debian: new phpmyadmin packages fix cross-site scripting - the community's center for security
debian: new phpmyadmin packages fix cross-site scripting - the community's center for security
the central voice for linux and open source security news
home
news topics
advisories
howtos
features newsletters
about
register
ls.comadvisoriesfeatureshowtoslinux eventsnewsnewsletterspresssecurity dictionarysecurity tips
welcome!
sign up!
engarde community
login
polls
when was the last time you read a book on linux like "linux firewalls?"
i'm reading right now!
this past month.
a couple months ago.
ealier in the year.
last year.
read? books? i have the internet.
security center
book reviews
security dictionary
security tips
selinux
white papers
community
linux events
linux user groups
link to us
featured blogs
danwalsh livejournal
tenable network security
mayank sharma: ibm
advisories
ubuntu: flac vulnerabilitymandriva: updated kernel packages fix multipleredhat: moderate: ruby security update
latest newsletters
linux security week: november 12th, 2007linux advisory watch: november 9th, 2007
subscribe
linuxsecurity newsletters
e-mail:
choose lists:
both lists
newsletter
security advisories
about our newsletters
rss feeds
get the linuxsecurity news you want faster with rss
powered by
debian: new phpmyadmin packages fix cross-site scripting
user rating:
how can i rate this item?
posted by benjamin d. thomas
omer singer of the digitrust group discovered several vulnerabilities in
phpmyadmin, an application to administrate mysql over the www. the common
vulnerabilities and exposures project identifies, phpmyadmin allows a remote attacker to inject arbitrary web script or html in the context of a logged in user's session (cross site scripting).
- --------------------------------------------------------------------------
debian security advisory dsa 1403-1 security@debian.org
http://www.debian.org/security/ thijs kinkhorst
november 8th, 2007 http://www.debian.org/security/faq
- --------------------------------------------------------------------------
package : phpmyadmin
vulnerability : missing input sanitising
problem-type : remote
debian-specific: no
cve id : cve-2007-5589 cve-2007-5386
omer singer of the digitrust group discovered several vulnerabilities in
phpmyadmin, an application to administrate mysql over the www. the common
vulnerabilities and exposures project identifies the following problems:
cve-2007-5589
phpmyadmin allows a remote attacker to inject arbitrary web script
or html in the context of a logged in user's session (cross site
scripting).
cve-2007-5386
phpmyadmin, when accessed by a browser that does not url-encode
requests, allows remote attackers to inject arbitrary web script
or html via the query string.
for the old stable distribution (sarge) this problem has been fixed in
version 4:2.6.2-3sarge6.
for the stable distribution (etch) this problem has been fixed in
version 4:2.9.1.1-6.
for the unstable distribution (sid) this problem has been fixed in
version 4:2.11.1.2-1.
we recommend that you upgrade your phpmyadmin package.
upgrade instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
if you are using the apt-get package manager, use the line for
sources.list as given below:
apt-get update
will update the internal database
apt-get upgrade
will install corrected packages
you may use an automated update by adding the resources from the
footer to the proper configuration.
debian gnu/linux 3.1 alias sarge
- --------------------------------
source archives:
http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.6.2-3sarge6.dsc
size/md5 checksum: 896 6f8e63669094450f8450a808deacff73
http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.6.2-3sarge6.diff.gz
size/md5 checksum: 42524 14903fdbe6383e4fa6934e4b955851ec
http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.6.2.orig.tar.gz
size/md5 checksum: 2654418 05e33121984824c43d94450af3edf267
architecture independent components:
http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.6.2-3sarge6_all.deb
size/md5 checksum: 2770320 b1cfa31fcc29881a78269f38de1387c6
debian gnu/linux 4.0 alias etch
- -------------------------------
source archives:
http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.9.1.1-6.dsc
size/md5 checksum: 1011 130531a7ffe3fd67421985abc0d7e3c1
http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.9.1.1-6.diff.gz
size/md5 checksum: 49749 0ea3fc9730fb32d1587e0757d3fbee25
http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.9.1.1.orig.tar.gz
size/md5 checksum: 3500563 f598509b308bf96aee836eb2338f523c
architecture independent components:
http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.9.1.1-6_all.deb
size/md5 checksum: 3606276 be23322772089af7b429c01b65fe1469
these files will probably be moved into the stable distribution on
its next update.
- ---------------------------------------------------------------------------------
for apt-get: deb http://security.debian.org/ stable/updates main
for dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
mailing list: debian-security-announce@lists.debian.org
< prev
next >
partner:
latest features
review: linux firewallsstate of linux security surveyunderstand: fork bombing attackreview: ruby by examplewhat makes metasploit tick?review: computer security basics 2nd editionreview: practical packet analysis
yesterday's edition
apparmor's security goals
interview with the author of "linux firewalls"
firefox security flaw affecting gmail's users
home |
about us |
advertise |
legal notice |
rss |
guardian digital
(c)copyright 2007 guardian digital, inc. all rights reserved.
Acceuil
suivante
debian: new phpmyadmin packages fix cross-site scripting - the community's center for security Mandriva: Updated netpbm packages fix vulnerability - The ... How to Fix No Child Left Behind - TIME Film Fix v1.0 JScreenFix - Fix stuck pixels and screen burn-in Mac OS X and iPod Troubleshooting, Support, and Help - MacFixIt Braun 1775 FREE Control /FIX 100 : avis de consommateurs ... Macworld: News: Word fix corrects quit on print error Macworld: Mac 911: Bugs & Fixes: Fix Leopard glitches Housse Sit Fix pour coussin 3 en 1, Housse Sit Fix - Fnac éveil et ... Blagojevich floats new temporary fix :: CHICAGO SUN-TIMES ... Here's hoping fix is in :: CHICAGO SUN-TIMES :: Mike Mulligan Fix-it Index Page Functions, events, club, bar, lounge, entertainment, Venues ... Fix the Fells - Home Excel Recovery Tool - Fix & Repair Excel File - Corrupt XLS Repair ... Fast Fix Jewelry and Watch Repairs B2BITS — High Performance FIX Solutions Definition: fix from Online Medical Dictionary Télécharger Object Fix Zip - Zebulon.fr : téléchargement du ... Aimfix - Jayloden.com BBC SPORT Tennis Llodra reveals match-fix approach BBC NEWS Science/Nature Lovelock urges ocean climate fix Growing a Business Website: Fix the Basics First (Jakob Nielsen's ... 6 Ways to Fix a Confused Information Architecture (Jakob Nielsen's ... Definition of fix - Merriam-Webster Online Dictionary ColdFusion MX 7 Cumulative Hot Fix 3 ColdFusion 8.0 Cumulative Hot Fix 1 FixMyXP.com - Your One Stop Windows XP Fix It Site Télécharger Works Fix réseau pc fix(usb) portable wifi - je ne trouve pas les config ... SubZero Fix PSTwo - : FOXCHIP : Modification et Réparation des ... GRC FIX-CIH Virus Recovery IEBlog : Fix My Settings in IE7 Let's Fix britain The Beyonce Fix Intro.... The new urgency to fix online privacy Tech News on ZDNet Macworld: News: Apple releases fix for iMac freezing issue Macworld: News: Apple posts QuickTime security fix SmitFraudFix QuickFix: Open Source FIX Engine Free Registry Fix - Fix My Registry Candy- Chocolate- A Candy Fix Lettres édifiantes et curieuses, écrites des missions étrangères. - Résultats Google Recherche de Livres Water fix proposed in Southeast - Weather - MSNBC.com OpenBSD 4.0 errata Reviews: Video Game Reviews Are Broken, Please Fix System Downloads : DHCP Fix /// AnalogX How to fix broken Firefox extensions Free Software Magazine molly.com » So How Do We Fix the Web, Really? PKH-fix - Prozeßkostenhilfeberechnung macosxhints.com - 10.5: A fix for broken video chats and screen ... Acheter Housse pouf Sit Fix... avec eco-SAPIENS MacNN Apple updates iMac fix for Tiger users MacNN Apple updates iMac fix for Tiger users Madeleine Fix-Hansen :: Design :: Illustration :: Media ... How not to fix HTML ¶ Personal Weblog of Joe Clark, Toronto Histoire philosophique et politique des établissemens et du ... - Résultats Google Recherche de Livres Markdown Fix Registry Repair, Clean Up & File Fix for Windows PNG in Internet Explorer: How to Use