Security fixes in phpmyadmin 2.8.1

Bug #45976 reported by Laurent CHARTRAIN
This bug report is a duplicate of:  Bug #82003: phpmyadmin has several security bugs. Edit Remove
260
Affects Status Importance Assigned to Milestone
phpmyadmin (Ubuntu)
Fix Released
Medium
Unassigned
Dapper
Confirmed
Undecided
Unassigned

Bug Description

Binary package hint: phpmyadmin

Hello,

I think it's strongly recommended to upgrade to phpmyadmin 2.8.1
It fixes security issue : http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2006-3

http://www.phpmyadmin.net/home_page/downloads.php?relnotes=1
phpmyadmin 2.8.0.4 also fixes some security issues and some bugs about PHP 5.1.2 (which is still the dapper version, even if I really hope PHP 5.1.4 will be in dapper)

So the 2.8.0.3 version in dapper must be upgraded !

Thx.

Revision history for this message
Olivier Cortès (olive) wrote :

Hi,

you can find an up-to-date package at:

deb http://secure.ryxeo.com/ubuntu dapper main restricted

If anyone is willing to give me upload rights to universe, i will be obliged to upload the package. Anytime soon i will apply to be an official universe uploader, but i didn't find the time to do it yet...

Revision history for this message
Olivier Cortès (olive) wrote :

Yeah, there are many security bugs in 2.8.0.3...

Changed in phpmyadmin:
status: Unconfirmed → Confirmed
Revision history for this message
Martin Pitt (pitti) wrote :

http://secure.ryxeo.com/ubuntu is a little too secure, it just gives a 'permission denied'. Usually we do not put new upstream versions into -security, but since it's only a 0.1-microversion, I'll take a look at the diff, and upload it if it looks sane.

Thank you!

Revision history for this message
Olivier Cortès (olive) wrote :

Sorry, it had Option -Indexes in the apache config. This is corrected now. But the package was still accessible with apt (only plain http index was denied).

Revision history for this message
Olivier Cortès (olive) wrote :

and sorry, i uploaded 2.8.1, not 2.0.8.4... it is thus not a microversion update...

Revision history for this message
Martin Pitt (pitti) wrote :

Edgy has 2.8.1.

Changed in phpmyadmin:
status: Confirmed → Fix Released
Revision history for this message
Martin Pitt (pitti) wrote :

Adding dapper task; if anyone feels like backporting the fix to 2.8.0.3, I'll assist with uploading/publishing.

Changed in phpmyadmin:
status: Unconfirmed → Confirmed
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.