Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 373951 (CVE-2011-2505) - <dev-db/phpmyadmin-3.4.3.1: Multiple Vulnerabilities PMASA-2011-{5,6,7,8} (CVE-2011-{2505,2506,2507,2508})
Summary: <dev-db/phpmyadmin-3.4.3.1: Multiple Vulnerabilities PMASA-2011-{5,6,7,8} (CV...
Status: RESOLVED FIXED
Alias: CVE-2011-2505
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL: http://www.phpmyadmin.net/home_page/s...
Whiteboard: B1 [glsa]
Keywords:
: 374167 (view as bug list)
Depends on:
Blocks:
 
Reported: 2011-07-03 21:32 UTC by Tim Sammut (RETIRED)
Modified: 2012-01-04 23:42 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tim Sammut (RETIRED) gentoo-dev 2011-07-03 21:32:16 UTC
Four new advisories released by upstream.

http://www.phpmyadmin.net/home_page/security/PMASA-2011-5.php
CVE-2011-2505
Possible session manipulation in Swekey authentication. 

http://www.phpmyadmin.net/home_page/security/PMASA-2011-6.php
CVE-2011-2506
Possible code injection in setup script in case session variables are compromised. 

http://www.phpmyadmin.net/home_page/security/PMASA-2011-7.php
CVE-2011-2507
Regular expression quoting issue in Synchronize code. 

http://www.phpmyadmin.net/home_page/security/PMASA-2011-8.php
CVE-2011-2508
Possible directory traversal. 

All appear fixed in 3.4.3.1.
Comment 1 Tim Sammut (RETIRED) gentoo-dev 2011-07-05 18:43:40 UTC
*** Bug 374167 has been marked as a duplicate of this bug. ***
Comment 2 Alex Legler (RETIRED) archtester gentoo-dev Security 2011-07-06 08:48:58 UTC
Arches, please test and mark stable:
=dev-db/phpmyadmin-3.4.3.1
Target keywords : "alpha amd64 hppa ppc ppc64 sparc x86"
Comment 3 Agostino Sarubbo gentoo-dev 2011-07-06 09:47:10 UTC
amd64 ok
Comment 4 Ian Delaney (RETIRED) gentoo-dev 2011-07-06 15:33:55 UTC
ditto
Comment 5 Markos Chandras (RETIRED) gentoo-dev 2011-07-06 17:48:46 UTC
amd64 done. Thanks Agostino and Ian
Comment 6 Thomas Kahle (RETIRED) gentoo-dev 2011-07-08 12:33:32 UTC
x86 stable. Thanks
Comment 7 Kacper Kowalik (Xarthisius) (RETIRED) gentoo-dev 2011-07-09 07:46:25 UTC
ppc/ppc64 stable
Comment 8 Raúl Porcel (RETIRED) gentoo-dev 2011-07-09 16:53:32 UTC
alpha/sparc stable
Comment 9 Jeroen Roovers (RETIRED) gentoo-dev 2011-07-11 02:03:07 UTC
Stable for HPPA.
Comment 10 Tim Sammut (RETIRED) gentoo-dev 2011-07-11 02:04:35 UTC
Thanks, folks. Added to existing GLSA request.
Comment 11 GLSAMaker/CVETool Bot gentoo-dev 2012-01-04 23:42:09 UTC
This issue was resolved and addressed in
 GLSA 201201-01 at http://security.gentoo.org/glsa/glsa-201201-01.xml
by GLSA coordinator Tim Sammut (underling).