As usual there are many fixes and security enhancements (no eval, no inline js).
(In reply to Marc Krämer from comment #0) > As usual there are many fixes and security enhancements (no eval, no inline > js).
CC: (none) => lists.jjorge, luigiwalser, marja11Assignee: bugsquad => php
Assignee: php => mageia
The security fix is for an issue that was introduced in 4.8.0, so an update for Mageia 6 isn't needed.
true David. I should better put it in backports.
phpmyadmin-4.8.0.1-2.mga6.src.rpm
Keywords: (none) => BackportSeverity: normal => enhancementSummary: Update phpmyadmin to 4.8.0.1 => Backport Request: Update phpmyadmin to 4.8.0.1Component: RPM Packages => Backports
Suggested advisory: ======================== Backported phpmyadmin package to the latest release. This backport has some security enhancements, as php does not need to have eval enabled. As all JS-inline scripts have been removed, it is save to turn on Content Security Policy for phpmyadmin, which adds additional protection against XSS vulnerabilities. Updated packages in core/backports_testing: ======================== phpmyadmin-4.8.0.1-2.mga6.noarch.rpm Source RPMs: phpmyadmin-4.8.0.1-2.mga6.src.rpm
After some testing, I have to refuse my own backport request.
Status: NEW => RESOLVEDResolution: (none) => WONTFIX