| Summary: | php-adodb new security issue CVE-2021-3850 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | andrewsfarm, davidwhodgins, herman.viaene, mageia, mageia, sysadmin-bugs |
| Version: | 8 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8-64-OK | ||
| Source RPM: | php-adodb-5.20.18-1.mga8.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2022-02-06 17:32:41 CET
David Walser
2022-02-06 17:32:54 CET
Whiteboard:
(none) =>
MGA8TOO Looks good for assigning to MarcK, maintainer of this package. Assignee:
bugsquad =>
mageia
Nicolas Lécureuil
2022-02-07 14:53:11 CET
CC:
(none) =>
mageia patch added in mga8/9
src:
- php-adodb-5.20.18-1.1.mga8Status comment:
Fixed upstream in 5.20.21 =>
(none) @Nico: why not update. Is it worth to do patching?! Pecl libs do not change that much. In most cases the new release has just the patch in it.
Marc Krämer
2022-02-07 18:56:44 CET
Assignee:
qa-bugs =>
mageia Updated php-adodb to fix a critical vulnerability: Security hotfix release addressing a critical vulnerability in PostgreSQL connections Additional fixes: - Fix usage of get_magic_* functions #619 #657 - Fix PHP warning in _rs2rs() function #679 - pdo: Fix Fatal error in _query() #666 - pdo: Fix undefined variable #678 - pgsql: Fix Fatal error in _close() method (PHP8) #666 - pgsql: fix deprecated function aliases (PHP8) #667 - text: fix Cannot pass parameter by reference #668 - Add support for persistent connections in PDO driver #650 - Connect to SQL Server database on a specified port. #624 - DSN database connection with password containing # fails #651 - Metacolumns returns wrong type for integer fields in Mysql 8 #642 - Uninitialized Variable access in mssqlnative ErrorNo() method #637 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3850 https://github.com/ADOdb/ADOdb/releases/tag/v5.20.21 Updated packages in core/updates_testing: ======================== php-adodb-5.20.21-1.mga8.noarch SRPM: php-adodb-5.20.21-1.mga8.src.rpm Assignee:
mageia =>
qa-bugs MGA8-64 Plasma on Lenovo B50 in Dutch No installation issues. Ref bug 19307: I do not see any proof (strace or something that this library is actually used in the example. And # urpmq --whatrequires php-adodb php-adodb # urpmq --whatrequires-recursive php-adodb php-adodb I don't like spending time on a developer's library, and will OK it on clean install as we usually do with such libraries. CC:
(none) =>
herman.viaene Validating. Advisory in Comment 4. Keywords:
(none) =>
validated_update
Dave Hodgins
2022-02-12 17:23:51 CET
CC:
(none) =>
davidwhodgins An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2022-0056.html Status:
NEW =>
RESOLVED |