Bug 127417 - [maintainer] databases/phpmyadmin security update to 2.11.9.1
Summary: [maintainer] databases/phpmyadmin security update to 2.11.9.1
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: Martin Wilke
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2008-09-16 06:50 UTC by Matthew Seaman
Modified: 2008-09-17 10:30 UTC (History)
1 user (show)

See Also:


Attachments
phpmyadmin.diff (1.13 KB, patch)
2008-09-16 06:50 UTC, Matthew Seaman
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Matthew Seaman 2008-09-16 06:50:01 UTC
A point release to close a code execution vulnerability.  This bug
allows a remote user logged in to the phpmyadmin web application to
run arbitrary shell commands with the credentials of the web
server. Not much more information is available yet:

phpMyAdmin release notes:
   https://sourceforge.net/project/shownotes.php?release_id=626450
   http://www.phpmyadmin.net/home_page/downloads.php?relnotes=1

Security Advisory:
   http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-7

Other Links:
   http://fd.the-wildcat.de/pma_e36a091q11.php
Comment 1 Martin Wilke freebsd_committer freebsd_triage 2008-09-16 09:20:30 UTC
Responsible Changed
From-To: freebsd-ports-bugs->miwi

I'll take it.
Comment 2 dfilter service freebsd_committer freebsd_triage 2008-09-17 10:29:02 UTC
miwi        2008-09-17 09:28:53 UTC

  FreeBSD ports repository

  Modified files:
    databases/phpmyadmin Makefile distinfo 
  Log:
  - Update to 2.11.9.1
  
  Security Update:
          A point release to close a code execution vulnerability. This bug
          allows a remote user logged in to the phpmyadmin web application to
          run arbitrary shell commands with the credentials of the web
          server.
  
  PR:             127417
  Submitted by:   Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
  Approved by:    portmgr (pav)
  Security:       http://www.vuxml.org/freebsd/74bf1594-8493-11dd-bb64-0030843d3802.html
  
  Revision  Changes    Path
  1.92      +1 -1      ports/databases/phpmyadmin/Makefile
  1.75      +3 -3      ports/databases/phpmyadmin/distinfo
_______________________________________________
cvs-all@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/cvs-all
To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"
Comment 3 Martin Wilke freebsd_committer freebsd_triage 2008-09-17 10:29:11 UTC
State Changed
From-To: open->closed

Committed. Thanks!