-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 25 Dec 2025 19:03:31 +0100 Source: postgresql-17 Binary: postgresql-doc-17 Architecture: all Version: 17.7-0+deb13u1 Distribution: trixie Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-grnet-03) Changed-By: Christoph Berg Description: postgresql-doc-17 - documentation for the PostgreSQL database management system Changes: postgresql-17 (17.7-0+deb13u1) trixie; urgency=medium . * New upstream version 17.7. . + Check for CREATE privileges on the schema in CREATE STATISTICS (Jelte Fennema-Nio) . This omission allowed table owners to create statistics in any schema, potentially leading to unexpected naming conflicts. . The PostgreSQL Project thanks Jelte Fennema-Nio for reporting this problem. (CVE-2025-12817) . + Avoid integer overflow in allocation-size calculations within libpq (Jacob Champion) . Several places in libpq were not sufficiently careful about computing the required size of a memory allocation. Sufficiently large inputs could cause integer overflow, resulting in an undersized buffer, which would then lead to writing past the end of the buffer. . The PostgreSQL Project thanks Aleksey Solovev of Positive Technologies for reporting this problem. (CVE-2025-12818) Checksums-Sha1: fb309b6a4c591e60b861a21d4103b296bca709c8 10206 postgresql-17_17.7-0+deb13u1_all-buildd.buildinfo 195fd55a0cb6fc4610bb4394ad6b61ea6b5521f1 2149344 postgresql-doc-17_17.7-0+deb13u1_all.deb Checksums-Sha256: 233333bf58b4394d6a45fb667edabc4aba62d78d6514b339cb43e0954aab5f34 10206 postgresql-17_17.7-0+deb13u1_all-buildd.buildinfo 9eaa960476ad6b5f1efdab39c207a63c1479d0ddf95e239a50732c046c329311 2149344 postgresql-doc-17_17.7-0+deb13u1_all.deb Files: 0b7a13e0e88b132383d9a6ea13156746 10206 database optional postgresql-17_17.7-0+deb13u1_all-buildd.buildinfo 360df0caec876687ddff6734150d13ba 2149344 doc optional postgresql-doc-17_17.7-0+deb13u1_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEHqtYLkdKRyCY94K8fUw6/tXbAmMFAmlUTPUACgkQfUw6/tXb AmO8Rg//dddVglUCK0y3wHOvAQc73E61kkiYekrk9k74BR/Tjo4620JgxKN8r7yc 3B5dU9E4Jrgjv46z9RcK/xVuiWxqO6f4IdBCVtxEpL7hLmB9YwYcXDpLcOWc/NJf 4gWDDPN0jA10uO6GEbM2n0a6uslNUfCEboYohKiBBsqeAoq2FTHxbdPHypCHVBRJ 6Su8lhjxYLEcmvn9uNm9eDHPoSih5gAWtrnODUGvClwgD19lG9XbCPevmzm5Ebik YDXeDihULtwgquYFg0KkumBCvxrW/n5VCbmeak5+/zPKShRxX2yP6cLn/9Rj4C1o 1VFehYU3JPMnluG6EM2nktMzt28a2oM1zfhJAt3H+l6+fKa1tYJg1z543OrG6h78 nkvXnYW1eCdq909ZaJHjQr9KnzB7EL/2TbBO2vQJtiFzMiXxJjYnUsFPq9DirOlX 92ILu87tUwIWRx5/ddjXnp8Tg0zhpeKmPnQS3dDOof9pWks2hRunQWxfmkdSEsVE 8/1EZly5EDFLZMQeuV3ED6o11dMh/1VESav2wBO/sjZ3eclf5LysaPpKnagV+nat zLgP1KqoFVGaLJb8k0UjFkHPq+2ZykHIMYI4uaUVBTmkCszDKewikIJ995pJsVxi mQm9UmhmRe/JgsOZAcUjmOr3nLk/YZQ8DzIZh7h9dj9f6rVIB4M= =qo57 -----END PGP SIGNATURE-----