Bug 78061 - [ maintainer ] databases/phpmyadmin (security) update to 2.6.1.pl2
Summary: [ maintainer ] databases/phpmyadmin (security) update to 2.6.1.pl2
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: freebsd-ports-bugs (Nobody)
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-02-25 11:10 UTC by Matthew Seaman
Modified: 2005-02-25 20:08 UTC (History)
1 user (show)

See Also:


Attachments
phpmyadmin.diff (5.44 KB, patch)
2005-02-25 11:10 UTC, Matthew Seaman
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Matthew Seaman 2005-02-25 11:10:37 UTC
Update to 2.6.1.pl2  --- this supercedes PR ports/78011

Update to phpmyadmin version 2.6.1.pl1:

Release notes:

   http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0

Announcement e-mail (quoted below) is at

   http://sourceforge.net/mailarchive/forum.php?thread_id=6674358&forum_id=2141
Patch level 1 of phpMyAdmin 2.6.1 fixes some security problems,
along with a few other bugs.
A more formal security alert will be posted when ready.

Meanwhile, the phpMyAdmin development team strongly advises an
upgrade to phpMyAdmin 2.6.1-pl1, and to also apply the following
security measures on your PHP installation (if feasible) by modifying
your php.ini configuration file (or virtual host settings):

- set register_globals to Off
- set display_errors to Off
- set log_errors to On
- define the path to your error log with the error_log directive

Both settings are recommended in the PHP documentation on a server
running in production. For example:
http://www.php.net/manual/en/security.errors.php
However, we suggest you review the impact of those changes before
applying them.

Meanwhile, work continues on the development version 2.6.2.
Comment 1 Pav Lucistnik freebsd_committer freebsd_triage 2005-02-25 20:08:30 UTC
State Changed
From-To: open->closed

Committed, thanks!