-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 09 Jul 2025 17:34:58 +0800 Source: pgpool2 Binary: libpgpool-dev libpgpool2 libpgpool2-dbgsym pgpool2 pgpool2-dbgsym postgresql-15-pgpool2 postgresql-15-pgpool2-dbgsym Architecture: armhf Version: 4.3.5-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Aron Xu Description: libpgpool-dev - pgpool control protocol library - headers libpgpool2 - pgpool control protocol library pgpool2 - connection pool server and replication proxy for PostgreSQL postgresql-15-pgpool2 - connection pool server and replication proxy for PostgreSQL - mod Closes: 1081659 1106119 Changes: pgpool2 (4.3.5-1+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2024-45624: incompatible policies may allow an unauthorized user to retrieve table data from query cache (Closes: #1081659) * CVE-2025-46801: authentication bypass by primary weakness vulnerability (Closes: #1106119) Checksums-Sha1: 6a104713b53dee3089c3575ad21cea9e4334f3a2 148260 libpgpool-dev_4.3.5-1+deb12u1_armhf.deb c328204e69672eff56849b85b7f5a516a5a8b884 64984 libpgpool2-dbgsym_4.3.5-1+deb12u1_armhf.deb 303f9daed4104a4af5096dd4d827b265dc7496e0 139188 libpgpool2_4.3.5-1+deb12u1_armhf.deb 51df63f6d233d97e6603dc00f1f453b247fa8d84 1839916 pgpool2-dbgsym_4.3.5-1+deb12u1_armhf.deb c9d9989e218083308c98f163c009307f97fe84de 10866 pgpool2_4.3.5-1+deb12u1_armhf-buildd.buildinfo a4d410ee3bcd7546010f30caaf5e64456fecfe4b 1173172 pgpool2_4.3.5-1+deb12u1_armhf.deb e2d6beb04cc3f9160b65f2e36ae0d5b7a6afa869 50060 postgresql-15-pgpool2-dbgsym_4.3.5-1+deb12u1_armhf.deb 3ba7fdb81aa419aa71efa9811e4e827767292b83 159240 postgresql-15-pgpool2_4.3.5-1+deb12u1_armhf.deb Checksums-Sha256: 328987e5855775de3f070998cd701ada5d20a8041e77ace980201399bfb5975a 148260 libpgpool-dev_4.3.5-1+deb12u1_armhf.deb 50c97ac4cc1ca1e325989a86d0d9649992d3119adac849c704459dafd5edd586 64984 libpgpool2-dbgsym_4.3.5-1+deb12u1_armhf.deb 1a37bcdf42dc62f60eb0ba2171e379ccda52a7bd6c428b0ee402e2ca93fd0441 139188 libpgpool2_4.3.5-1+deb12u1_armhf.deb 1115b4b8bac9f24d30bc683268f2b99c0d87fe71cf721b2e7341b021e1305e57 1839916 pgpool2-dbgsym_4.3.5-1+deb12u1_armhf.deb 1160ea0e20691095c971a78559dd4de9db056d28a2440632a2680ed81b7d7c3d 10866 pgpool2_4.3.5-1+deb12u1_armhf-buildd.buildinfo 2f55077e79e1c9e43c5c27790391aadddda0088c035ada37f1eac7ca2110233f 1173172 pgpool2_4.3.5-1+deb12u1_armhf.deb 65f418bddb47fbb7ceded2f14480c4568126b3b8dcb18271d36964b0dc61bbdb 50060 postgresql-15-pgpool2-dbgsym_4.3.5-1+deb12u1_armhf.deb c821973e11d62e3c5beac9fac9be4dc7de5e3deae4bacf965dea19ac176898f4 159240 postgresql-15-pgpool2_4.3.5-1+deb12u1_armhf.deb Files: ae0c5832265d6321515ce00e56eafd39 148260 libdevel optional libpgpool-dev_4.3.5-1+deb12u1_armhf.deb 5ae68dd96a56cbfa51a9e11e0fd65793 64984 debug optional libpgpool2-dbgsym_4.3.5-1+deb12u1_armhf.deb cdc554730abe5cb266e400c184a19102 139188 libs optional libpgpool2_4.3.5-1+deb12u1_armhf.deb 935702f491538e500bdc7ed21d607261 1839916 debug optional pgpool2-dbgsym_4.3.5-1+deb12u1_armhf.deb 1834b908a60b2e24c827021e373f7322 10866 database optional pgpool2_4.3.5-1+deb12u1_armhf-buildd.buildinfo 4a2e2b1c8cb2861f26826d3cee239b5d 1173172 database optional pgpool2_4.3.5-1+deb12u1_armhf.deb 6d9e7692b08d3f401f54552574c3bcf6 50060 debug optional postgresql-15-pgpool2-dbgsym_4.3.5-1+deb12u1_armhf.deb 64b080e2c7871a26c7414afeb7eb282a 159240 database optional postgresql-15-pgpool2_4.3.5-1+deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEegRwmIwj8f99iF4m4CwlMGxHD8UFAmiUaHEACgkQ4CwlMGxH D8WXeBAAmixENl7kL9eqDE0OZwQqfr0DByWLm5XbpwbHiuwbmBZ7qtHdCFKNtxNB 1DK5hqp9djZGPQfMMJ2rc/gmuF9sNApeQ5ZFkmizWAJnEZa5nNbt8TdjuLtOpu5t lyvdTaYrYf5OYmUEqL6YgtFmWavfJADcM7WQSSNL5JnESo3Tom2qEVnU0s0ouRAu wK34o3ypwaRj2c7360X9AMvFkReRIllu4uSjlgXeJCWgSlLSqX4pYo7JsHPUiGng 5QCDodtzjOfu7mg7HzoUHih7i080SqsgksMvLZU4IaL5TzyFHVRQo8foUO+FuMss j12NqWq9eKAm/11iwl9UoITyal5qwwdb+6fdDq7UMq7k74GmxisD+KTHMiznw8K1 t4UfEUybA9py7vN3Pjn6SqgHrrpF8ENtyd+/9A1d0aEoMoaHcJ6x32Hty0gVVt4S P2OXiZQVEbaLuobx+vFtCPHYjkg4O6BEGHb/j92fkg4B+/aEbVu9oPQh7GgBX/iP jqe141jpJ8mSZrruEsMnCzw0QzIyL5aKlRj6xG18nm7IfBZ1xd7zKIrX9KHCp/fU p+kCrYXAJvlHWYRPN2UX2yIDL+PVcgBbJR2yt8vp58FxADr7BAEyp7RKK/7nt9JO lHX/fC+hsnudyptamPLIYaFefYbUQRLkkFlvy+Q6WO9WRNGivVM= =93N0 -----END PGP SIGNATURE-----