debian: new phpmyadmin packages fix cross-site scripting - the community's center for security

debian: new phpmyadmin packages fix cross-site scripting - the community's center for security the central voice for linux and open source security news home news topics advisories howtos features newsletters about register ls.comadvisoriesfeatureshowtoslinux eventsnewsnewsletterspresssecurity dictionarysecurity tips welcome! sign up! engarde community login polls when was the last time you read a book on linux like "linux firewalls?" i'm reading right now! this past month. a couple months ago. ealier in the year. last year. read? books? i have the internet.   security center book reviews security dictionary security tips selinux white papers community linux events linux user groups link to us featured blogs danwalsh livejournal tenable network security mayank sharma: ibm advisories ubuntu: flac vulnerabilitymandriva: updated kernel packages fix multipleredhat: moderate: ruby security update latest newsletters linux security week: november 12th, 2007linux advisory watch: november 9th, 2007 subscribe linuxsecurity newsletters e-mail: choose lists: both lists newsletter security advisories about our newsletters rss feeds get the linuxsecurity news you want faster with rss powered by debian: new phpmyadmin packages fix cross-site scripting user rating:      how can i rate this item? posted by benjamin d. thomas    omer singer of the digitrust group discovered several vulnerabilities in phpmyadmin, an application to administrate mysql over the www. the common vulnerabilities and exposures project identifies, phpmyadmin allows a remote attacker to inject arbitrary web script or html in the context of a logged in user's session (cross site scripting). - -------------------------------------------------------------------------- debian security advisory dsa 1403-1 security@debian.org http://www.debian.org/security/ thijs kinkhorst november 8th, 2007 http://www.debian.org/security/faq - -------------------------------------------------------------------------- package : phpmyadmin vulnerability : missing input sanitising problem-type : remote debian-specific: no cve id : cve-2007-5589 cve-2007-5386 omer singer of the digitrust group discovered several vulnerabilities in phpmyadmin, an application to administrate mysql over the www. the common vulnerabilities and exposures project identifies the following problems: cve-2007-5589 phpmyadmin allows a remote attacker to inject arbitrary web script or html in the context of a logged in user's session (cross site scripting). cve-2007-5386 phpmyadmin, when accessed by a browser that does not url-encode requests, allows remote attackers to inject arbitrary web script or html via the query string. for the old stable distribution (sarge) this problem has been fixed in version 4:2.6.2-3sarge6. for the stable distribution (etch) this problem has been fixed in version 4:2.9.1.1-6. for the unstable distribution (sid) this problem has been fixed in version 4:2.11.1.2-1. we recommend that you upgrade your phpmyadmin package. upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. if you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages you may use an automated update by adding the resources from the footer to the proper configuration. debian gnu/linux 3.1 alias sarge - -------------------------------- source archives: http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.6.2-3sarge6.dsc size/md5 checksum: 896 6f8e63669094450f8450a808deacff73 http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.6.2-3sarge6.diff.gz size/md5 checksum: 42524 14903fdbe6383e4fa6934e4b955851ec http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.6.2.orig.tar.gz size/md5 checksum: 2654418 05e33121984824c43d94450af3edf267 architecture independent components: http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.6.2-3sarge6_all.deb size/md5 checksum: 2770320 b1cfa31fcc29881a78269f38de1387c6 debian gnu/linux 4.0 alias etch - ------------------------------- source archives: http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.9.1.1-6.dsc size/md5 checksum: 1011 130531a7ffe3fd67421985abc0d7e3c1 http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.9.1.1-6.diff.gz size/md5 checksum: 49749 0ea3fc9730fb32d1587e0757d3fbee25 http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.9.1.1.orig.tar.gz size/md5 checksum: 3500563 f598509b308bf96aee836eb2338f523c architecture independent components: http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.9.1.1-6_all.deb size/md5 checksum: 3606276 be23322772089af7b429c01b65fe1469 these files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- for apt-get: deb http://security.debian.org/ stable/updates main for dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main mailing list: debian-security-announce@lists.debian.org   < prev   next > partner:   latest features review: linux firewallsstate of linux security surveyunderstand: fork bombing attackreview: ruby by examplewhat makes metasploit tick?review: computer security basics 2nd editionreview: practical packet analysis yesterday's edition apparmor's security goals interview with the author of "linux firewalls" firefox security flaw affecting gmail's users home | about us | advertise | legal notice | rss | guardian digital (c)copyright 2007 guardian digital, inc. all rights reserved.

Acceuil

suivante

debian: new phpmyadmin packages fix cross-site scripting - the community's center for security  Mandriva: Updated netpbm packages fix vulnerability - The ...  How to Fix No Child Left Behind - TIME  Film Fix v1.0  JScreenFix - Fix stuck pixels and screen burn-in  Mac OS X and iPod Troubleshooting, Support, and Help - MacFixIt  Braun 1775 FREE Control /FIX 100 : avis de consommateurs ...  Macworld: News: Word fix corrects quit on print error  Macworld: Mac 911: Bugs & Fixes: Fix Leopard glitches  Housse Sit Fix pour coussin 3 en 1, Housse Sit Fix - Fnac éveil et ...  Blagojevich floats new temporary fix :: CHICAGO SUN-TIMES ...  Here's hoping fix is in :: CHICAGO SUN-TIMES :: Mike Mulligan  Fix-it Index Page  Functions, events, club, bar, lounge, entertainment, Venues ...  Fix the Fells - Home  Excel Recovery Tool - Fix & Repair Excel File - Corrupt XLS Repair ...  Fast Fix Jewelry and Watch Repairs  B2BITS — High Performance FIX Solutions  Definition: fix from Online Medical Dictionary  Télécharger Object Fix Zip - Zebulon.fr : téléchargement du ...  Aimfix - Jayloden.com  BBC SPORT Tennis Llodra reveals match-fix approach  BBC NEWS Science/Nature Lovelock urges ocean climate fix  Growing a Business Website: Fix the Basics First (Jakob Nielsen's ...  6 Ways to Fix a Confused Information Architecture (Jakob Nielsen's ...  Definition of fix - Merriam-Webster Online Dictionary  ColdFusion MX 7 Cumulative Hot Fix 3  ColdFusion 8.0 Cumulative Hot Fix 1  FixMyXP.com - Your One Stop Windows XP Fix It Site  Télécharger Works Fix  réseau pc fix(usb) portable wifi - je ne trouve pas les config ...  SubZero Fix PSTwo - : FOXCHIP : Modification et Réparation des ...  GRC FIX-CIH Virus Recovery  IEBlog : Fix My Settings in IE7  Let's Fix britain  The Beyonce Fix Intro....  The new urgency to fix online privacy Tech News on ZDNet  Macworld: News: Apple releases fix for iMac freezing issue  Macworld: News: Apple posts QuickTime security fix  SmitFraudFix  QuickFix: Open Source FIX Engine  Free Registry Fix - Fix My Registry  Candy- Chocolate- A Candy Fix  Lettres édifiantes et curieuses, écrites des missions étrangères. - Résultats Google Recherche de Livres  Water fix proposed in Southeast - Weather - MSNBC.com  OpenBSD 4.0 errata  Reviews: Video Game Reviews Are Broken, Please Fix  System Downloads : DHCP Fix /// AnalogX  How to fix broken Firefox extensions Free Software Magazine  molly.com » So How Do We Fix the Web, Really?  PKH-fix - Prozeßkostenhilfeberechnung  macosxhints.com - 10.5: A fix for broken video chats and screen ...  Acheter Housse pouf Sit Fix... avec eco-SAPIENS  MacNN Apple updates iMac fix for Tiger users  MacNN Apple updates iMac fix for Tiger users  Madeleine Fix-Hansen :: Design :: Illustration :: Media ...  How not to fix HTML ¶ Personal Weblog of Joe Clark, Toronto  Histoire philosophique et politique des établissemens et du ... - Résultats Google Recherche de Livres  Markdown Fix  Registry Repair, Clean Up & File Fix for Windows  PNG in Internet Explorer: How to Use