Publishing details
Changelog
postgresql-15 (15.2-1) unstable; urgency=medium
* New upstream version.
+ libpq can leak memory contents after GSSAPI transport encryption
initiation fails (Jacob Champion)
A modified server, or an unauthenticated man-in-the-middle, can send a
not-zero-terminated error message during setup of GSSAPI (Kerberos)
transport encryption. libpq will then copy that string, as well as
following bytes in application memory up to the next zero byte, to its
error report. Depending on what the calling application does with the
error report, this could result in disclosure of application memory
contents. There is also a small probability of a crash due to reading
beyond the end of memory. Fix by properly zero-terminating the server
message. (CVE-2022-41862)
-- Christoph Berg <email address hidden> Tue, 07 Feb 2023 14:57:10 +0100
Builds
Built packages
-
libecpg-compat3
older version of run-time library for ECPG programs
-
libecpg-compat3-dbgsym
debug symbols for libecpg-compat3
-
libecpg-dev
development files for ECPG (Embedded PostgreSQL for C)
-
libecpg-dev-dbgsym
debug symbols for libecpg-dev
-
libecpg6
run-time library for ECPG programs
-
libecpg6-dbgsym
debug symbols for libecpg6
-
libpgtypes3
shared library libpgtypes for PostgreSQL 15
-
libpgtypes3-dbgsym
debug symbols for libpgtypes3
-
libpq-dev
header files for libpq5 (PostgreSQL library)
-
libpq5
PostgreSQL C client library
-
libpq5-dbgsym
debug symbols for libpq5
-
postgresql-15
The World's Most Advanced Open Source Relational Database
-
postgresql-15-dbgsym
debug symbols for postgresql-15
-
postgresql-client-15
front-end programs for PostgreSQL 15
-
postgresql-client-15-dbgsym
debug symbols for postgresql-client-15
-
postgresql-doc-15
documentation for the PostgreSQL database management system
-
postgresql-plperl-15
PL/Perl procedural language for PostgreSQL 15
-
postgresql-plperl-15-dbgsym
debug symbols for postgresql-plperl-15
-
postgresql-plpython3-15
PL/Python 3 procedural language for PostgreSQL 15
-
postgresql-plpython3-15-dbgsym
debug symbols for postgresql-plpython3-15
-
postgresql-pltcl-15
PL/Tcl procedural language for PostgreSQL 15
-
postgresql-pltcl-15-dbgsym
debug symbols for postgresql-pltcl-15
-
postgresql-server-dev-15
development files for PostgreSQL 15 server-side programming
Package files