Bug 90085 - [security][maintainer] databases/phpmyadmin -- update to 2.7.0-pl1
Summary: [security][maintainer] databases/phpmyadmin -- update to 2.7.0-pl1
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: Marcus Alves Grando
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-12-07 20:50 UTC by Matthew Seaman
Modified: 2005-12-07 21:41 UTC (History)
1 user (show)

See Also:


Attachments
phpmyadmin.diff (1.23 KB, patch)
2005-12-07 20:50 UTC, Matthew Seaman
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Matthew Seaman 2005-12-07 20:50:10 UTC
From the security advisory PMASA-2005-9
(http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2005-9):

Announcement-ID: PMASA-2005-9
Date: 2005-12-07

Summary:
Cross-Site Scripting, local and remote code execution vulnerabilities

Description:
Two days after the release of version 2.7.0, we received a security advisory from Stefan Esser (sesser@hardened-php.net) and we wish to thank him for his work.

It is possible to overwrite the global import_blacklist variable to open phpMyAdmin 2.7.0 to those vulnerabilities.

Severity:
We consider these vulnerabilities to be serious.

Affected versions:
Only the unpatched 2.7.0 version.

Solution:
Upgrade to phpMyAdmin 2.7.0-pl1 or newer.

References:
http://www.hardened-php.net/advisory_252005.110.html

For further information and in case of questions, please contact the phpMyAdmin team. Our website is http://www.phpmyadmin.net/.
Comment 1 Marcus Alves Grando freebsd_committer freebsd_triage 2005-12-07 20:56:47 UTC
Responsible Changed
From-To: freebsd-ports-bugs->mnag

I'll take it.
Comment 2 Marcus Alves Grando freebsd_committer freebsd_triage 2005-12-07 21:41:54 UTC
State Changed
From-To: open->closed

Committed. Thanks!