Sync phpmyadmin 4:3.3.7-2 (universe) from Debian sid (main)

Bug #684865 reported by Micah Gersten
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
phpmyadmin (Ubuntu)
Invalid
Wishlist
Unassigned
Maverick
Fix Released
Wishlist
Unassigned

Bug Description

Please sync phpmyadmin 4:3.3.7-2 (universe) from Debian sid (main)

Changelog entries since current maverick version 4:3.3.7-1:

phpmyadmin (4:3.3.7-2) unstable; urgency=high

  * Fix XSS on search (PMASA-2010-8, CVE-2010-4329).

 -- Michal Čihař <email address hidden> Wed, 01 Dec 2010 15:08:04 +0100

Tags: sync

CVE References

Micah Gersten (micahg)
Changed in phpmyadmin (Ubuntu):
importance: Undecided → Wishlist
tags: added: sync
security vulnerability: no → yes
Revision history for this message
Micah Gersten (micahg) wrote :

Bug #684861 is for Natty, so marking Natty task invalid.

Changed in phpmyadmin (Ubuntu):
status: New → Invalid
Changed in phpmyadmin (Ubuntu Maverick):
importance: Undecided → Wishlist
status: New → Confirmed
status: Confirmed → New
Revision history for this message
Artur Rona (ari-tczew) wrote :

motu-swat ACK.

Revision history for this message
Steve Beattie (sbeattie) wrote :

Thanks, I've gone ahead and done a security-fake-sync against 4:3.3.7-2 and pushed it into the ubuntu-security-proposed ppa: https://launchpad.net/~ubuntu-security-proposed/+archive/ppa/ where it's currently building. Please test and report feedback here.

Thanks for helping to improve Ubuntu!

Steve Beattie (sbeattie)
Changed in phpmyadmin (Ubuntu Maverick):
status: New → Fix Committed
Revision history for this message
Steve Beattie (sbeattie) wrote :

$ $UQT/security-tools/unembargo --ppa ubuntu-security-proposed/ppa phpmyadmin --lpnet
Loading Ubuntu Distribution ...
Loading Ubuntu Archive ...
Loading ubuntu-security-proposed 'ppa' PPA ...
Locating phpmyadmin ...
        Publishing phpmyadmin 4:3.3.7-2build0.10.10.1 to ubuntu/primary maverick (Security)...

Changed in phpmyadmin (Ubuntu Maverick):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.