Upstream has issued advisories on August 17: http://www.phpmyadmin.net/home_page/security/PMASA-2014-8.php http://www.phpmyadmin.net/home_page/security/PMASA-2014-9.php Updated packages uploaded for Mageia 3, Mageia 4, and Cauldron. Advisory: ======================== Updated phpmyadmin package fixes security vulnerabilities: In phpMyAdmin before 4.1.14.3, multiple XSS vulnerabilities exist in browse table, ENUM editor, monitor, query charts and table relations pages (CVE-2014-5273). In phpMyAdmin before 4.1.14.3, with a crafted view name it is possible to trigger an XSS when dropping the view in view operation page (CVE-2014-5274). References: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5273 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5274 http://www.phpmyadmin.net/home_page/security/PMASA-2014-8.php http://www.phpmyadmin.net/home_page/security/PMASA-2014-9.php ======================== Updated packages in core/updates_testing: ======================== phpmyadmin-4.1.14.3-1.mga3 phpmyadmin-4.1.14.3-1.mga4 from SRPMS: phpmyadmin-4.1.14.3-1.mga3.src.rpm phpmyadmin-4.1.14.3-1.mga4.src.rpm Reproducible: Steps to Reproduce:
Whiteboard: (none) => MGA3TOO
Procedure: https://bugs.mageia.org/show_bug.cgi?id=12834#c7
CC: (none) => remiWhiteboard: MGA3TOO => MGA3TOO has_procedure
Tested mga4-64 as in the procedure bug: Version shows correctly. user added with same name database, table created, user and database deleted logged out all OK
CC: (none) => wrw105Whiteboard: MGA3TOO has_procedure => MGA3TOO has_procedure mga4-64-ok
tested mga3-32 as above. No regressions noted.
Whiteboard: MGA3TOO has_procedure mga4-64-ok => MGA3TOO has_procedure mga4-64-ok mga3-32-ok
This can be validated once the advisory is uploaded.
just noticed the ready to validate notice, but I've reinstalled mga3-64, so this seemed like a good "Put it through its paces" thing. No regressions noted.
Whiteboard: MGA3TOO has_procedure mga4-64-ok mga3-32-ok => MGA3TOO has_procedure mga4-64-ok mga3-32-ok mga3-64-ok
Advisory uploaded. Validating. Could sysadmin please push to 3 & 4 updates Thanks
Keywords: (none) => validated_updateWhiteboard: MGA3TOO has_procedure mga4-64-ok mga3-32-ok mga3-64-ok => MGA3TOO advisory has_procedure mga4-64-ok mga3-32-ok mga3-64-okCC: (none) => sysadmin-bugs
An update for this issue has been pushed to Mageia Updates repository. http://advisories.mageia.org/MGASA-2014-0344.html
Status: NEW => RESOLVEDResolution: (none) => FIXED
URL: (none) => http://lwn.net/Vulnerabilities/609185/