| Summary: | phpmyadmin new security issue CVE-2018-7260 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | lists.jjorge, sysadmin-bugs |
| Version: | 6 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA6-64-OK | ||
| Source RPM: | phpmyadmin-4.7.7-1.mga7.src.rpm | CVE: | |
| Status comment: | Fixed upstream in 4.7.8 | ||
|
Description
David Walser
2018-02-23 12:08:09 CET
David Walser
2018-02-23 12:08:24 CET
Status comment:
(none) =>
Fixed upstream in 4.7.8 Thanks for the report. Version 4.7.8 submitted to cauldron and MGA6. Assignee:
lists.jjorge =>
qa-bugs Mageia 6 update hasn't been pushed yet. Assignee:
qa-bugs =>
lists.jjorge
José Jorge
2018-02-23 13:40:25 CET
Assignee:
lists.jjorge =>
qa-bugs (In reply to David Walser from comment #2) > Mageia 6 update hasn't been pushed yet. You are right, now it is pushed. Advisory: ======================== Updated phpmyadmin package fixes security vulnerability: A self-cross site scripting (XSS) vulnerability has been reported relating to the central columns feature (CVE-2018-7260). References: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7260 https://www.phpmyadmin.net/security/PMASA-2018-1/ https://www.phpmyadmin.net/files/4.7.8/ https://www.phpmyadmin.net/news/2018/2/20/security-fix-phpmyadmin-478-released/ ======================== Updated packages in core/updates_testing: ======================== phpmyadmin-4.7.8-1.mga6 from phpmyadmin-4.7.8-1.mga6.src.rpm Testing M6/64 AFTER update to: phpmyadmin-4.7.8-1.mga6 http://localhost/phpmyadmin Chose UK English language at login, created a database, one table, 4 different fields, first made unique & index, inserted rows, edited data, deleted by row, deleted table, deleted the DB. All looks OK, so OKing & validating the update as it has nothing to do with the current Qt update. Keywords:
(none) =>
validated_update An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2018-0156.html Resolution:
(none) =>
FIXED |