-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 12 Nov 2019 15:00:36 +0100 Source: postgresql-common Architecture: source Version: 200+deb10u3 Distribution: buster-security Urgency: medium Maintainer: Debian PostgreSQL Maintainers <team+postgre...@tracker.debian.org> Changed-By: Christoph Berg <m...@debian.org> Changes: postgresql-common (200+deb10u3) buster-security; urgency=medium . * pg_ctlcluster: Drop privileges before creating socket and stats temp directories outside /var/run/postgresql. The default configuration is not affected by this change. Users with directories on volatile storage (tmpfs) in other locations have to make sure the parent directory is writable for the cluster owner. (CVE-2019-3466, discovered by Rich Mirch) Checksums-Sha1: 5725ca31eba3b9d2c0701d6939dd5624d1da4ea5 2341 postgresql-common_200+deb10u3.dsc 54e07a903db4a4a68114dd3f47ec149002511045 213376 postgresql-common_200+deb10u3.tar.xz Checksums-Sha256: 14a3734d2e62c89f7aa689d3014e243fb9bdb0030940b1ed0cb721a651e7f947 2341 postgresql-common_200+deb10u3.dsc 394e775ac9227d79f5c258bf1a6b0b446f6b8abf08ad1e75d07f9935353014e6 213376 postgresql-common_200+deb10u3.tar.xz Files: 87bd864ba0f8633103cdd039236c8299 2341 database optional postgresql-common_200+deb10u3.dsc d8c7a1bc33ca1f8e47e809857c48b356 213376 database optional postgresql-common_200+deb10u3.tar.xz
-----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEXEj+YVf0kXlZcIfGTFprqxLSp64FAl3McpIACgkQTFprqxLS p66XKA//Ww3Wi4PcIYPcwjgfCm6eVNnKgehxGsybKul5xETJN87lU7U0xDxtu2OO MICrFvtrgov0GCs86bCW5FAltJ4bSuk94k7ZasX8CUOb4juMY4rPOY89qtroY1Xz LuFU24zoG+1pCKVr28wR4ObYElFwjKPpbquKRSTSLy/2T389MgbNjAoOUr7+5Ivk hZT2AF6E7RZDDzuwYSoG+8VZr2V664WwQuK60+tE5lhnvyIMT8klq/HWAa5tk+eY Cw2OSCUvGYN5oWCaVSTdsp5I/ByTP41OQ3omvaMi9poY9x8BgUtE5RtejkgoH/FU W2Qjf7VBBE5POQqlZEXmqEM7LWDBXX+//gJXdQ3LD6X8rRwyJ3tilI9yZ+XZXd4U 2hmwXl3UXX7H7PwuAc1L7WrwUHWDOWxfvMUAHrA+0RIXjQ3BoPMUFdzOW0FqoSnW qdXqcjbFa9r/GOJfvv9rG5R+pW0MQ18ial0jD1ThILdUnyKTDcqcCinusX+aX3I0 hX1/WJlEavznih8ssivFc3mjdJ/0Nbl72VPkvvMzpgwLh+I79+TAJe0bEjMX8Dg5 6Sd4V+Rpi79A06nwM5M6FCzy/CYCvRJTV4nOJmwfWbWSAqs+m2rmG9ewgkCkFlWa ppqqTSQ7tTTirettANtjaSX/fc6ZVlTpBqR8BjQ9HcN2Ll5MqcA= =FXNI -----END PGP SIGNATURE-----