Bug 159143 - [maintainer] databases/phpmyadmin security update to 3.4.3.2
Summary: [maintainer] databases/phpmyadmin security update to 3.4.3.2
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: Ryan Steinmetz
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-07-23 17:50 UTC by Matthew Seaman
Modified: 2011-07-26 14:10 UTC (History)
1 user (show)

See Also:


Attachments
phpmyadmin.diff (1.13 KB, patch)
2011-07-23 17:50 UTC, Matthew Seaman
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Matthew Seaman 2011-07-23 17:50:09 UTC
From the announcement message:

"Welcome to phpMyAdmin 3.4.3.2 and to phpMyAdmin 3.3.10.3, which are
security releases.

Please refer to the upcoming PMASA-2011-9 to PMASA-2011-12 announcements
on http://www.phpmyadmin.net/home_page/security/.

Details will appear on http://phpmyadmin.net. In a hurry? you can visit
http://sourceforge.net/projects/phpmyadmin to download.

Marc Delisle, for the team"

Still awaiting publication ofthe advisories.  The only detail I've
found so far is in the ChangeLog:

3.4.3.2 (2011-07-23)
- [security] Fixed XSS vulnerability, see PMASA-2011-9
- [security] Fixed local file inclusion vulnerability, see PMASA-2011-10
- [security] Fixed local file inclusion vulnerability and code execution, see PMASA-2011-11
- [security] Fixed possible session manipulation in swekey authentication, see PMASA-2011-12
Comment 1 Ryan Steinmetz freebsd_committer freebsd_triage 2011-07-24 05:22:11 UTC
Responsible Changed
From-To: freebsd-ports-bugs->zi

I'll take it.
Comment 2 Ryan Steinmetz freebsd_committer freebsd_triage 2011-07-26 02:13:48 UTC
State Changed
From-To: open->closed

Committed. Thanks!
Comment 3 dfilter service freebsd_committer freebsd_triage 2011-07-26 02:22:07 UTC
zi          2011-07-26 01:21:53 UTC

  FreeBSD ports repository

  Modified files:
    databases/phpmyadmin Makefile 
  Log:
  Update to 3.4.3.2
  
  PR:             ports/159143
  Submitted by:   Matthew Seaman <m.seaman@infracaninophile.co.uk> [maintainer]
  Approved by:    wxs (mentor)
  
  Revision  Changes    Path
  1.140     +1 -1      ports/databases/phpmyadmin/Makefile
_______________________________________________
cvs-all@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/cvs-all
To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"
Comment 4 dfilter service freebsd_committer freebsd_triage 2011-07-26 14:02:28 UTC
zi          2011-07-26 13:02:14 UTC

  FreeBSD ports repository

  Modified files:
    databases/phpmyadmin distinfo 
  Log:
  Forced commit to correct incorrect log message from prior commit.
  
  Update to 3.4.3.2
  
  PR:             ports/159143
  Submitted by:   Matthew Seaman <m.seaman@infracaninophile.co.uk> [maintainer]
  Approved by:    wxs (mentor)
  
  Revision  Changes    Path
  1.117     +0 -0      ports/databases/phpmyadmin/distinfo
_______________________________________________
cvs-all@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/cvs-all
To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"