• [SECURITY] [DSA 2097-2] New phpmyadmin packages fix several vulnerabili

    From Thijs Kinkhorst@1:229/2 to All on Sat Sep 11 16:40:02 2010
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-2097-2 [email protected] http://www.debian.org/security/ Thijs Kinkhorst September 11, 2010 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : phpmyadmin
    Vulnerability : insufficient input sanitising
    Problem type : remote
    Debian-specific: no
    CVE Id(s) : CVE-2010-3055 CVE-2010-3056

    The update in DSA 2097 for phpMyAdmin did not correctly apply the intended changes, thereby not completely addressing the vulnerabilities. Updated packages now fix the issues described in the original advisory text below.

    Several remote vulnerabilities have been discovered in phpMyAdmin, a tool
    to administer MySQL over the web. The Common Vulnerabilities and Exposures project identifies the following problems:

    CVE-2010-3055

    The configuration setup script does not properly sanitise its output
    file, which allows remote attackers to execute arbitrary PHP code via
    a crafted POST request. In Debian, the setup tool is protected through
    Apache HTTP basic authentication by default.

    CVE-2010-3056

    Various cross site scripting issues have been discovered that allow
    a remote attacker to inject arbitrary web script or HTML.

    For the stable distribution (lenny), these problems have been fixed in
    version 2.11.8.1-5+lenny6.

    For the testing (squeeze) and unstable distribution (sid), these problems
    have been fixed in version 3.3.5.1-1.

    We recommend that you upgrade your phpmyadmin package.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 5.0 alias lenny
    - --------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.11.8.1.orig.tar.gz
    Size/MD5 checksum: 2870014 075301d16404c2d7d58216efc14f7a50
    http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.11.8.1-5+lenny6.diff.gz
    Size/MD5 checksum: 74349 e6f8e4ff6d973af576abeb4760caf5e0
    http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.11.8.1-5+lenny6.dsc
    Size/MD5 checksum: 1548 d6b8c634186104661caee4ac419a10ea

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/p/phpmyadmin/phpmyadmin_2.11.8.1-5+lenny6_all.deb
    Size/MD5 checksum: 2886448 dcfc410cc5bcebc61bb32e33662e7fd3


    These files will probably be moved into the stable distribution on
    its next update.

    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: [email protected]
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg> -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.10 (GNU/Linux)

    iQEcBAEBAgAGBQJMi5HuAAoJEOxfUAG2iX57mq4H/jpm3TX1OTgjyFcivXT2WLGP 7wzuKKTl8TxoO4aqCEH9LmEtu2a+La7Vcme64HgXgVR3MG/+ZIXAEv6YQrnKwgfE mli4nLPwKkMsjY6iq/60F/AZp1NIKrSrfIMNOYM9SciLp+mhdzAup+JRx+1bPlxE 6pFEiKfs1/FHmuQFxPHZYtzCFwm//3p+ihP46fJvRqaD91iX3kFdHEdBB2Xctet4 NmhNRXQnugTE7NtnhRB0I9Kz4e92l5wLFbU+WUZhmrbOPyX2n9TjnST0IO++/Jtn 40ClfqAlERCY6qFFDON005OCmIX7bGAcO3j28I3feMOts6CGsbTyxrW7gyVo/8o=
    =Ehxb
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • From Lorenzo "Lo'oris" Petrone@1:229/2 to Thijs Kinkhorst on Sat Sep 11 17:10:02 2010
    XPost: linux.debian.security
    From: [email protected]

    --0016361e80163e5b0b048ffd0087
    Content-Type: text/plain; charset=UTF-8
    Content-Transfer-Encoding: quoted-printable

    On Sat, Sep 11, 2010 at 4:36 PM, Thijs Kinkhorst <[email protected]> wrote:

    For the testing (squeeze) and unstable distribution (sid), these problems have been fixed in version 3.3.5.1-1.


    bon, non avevo letto, è già su la versione fixata, gg

    --
    venera Lo'oris su http://looris.net

    --0016361e80163e5b0b048ffd0087
    Content-Type: text/html; charset=UTF-8
    Content-Transfer-Encoding: quoted-printable

    <div class="gmail_quote">On Sat, Sep 11, 2010 at 4:36 PM, Thijs Kinkhorst <span dir="ltr">&lt;<a href="mailto:[email protected]">[email protected]</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;
    padding-left:1ex;">
    <div id=":gt">For the testing (squeeze) and unstable distribution (sid), these problems<br>
    have been fixed in version 3.3.5.1-1.<br></div></blockquote></div><br>bon, non avevo letto, è già su la versione fixata, gg<br clear="all"><br>-- <br>venera Lo&#39;oris su <a href="http://looris.net">http://looris.net</a><br>


    --0016361e80163e5b0b048ffd0087--


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/AANLkTikvfLVmaDcz7ZcBwWHO01xXqpsE4QPZ