Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 410671 (CVE-2012-1600) - <dev-db/phppgadmin-5.0.4 : Functions Script Insertion Vulnerability (CVE-2012-1600)
Summary: <dev-db/phppgadmin-5.0.4 : Functions Script Insertion Vulnerability (CVE-2012...
Status: RESOLVED FIXED
Alias: CVE-2012-1600
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/48574/
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-04-03 16:04 UTC by Agostino Sarubbo
Modified: 2012-08-14 05:46 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-04-03 16:04:30 UTC
From secunia security advisory at $URL:
Comment 1 Agostino Sarubbo gentoo-dev 2012-04-03 16:05:19 UTC
Description
A vulnerability has been reported in phpPgAdmin, which can be exploited by malicious users to conduct script insertion attacks.

Certain unspecified input related to functions is not properly sanitised before being used. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the malicious data is being viewed.

The vulnerability is reported in version 5.0.3. Prior versions may also be affected.


Solution
Update to version 5.0.4.
Comment 2 Aaron W. Swenson gentoo-dev 2012-06-08 17:06:09 UTC
*phppgadmin-5.0.4 (08 Jun 2012)

  08 Jun 2012; Aaron W. Swenson <titanofold@gentoo.org>
  +phppgadmin-5.0.4.ebuild:
  Version bump.
Comment 3 Jeroen Roovers (RETIRED) gentoo-dev 2012-06-09 14:08:01 UTC
Arch teams, please test and mark stable:
=dev-db/phppgadmin-5.0.4
Target KEYWORDS="amd64 hppa ppc x86"
Comment 4 Agostino Sarubbo gentoo-dev 2012-06-11 09:20:11 UTC
amd64 stable
Comment 5 Jeroen Roovers (RETIRED) gentoo-dev 2012-06-11 11:16:53 UTC
Stable for HPPA.
Comment 6 Andreas Schürch gentoo-dev 2012-06-13 11:59:55 UTC
x86 stable, thanks
Comment 7 Michael Weber (RETIRED) gentoo-dev 2012-07-08 21:00:34 UTC
ppc stable, last arch.
Comment 8 Agostino Sarubbo gentoo-dev 2012-07-08 21:05:54 UTC
@security: please vote
Comment 9 Tim Sammut (RETIRED) gentoo-dev 2012-08-14 05:46:28 UTC
Thanks, folks. Closing noglsa for XSS.