc postgresql-contrib postgresql-all Architecture: source Version: 181+deb9u1 Distribution: stretch-security Urgency: medium Maintainer: Debian PostgreSQL Maintainers <pkg-postgresql-public@lists.alioth.debian.org> Changed-By: Christoph Berg <myon@debian.org> Description: postgresql - object-relational SQL database (supported version) postgresql-all - metapackage depending on all PostgreSQL server packages postgresql-client - front-end programs for PostgreSQL (supported version) postgresql-client-common - manager for multiple PostgreSQL client versions postgresql-common - PostgreSQL database-cluster manager postgresql-contrib - additional facilities for PostgreSQL (supported version) postgresql-doc - documentation for the PostgreSQL database management system postgresql-server-dev-all - extension build tool for multiple PostgreSQL versions Changes: postgresql-common (181+deb9u1) stretch-security; urgency=medium . * pg_ctlcluster, pg_createcluster, pg_upgradecluster: Use lchown instead of chown to mitigate privilege escalation via symlinks. (CVE-2017-8806. Related to CVE-2017-12172 in PostgreSQL; extends our earlier fix for CVE-2016-1255.) Checksums-Sha1: b1662324b2d41bdeb7d9088ed06b9d8f508b0bf4 2372 postgresql-common_181+deb9u1.dsc a9cfb9390522f084c9cfa91e1d18a28dac12b6f7 201804 postgresql-common_181+deb9u1.tar.xz c6f331314f3cdb97d7e506b029c1907a91aa3414 5969 postgresql-common_181+deb9u1_source.buildinfo Checksums-Sha256: c21965f1adabf78feb1890cd3c342091c78f6f83e4238e03cdca201018481e28 2372 postgresql-common_181+deb9u1.dsc 4852c182eb397e075b49e3aa65b07c3fb21a23788bccce4d72bc7332ca5fc157 201804 postgresql-common_181+deb9u1.tar.xz 620c68e05634d29d96125bdb3667770cf721da5479cb9d928348c1b0fd7a05ae 5969 postgresql-common_181+deb9u1_source.buildinfo Files: 1a1a330ac911e3e18040c0c382b46b40 2372 database optional postgresql-common_181+deb9u1.dsc 86e31ddcce029108c339cfce9b9beb11 201804 database optional postgresql-common_181+deb9u1.tar.xz 7b3132419ecd82c09ceb577a30cad208 5969 database optional postgresql-common_181+deb9u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEXEj+YVf0kXlZcIfGTFprqxLSp64FAloDHH4ACgkQTFprqxLS p66XCg//RCBqieX+5en5WkNG/UnRQNjDfRrw87KcIFvtALXZ68780dzaKVYaleVN wsVrxupNEmD0c85UBv4f2Cs4fKeQtpJdHrRQVnXE1SJxp+OZANyTaehBG83j/KKy NOuzPor20B7f78O37aIOztqCFta9Yw7JK9uPVCbz6fFqDm9BHzovRWZPLj3U1Ty2 fM3KoUI6ouv+uwnToNuADCPWT3GMYhljZeD3A692PBwqUH9VLnqtWojpeQKQn5mF VeqH61+ZRt1OAPNLxRXAdI3lLkoHPUDBOrTQkRQtvlvhFb2DQ2cqO3jmBfmPtYAl VdSCxtENqzVVNIA5EV/p1n9ZcQw6qRlLLMyMLu2PWbIXFMxgsVBf025PKRs+XhuQ YXGk63okcfvoRBfhuENrk9SSjbhTpDzRohSrAacNNI0rtsst3LeydLDsPbhbjVk9 Ock0beCGEL1kMa+183IWvo+y/AbFlVYaOZGvHz4oetjnL5hXsK1WOQjtn2PBgctB Xy/MLj1tmMO/q+7qAQ7klI2gdt3EFQ6pJUiz0Q5+mwklSarmnu6NkB6mv8t+RveM Q0F1o6avrFNcOI0oQpIW1EQF9JfKXUX81M6yy8LFWcCBVeVrjUeyF0XjtG7CL6Ds 1WbLU5ETRQFXj+WQlz6D3EYRduNCdZmGBtVMprAirLI3PXo4+PA= =0wDK -----END PGP SIGNATURE-----