-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 09 Jul 2025 17:34:58 +0800 Source: pgpool2 Binary: libpgpool-dev libpgpool2 libpgpool2-dbgsym pgpool2 pgpool2-dbgsym postgresql-15-pgpool2 postgresql-15-pgpool2-dbgsym Architecture: i386 Version: 4.3.5-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-conova-02) Changed-By: Aron Xu Description: libpgpool-dev - pgpool control protocol library - headers libpgpool2 - pgpool control protocol library pgpool2 - connection pool server and replication proxy for PostgreSQL postgresql-15-pgpool2 - connection pool server and replication proxy for PostgreSQL - mod Closes: 1081659 1106119 Changes: pgpool2 (4.3.5-1+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2024-45624: incompatible policies may allow an unauthorized user to retrieve table data from query cache (Closes: #1081659) * CVE-2025-46801: authentication bypass by primary weakness vulnerability (Closes: #1106119) Checksums-Sha1: 16a1049e728f55fa1d30a02cebedebb3ba4bdf77 152184 libpgpool-dev_4.3.5-1+deb12u1_i386.deb cac88cc5f3cfdd754fc9e43d1265e2b7fbeaac44 58020 libpgpool2-dbgsym_4.3.5-1+deb12u1_i386.deb 077404142829f2f44e623e05e223dd901f12bbec 142508 libpgpool2_4.3.5-1+deb12u1_i386.deb e4b8340deea6d72092f85004ab03e3e4ab1129dc 1806080 pgpool2-dbgsym_4.3.5-1+deb12u1_i386.deb 9934b42e0e4f9e44f0b9fecadc395048e2a2df44 10932 pgpool2_4.3.5-1+deb12u1_i386-buildd.buildinfo 78eb52512118fd58ff30e1f153edf7c6f24a8685 1258652 pgpool2_4.3.5-1+deb12u1_i386.deb 268a33ddff0038de6e271eac71c902dcd0a5f52a 47820 postgresql-15-pgpool2-dbgsym_4.3.5-1+deb12u1_i386.deb eb53a6ed6816560d1f725bfa874c9f4eb06585fd 160624 postgresql-15-pgpool2_4.3.5-1+deb12u1_i386.deb Checksums-Sha256: 614eb42d10180359e3c0f77ba9dff4fb4b63e9a710931265f537b644126d6a8f 152184 libpgpool-dev_4.3.5-1+deb12u1_i386.deb 874e5b3620931e7a5ad57882d43536bdf1d6fd716256f6928796114fdf0f36e7 58020 libpgpool2-dbgsym_4.3.5-1+deb12u1_i386.deb 301a7f2083bb486f490a6c880675a6f318499e28ba57356656b720cb52a53698 142508 libpgpool2_4.3.5-1+deb12u1_i386.deb db86c192f08da23bb2f56c0ff1fd2562650699d16476666c8252367b6f6282ae 1806080 pgpool2-dbgsym_4.3.5-1+deb12u1_i386.deb 6d9cdeccac26ea432328a3814877f7bf69a47247b5e117569cbec86eb91e3623 10932 pgpool2_4.3.5-1+deb12u1_i386-buildd.buildinfo 4b192912b905f45a8e4b7cd9dfa999f19003005e6858a4f8ed9e0c539a51c066 1258652 pgpool2_4.3.5-1+deb12u1_i386.deb f0deaa21d5ed3745cd56ed48d2a66047ebc35e6e52c832722df10ea5dc6d03b6 47820 postgresql-15-pgpool2-dbgsym_4.3.5-1+deb12u1_i386.deb 69bd1b522f8ad72d0c3ab5cd559d393fbb2315d12d07acc2fec1ca6644225f8e 160624 postgresql-15-pgpool2_4.3.5-1+deb12u1_i386.deb Files: ab57485829614b4969b75d7690fc36da 152184 libdevel optional libpgpool-dev_4.3.5-1+deb12u1_i386.deb e54934fb62ebc2dbaf5e23192f76c81f 58020 debug optional libpgpool2-dbgsym_4.3.5-1+deb12u1_i386.deb 6f01c49930b53c0921c462b6366366f4 142508 libs optional libpgpool2_4.3.5-1+deb12u1_i386.deb 4480205d003a6a7f381268694ffa7d14 1806080 debug optional pgpool2-dbgsym_4.3.5-1+deb12u1_i386.deb ee5762680616410699f1fabdf59a20ad 10932 database optional pgpool2_4.3.5-1+deb12u1_i386-buildd.buildinfo 28dbbd6750c15a34717a1acc97ec2d58 1258652 database optional pgpool2_4.3.5-1+deb12u1_i386.deb e594ff07b9920f7a80e0665f9bdefaf9 47820 debug optional postgresql-15-pgpool2-dbgsym_4.3.5-1+deb12u1_i386.deb 55dcdc81de93d384964c0a058f192376 160624 database optional postgresql-15-pgpool2_4.3.5-1+deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEErwLLVsiCiGZggzpHJuP6X4A0XeIFAmiUaJUACgkQJuP6X4A0 XeK6Iw/8DmHaVWNbBB/PqVLCsJYdHeTKS3hlRtKztIhhH8Omg6O/KedBu2FTZhbe GXpNoMuQVeo1SQSEc4bjje9i0FpfxS2ef+UI0gTpK4bQ7UCSAFEM39cyIXbpoPQr FRQlObU6QRpXwq6cNjicOeWc0cyFKijUvzIMMFaz8Fh+HzyRm39axODL10WigCMv WKXXf4J+UJ6FNGcxijO4fSpFl4n5jGpHsFZdD+zryLEdvNUXjtq4jPlXZNOXccOR J9St6BhxjcIIo5qLMWfDVscHE3lej+/E4FkRw+Nxcrim2IgB5qaa8JOZKgtzUNNu JoZlVF+JDjiyHdJUibtksNP8u3XNVcE9AfsJZ1M8mF+7Tb3VMfOcfbYzYaFyu0Jk Qx2t2lZ59Ca1d/ASyuGAHz8zzbpYw9DnEb3jYE4wPLLu4s5npKWbDLEMAtbv2MTz KV5vK63AXOytbxfzXGtXJVuoogjjoBqNqc5HtruEXzXgMKJ+kXUOioBA0zJKqmP8 sa7MOLUkxYeLGWWiNd+GTA/2AGuCNF0l+DlxxQyQB4Sg4db5rUhIO1kW5g5B6Ymg 7Dt8lNGH3/yhNhNLfr2FOGuDQcuLe9gDNE+62K7AKd+/jx3sN0irH3TgLj6Ud0OB KtW6picOfJNWcM2dSS7n5UiCW3MBamKKOgV2voQ3fAckBfa5I60= =qYgc -----END PGP SIGNATURE-----