Format: 1.8 Date: Thu, 11 May 2023 16:24:27 -0400 Source: postgresql-15 Built-For-Profiles: noudeb Architecture: source Version: 15.3-0ubuntu0.23.04.1~ppa1 Distribution: lunar Urgency: medium Maintainer: Ubuntu Developers Changed-By: Sergio Durigan Junior Launchpad-Bugs-Fixed: 2019214 Changes: postgresql-15 (15.3-0ubuntu0.23.04.1~ppa1) lunar; urgency=medium . * New upstream version (LP: #2019214). . + A dump/restore is not required for those running 15.X. . + Also, if you are upgrading from a version earlier than 15.1, see those release notes as well please. . + Prevent CREATE SCHEMA from defeating changes in search_path (Alexander Lakhin) . Within a CREATE SCHEMA command, objects in the prevailing search_path, as well as those in the newly-created schema, would be visible even within a called function or script that attempted to set a secure search_path. This could allow any user having permission to create a schema to hijack the privileges of a security definer function or extension script. (CVE-2023-2454) . + Enforce row-level security policies correctly after inlining a set-returning function (Stephen Frost, Tom Lane) . If a set-returning SQL-language function refers to a table having row-level security policies, and it can be inlined into a calling query, those RLS policies would not get enforced properly in some cases involving re-using a cached plan under a different role. This could allow a user to see or modify rows that should have been invisible. (CVE-2023-2455) . + Details about these and many further changes can be found at: https://www.postgresql.org/docs/15/release-15-3.html. Checksums-Sha1: 60a46d66b4051915c7889a3640b65d9984e1596d 4034 postgresql-15_15.3-0ubuntu0.23.04.1~ppa1.dsc d78287ab06bf0830b03fcc1b412ef6d643a336d3 29946539 postgresql-15_15.3.orig.tar.gz 6d1642ae91e35614c097b82a8c1d6b09b5dcc292 23716 postgresql-15_15.3-0ubuntu0.23.04.1~ppa1.debian.tar.xz f3368de2afacdcabe98bdd86cef4f5f8e5b33b61 8856 postgresql-15_15.3-0ubuntu0.23.04.1~ppa1_source.buildinfo Checksums-Sha256: be24560f43c55a9d267c051f2788f8f12fdc472e71172fe5e65e8dee1ded5876 4034 postgresql-15_15.3-0ubuntu0.23.04.1~ppa1.dsc 086d38533e28747966a4d5f1e78ea432e33a78f21dcb9133010ecb5189fad98c 29946539 postgresql-15_15.3.orig.tar.gz c1762fd3b9c9c2e2c55b3ab1a8c2a5333648d5cbdf0289243f54788fe60c0212 23716 postgresql-15_15.3-0ubuntu0.23.04.1~ppa1.debian.tar.xz 1eabb365cfcafc567713b326fc678f117b0e6aa09424accd9c96389283b8f2ff 8856 postgresql-15_15.3-0ubuntu0.23.04.1~ppa1_source.buildinfo Files: 9bb5041cd92b42f94644e680e75e5c79 4034 database optional postgresql-15_15.3-0ubuntu0.23.04.1~ppa1.dsc 4280bab93cc5628e80a777309268a0ea 29946539 database optional postgresql-15_15.3.orig.tar.gz b86b469a14a50744851392f239c41ffb 23716 database optional postgresql-15_15.3-0ubuntu0.23.04.1~ppa1.debian.tar.xz 914c5a457952df759cfdc797f40eaa02 8856 database optional postgresql-15_15.3-0ubuntu0.23.04.1~ppa1_source.buildinfo Original-Maintainer: Debian PostgreSQL Maintainers